Privacy Policy
Effective Date: March 29, 2026
Last Updated: May 7, 2026
This Privacy Policy describes how Noct, LLC ("Noct," "we," "us," or "our") collects, uses, stores, protects, and discloses information obtained through our website located at https://noct.gg, our security scanning platform, dashboards, APIs, alerts, reports, and related services or communications (collectively, the "Services").
This Privacy Policy is intended to explain our data practices. Your use of the Services may also be governed by our Terms of Service, subscription terms, order forms, or other applicable agreements.
If you access or use the Services on behalf of a business, organization, or other entity, "you" refers to that entity, and you represent that you have authority to use the Services on its behalf.
1. INFORMATION WE COLLECT
1.1 Account and Registration Information
When you create an account, register for the Services, or communicate with us, we may collect information such as your name, business name, email address, job title, password or authentication information, and other account-related information.
For business customers, this may also include company size, industry, role, and other organizational details.
1.2 Billing and Subscription Information
If you purchase paid Services, we collect information necessary to manage your subscription, billing status, plan limits, usage tier, invoices, payment status, transaction history, and related billing records.
Billing and payment information may be processed by third-party billing or payment service providers. These providers may receive information necessary to process payments, manage invoices, prevent fraud, and complete transactions.
Noct does not provide Target Data, Scan Results, alerts, reports, AI summary inputs, or AI-generated summaries to billing or payment providers.
1.3 Infrastructure and Target Data
To perform security scanning, you may provide information about servers, IP addresses, hostnames, domains, subdomains, applications, cloud assets, endpoints, or other infrastructure assets that you represent you are authorized to scan ("Target Data").
We treat Target Data as confidential customer data and use it only to provide, secure, support, and improve the Services, enforce our agreements, comply with law, and protect Noct, our customers, and third parties.
You are responsible for ensuring that you have the necessary rights, permissions, and authority to submit Target Data to the Services and to authorize scans of such assets.
1.4 Scan Results, Alerts, and Security Findings
We generate and store data resulting from authorized scans of your submitted assets, including detected services, open ports, software version information, configuration details, security alerts, risk indicators, vulnerability information, remediation context, alert status, timestamps, and related metadata ("Scan Results").
Scan Results are associated with your account and treated as confidential customer data.
1.5 AI-Assisted Alert Summaries
The Services may use AI-assisted systems to summarize alert information, scan findings, remediation context, and other security-related information for display within your dashboard, reports, or alerts.
Noct operates these AI-assisted systems locally on Noct-controlled infrastructure within the United States. Customer security data is not sent to third-party AI providers.
We do not use your Target Data, Scan Results, alerts, AI inputs, or AI-generated summaries to train machine learning models or develop generalized AI models.
The AI summarization process is designed so that direct asset identifiers, such as IP addresses, domains, hostnames, and similar infrastructure identifiers, are excluded from the data provided to the AI system unless technically necessary to generate the requested summary.
AI-generated summaries may be stored with the related alert, scan result, report, or customer account so they can be displayed in the Services.
AI-generated summaries are provided for convenience and readability. They may not replace the underlying scan data, technical findings, or your own security review.
1.6 Usage, Traffic, and Technical Data
We automatically collect certain technical and usage data when you interact with the Services, including IP addresses, browser type and version, device information, operating system, referring URLs, pages viewed, features used, timestamps, session identifiers, authentication events, API usage, error logs, security logs, and traffic metadata.
Some traffic, request, CDN, firewall, proxy, anti-abuse, or security metadata may be processed by third-party service providers, including Cloudflare or similar providers, to protect the Services, route traffic, prevent abuse, and maintain availability.
We use usage, traffic, and technical data for platform security, abuse prevention, authentication, debugging, performance monitoring, service reliability, analytics, and service improvement.
1.7 Communications and Support
If you contact us by email, through our website, through support channels, or through in-platform messaging, we may retain those communications and any information you provide within them.
Support and communication data may be processed by third-party email, communication, or customer support service providers as necessary to receive, respond to, organize, and manage support requests.
You should not include credentials, secrets, private keys, or highly sensitive infrastructure information in support communications unless we specifically request that information for a supported purpose.
