Privacy Policy

Effective Date: March 29, 2026
Last Updated: May 7, 2026

This Privacy Policy describes how Noct, LLC ("Noct," "we," "us," or "our") collects, uses, stores, protects, and discloses information obtained through our website located at https://noct.gg, our security scanning platform, dashboards, APIs, alerts, reports, and related services or communications (collectively, the "Services").

This Privacy Policy is intended to explain our data practices. Your use of the Services may also be governed by our Terms of Service, subscription terms, order forms, or other applicable agreements.

If you access or use the Services on behalf of a business, organization, or other entity, "you" refers to that entity, and you represent that you have authority to use the Services on its behalf.

1. INFORMATION WE COLLECT

1.1 Account and Registration Information

When you create an account, register for the Services, or communicate with us, we may collect information such as your name, business name, email address, job title, password or authentication information, and other account-related information.

For business customers, this may also include company size, industry, role, and other organizational details.

1.2 Billing and Subscription Information

If you purchase paid Services, we collect information necessary to manage your subscription, billing status, plan limits, usage tier, invoices, payment status, transaction history, and related billing records.

Billing and payment information may be processed by third-party billing or payment service providers. These providers may receive information necessary to process payments, manage invoices, prevent fraud, and complete transactions.

Noct does not provide Target Data, Scan Results, alerts, reports, AI summary inputs, or AI-generated summaries to billing or payment providers.

1.3 Infrastructure and Target Data

To perform security scanning, you may provide information about servers, IP addresses, hostnames, domains, subdomains, applications, cloud assets, endpoints, or other infrastructure assets that you represent you are authorized to scan ("Target Data").

We treat Target Data as confidential customer data and use it only to provide, secure, support, and improve the Services, enforce our agreements, comply with law, and protect Noct, our customers, and third parties.

You are responsible for ensuring that you have the necessary rights, permissions, and authority to submit Target Data to the Services and to authorize scans of such assets.

1.4 Scan Results, Alerts, and Security Findings

We generate and store data resulting from authorized scans of your submitted assets, including detected services, open ports, software version information, configuration details, security alerts, risk indicators, vulnerability information, remediation context, alert status, timestamps, and related metadata ("Scan Results").

Scan Results are associated with your account and treated as confidential customer data.

1.5 AI-Assisted Alert Summaries

The Services may use AI-assisted systems to summarize alert information, scan findings, remediation context, and other security-related information for display within your dashboard, reports, or alerts.

Noct operates these AI-assisted systems locally on Noct-controlled infrastructure within the United States. Customer security data is not sent to third-party AI providers.

We do not use your Target Data, Scan Results, alerts, AI inputs, or AI-generated summaries to train machine learning models or develop generalized AI models.

The AI summarization process is designed so that direct asset identifiers, such as IP addresses, domains, hostnames, and similar infrastructure identifiers, are excluded from the data provided to the AI system unless technically necessary to generate the requested summary.

AI-generated summaries may be stored with the related alert, scan result, report, or customer account so they can be displayed in the Services.

AI-generated summaries are provided for convenience and readability. They may not replace the underlying scan data, technical findings, or your own security review.

1.6 Usage, Traffic, and Technical Data

We automatically collect certain technical and usage data when you interact with the Services, including IP addresses, browser type and version, device information, operating system, referring URLs, pages viewed, features used, timestamps, session identifiers, authentication events, API usage, error logs, security logs, and traffic metadata.

Some traffic, request, CDN, firewall, proxy, anti-abuse, or security metadata may be processed by third-party service providers, including Cloudflare or similar providers, to protect the Services, route traffic, prevent abuse, and maintain availability.

We use usage, traffic, and technical data for platform security, abuse prevention, authentication, debugging, performance monitoring, service reliability, analytics, and service improvement.

1.7 Communications and Support

If you contact us by email, through our website, through support channels, or through in-platform messaging, we may retain those communications and any information you provide within them.

Support and communication data may be processed by third-party email, communication, or customer support service providers as necessary to receive, respond to, organize, and manage support requests.

You should not include credentials, secrets, private keys, or highly sensitive infrastructure information in support communications unless we specifically request that information for a supported purpose.

1.8 Cookies and Tracking Technologies

We use cookies and similar technologies to maintain sessions, authenticate users, remember preferences, secure accounts, analyze platform usage, route traffic, prevent abuse, and improve the Services.

Third-party traffic protection, CDN, proxy, analytics, or security providers may also use cookies, logs, or similar technologies as necessary to provide their services.

You may control cookie behavior through your browser settings. However, disabling certain cookies may affect the functionality, security, or availability of the Services.

2. HOW WE USE YOUR INFORMATION

We use the information we collect for the following purposes:

We do not sell your Target Data or Scan Results.

We do not use your Target Data, Scan Results, alerts, AI summary inputs, or AI-generated summaries to train machine learning models, develop competing products, or create generalized datasets unrelated to providing the Services to you.

3. AUTHORIZED SCANNING AND CUSTOMER RESPONSIBILITY

The Services are intended to be used only for security scanning of assets that you own, control, administer, or are otherwise legally authorized to test.

By submitting Target Data or initiating scans, you represent that you have all necessary rights, permissions, and authority to scan those assets and to provide related data to Noct.

Noct may suspend, limit, or terminate scanning activity if we believe the Services are being used to scan unauthorized assets, violate law, violate our Terms of Service, create security risks, or harm third parties.

4. LEGAL BASIS FOR PROCESSING, WHERE APPLICABLE

Where required by applicable law, including the GDPR, UK GDPR, and similar frameworks, our processing