1.8 Cookies and Tracking Technologies
We use cookies and similar technologies to maintain sessions, authenticate users, remember preferences, secure accounts, analyze platform usage, route traffic, prevent abuse, and improve the Services.
Third-party traffic protection, CDN, proxy, analytics, or security providers may also use cookies, logs, or similar technologies as necessary to provide their services.
You may control cookie behavior through your browser settings. However, disabling certain cookies may affect the functionality, security, or availability of the Services.
2. HOW WE USE YOUR INFORMATION
We use the information we collect for the following purposes:
- To provision, operate, maintain, secure, and improve the Services
- To create and manage user accounts
- To authenticate users and enforce access controls
- To perform authorized security scans
- To generate, store, display, and manage Scan Results, alerts, findings, and reports
- To generate AI-assisted summaries of alert and finding information
- To provide dashboards, notifications, APIs, and customer-facing security insights
- To process payments, manage billing, and enforce subscription limits
- To communicate with you about your account, alerts, reports, service updates, support requests, and administrative notices
- To respond to support requests, inquiries, bug reports, and security reports
- To monitor platform performance, reliability, availability, abuse, and security events
- To route traffic, protect the Services, prevent denial-of-service attacks, and block malicious activity
- To detect, investigate, and prevent fraud, abuse, unauthorized access, malicious activity, or illegal activity
- To enforce our Terms of Service, acceptable use rules, and other applicable agreements
- To comply with applicable legal obligations
- To protect the rights, property, safety, and security of Noct, our customers, users, and third parties
We do not sell your Target Data or Scan Results.
We do not use your Target Data, Scan Results, alerts, AI summary inputs, or AI-generated summaries to train machine learning models, develop competing products, or create generalized datasets unrelated to providing the Services to you.
3. AUTHORIZED SCANNING AND CUSTOMER RESPONSIBILITY
The Services are intended to be used only for security scanning of assets that you own, control, administer, or are otherwise legally authorized to test.
By submitting Target Data or initiating scans, you represent that you have all necessary rights, permissions, and authority to scan those assets and to provide related data to Noct.
Noct may suspend, limit, or terminate scanning activity if we believe the Services are being used to scan unauthorized assets, violate law, violate our Terms of Service, create security risks, or harm third parties.
4. LEGAL BASIS FOR PROCESSING, WHERE APPLICABLE
Where required by applicable law, including the GDPR, UK GDPR, and similar frameworks, our processing of personal data is based on one or more of the following legal grounds:
- Performance of a contract: Processing necessary to provide the Services you requested
- Legitimate interests: Processing necessary for our legitimate business interests, including platform security, fraud prevention, service improvement, customer support, and product operation, where those interests are not overridden by your rights
- Legal obligation: Processing necessary to comply with applicable law, legal process, or regulatory requirements
- Consent: Where we rely on consent, you may withdraw that consent at any time without affecting the lawfulness of processing before withdrawal
For business customers, Noct may act as a service provider, processor, or similar role with respect to certain customer-submitted data, depending on the applicable privacy law and the nature of the data.
5. DATA STORAGE AND SECURITY
5.1 Customer Security Data Location and Local Processing
Customer security data, including Target Data, Scan Results, alerts, reports, AI summary inputs, and AI-generated summaries, is stored and processed within the United States on Noct-controlled systems.
Noct does not transfer Target Data, Scan Results, alerts, reports, AI summary inputs, or AI-generated summaries outside the United States.
Noct does not use third-party AI providers, third-party analytics providers, third-party logging providers, third-party monitoring providers, third-party support providers, or third-party infrastructure providers to store, process, analyze, monitor, log, host, or manage Target Data, Scan Results, alerts, reports, AI summary inputs, or AI-generated summaries.
5.2 Operational Vendor Processing
Noct may use limited third-party service providers for operational business functions, including email, billing, customer support, traffic protection, CDN/proxy services, firewall services, anti-abuse services, and basic request logging.
These providers may process limited account, billing, support, usage, traffic, request, device, or technical data as necessary to provide those services.
These providers do not receive Target Data, Scan Results, alert contents, reports, AI summary inputs, or AI-generated summaries unless expressly stated in this Privacy Policy, directed by you, or required by law.
5.3 Encryption
Data transmitted to and from the Services is encrypted in transit using TLS or comparable encryption protocols.
Data stored on our systems is encrypted at rest using industry-standard encryption methods, such as AES-256 or equivalent protections, where technically feasible and appropriate.
5.4 Access Controls
Access to customer data is governed by role-based access controls. Only authorized personnel with a legitimate operational, security, support, or compliance need may access customer data.
We maintain audit logs or security logs for sensitive systems where appropriate.
5.5 Sensitive Data Handling
Sensitive infrastructure data, including credentials, secrets, tokens, or similar sensitive values processed as part of a scan, is handled with additional safeguards.
Where technically feasible, such sensitive data is decrypted only in memory during execution and is not persisted to storage in plaintext.
You should not submit credentials, secrets, private keys, or sensitive tokens to the Services unless the Services specifically request them for a supported scanning or integration feature.
5.6 Security Practices
We maintain administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction.
These safeguards may include encryption, access controls, logging, internal security reviews, vulnerability remediation, infrastructure hardening, and monitoring for suspicious activity.
However, no system is completely secure, and we cannot guarantee that unauthorized access, security incidents, or data loss will never occur.
6. DATA RETENTION
We retain information for as long as reasonably necessary to provide the Services, maintain your account, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and protect the security of the Services.
6.1 Account Data
We retain account information for as long as your account remains active or as necessary to provide the Services.
6.2 Target Data and Scan Results
We retain Target Data, Scan Results, alerts, findings, reports, and related AI-generated summaries for as long as your account is active or as otherwise needed to provide the Services.
If you terminate your account, we will delete or anonymize Target Data and Scan Results within 90 days of account closure, unless retention is required by law, security obligations, backup processes, dispute resolution, fraud prevention, or enforcement of our agreements.
6.3 Billing Records
Billing, invoice, tax, and payment-related records may be retained for the period required by accounting, tax, legal, or compliance obligations.
Billing providers may retain payment-related records according to their own legal, fraud-prevention, and compliance obligations.
6.4 Logs and Usage Data
Usage, technical, audit, request, traffic, and security logs may be retained for security, fraud prevention, debugging, compliance, and operational purposes.
Third-party traffic protection, CDN, proxy, firewall, billing, email, or support providers may retain limited operational data according to their own retention policies.
Usage and technical data may be retained in aggregated, de-identified, or anonymized form after account closure.
6.5 Backups
Deleted data may persist for a limited period in encrypted backups or disaster recovery systems before being overwritten or deleted according to our backup retention practices.
7. SHARING AND DISCLOSURE OF INFORMATION
We do not sell, rent, or trade your personal information, Target Data, or Scan Results to third parties.
We may share information in the following limited circumstances:
7.1 Limited Service Providers
Noct may use limited third-party service providers for operational business functions, including email, billing, customer support, traffic protection, CDN/proxy services, firewall services, anti-abuse services, and basic request logging.
These providers may process limited information necessary to provide their services, such as account contact information, billing information, payment status, support communications, IP addresses, device information, request metadata, traffic logs, firewall events, and similar operational data.
Noct does not provide these service providers with Target Data, Scan Results, alert contents, reports, AI summary inputs, or AI-generated summaries unless expressly stated in this Privacy Policy, directed by you, or required by law.
7.2 Customer Security Data
Noct does not use third-party vendors to store, process, analyze, monitor, log, host, or manage Target Data, Scan Results, alerts, reports, AI summary inputs, or AI-generated summaries.
Customer security data is handled on Noct-controlled systems within the United States.
7.3 Billing and Payment Handling
Billing and payment information may be processed by third-party billing or payment service providers as necessary to manage subscriptions, process payments, prevent fraud, issue invoices, and complete transactions.
Noct does not provide Target Data, Scan Results, alerts, reports, AI summary inputs, or AI-generated summaries to billing or payment providers.
7.4 Support and Communications
Support and communication providers may process communications you send to us, including your email address, contact details, support messages, and related metadata.
You should not include credentials, secrets, private keys, or unnecessary sensitive infrastructure information in support communications.
7.5 Traffic Protection, CDN, Proxy, Firewall, and Logging Providers
Noct may use providers such as Cloudflare or similar services to route traffic, protect the Services, prevent abuse, improve availability, provide firewall functionality, and maintain basic request logs.
These providers may process IP addresses, device information, request headers, URLs requested, timestamps, firewall events, bot-detection signals, and other traffic or request metadata.
7.6 Business Transfers
If Noct undergoes a merger, acquisition, financing, reorganization, asset sale, bankruptcy, or similar transaction, customer data may be transferred to an acquiring or successor entity.
Where required, we will provide notice before customer data becomes subject to a materially different privacy policy.
7.7 Legal Requirements
We may disclose information if required to do so by law, regulation, subpoena, court order, legal process, governmental request, or similar obligation.
We may also disclose information where we believe disclosure is necessary to protect the rights, property, safety, or security of Noct, our customers, users, third parties, or the public.
7.8 Enforcement and Abuse Prevention
We may disclose information as necessary to enforce our Terms of Service, investigate potential violations, detect and prevent fraud, prevent unauthorized scanning, address security incidents, or protect against malicious activity.
7.9 Customer Instructions
We may share or disclose information at your direction, with your consent, or as necessary to provide features you request, such as exports, notifications, reports, or API access.
We will not disclose your Target Data or Scan Results to third parties except as described in this Privacy Policy, as directed by you, as necessary to provide the Services, or as required by law.
8. YOUR RIGHTS AND CHOICES
Depending on your jurisdiction, you may have certain rights regarding your personal data, including:
- Access: Request a copy of personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of personal data, subject to legal and operational retention obligations
- Portability: Request a machine-readable export of personal data
- Restriction: Request that we restrict certain processing activities
- Objection: Object to processing based on legitimate interests
- Withdrawal of consent: Withdraw consent where processing is based on consent
To exercise these rights, contact us at [email protected].
We will respond to verified requests within 30 days unless a different response period is required or permitted by applicable law. We may require information to verify your identity and authority before processing a request.
If you are located in the European Economic Area, United Kingdom, or Switzerland, you may have the right to lodge a complaint with your applicable data protection authority.
9. CALIFORNIA PRIVACY RIGHTS
If you are a California resident, you may have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including:
- The right to know what categories of personal information we collect, use, disclose, or share
- The right to request access to personal information
- The right to request deletion of personal information
- The right to request correction of inaccurate personal information
- The right to opt out of the sale or sharing of personal information
- The right to limit the use of sensitive personal information, where applicable
- The right not to be discriminated against for exercising privacy rights
We do not sell personal information.
We do not share personal information for cross-context behavioral advertising as that term is defined under California privacy law.
We may collect the following categories of personal information, depending on how you use the Services:
- Identifiers, such as name, email address, business name, IP address, account identifiers, and online identifiers
- Commercial information, such as subscription plan, billing status, invoices, payment status, and payment history
- Internet or network activity information, such as login activity, API usage, session data, browser information, device information, traffic metadata, request logs, firewall events, and pages viewed
- Professional or employment-related information, such as job title, business role, company name, and business contact details
- Customer-submitted infrastructure information, such as domains, hostnames, IP addresses, and related security scan targets
- Security and diagnostic information, such as scan results, alerts, findings, logs, and platform security events
- Inferences or summaries generated from scan findings, such as AI-assisted alert summaries or risk descriptions
- Communications information, such as support messages, email communications, and related metadata
To submit a California privacy request, contact us at [email protected].
10. CHILDREN'S PRIVACY
The Services are intended for business use by individuals who are at least 18 years old.
We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have collected personal information from an individual under 18, we will delete it promptly.
11. THIRD-PARTY LINKS AND SERVICES
The Services may contain links to third-party websites, documentation, integrations, or services.
We are not responsible for the privacy practices, security practices, or content of third-party services. This Privacy Policy does not apply to information collected by third parties.
We encourage you to review the privacy policies of any third-party services you access.
12. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices, Services, technology, legal obligations, or business operations.
When we make material changes, we will notify you by email, through the Services, or by posting a prominent notice before or when the changes become effective, as required by law.
The "Last Updated" date at the top of this Privacy Policy reflects the most recent revision.
Your continued use of the Services after an updated Privacy Policy becomes effective means that you acknowledge the updated Privacy Policy.
13. CONTACT US
If you have questions, concerns, or requests regarding this Privacy Policy or data practices, contact us:
Noct, LLC
Security: [email protected]
Support: [email protected]
Website: https://noct.gg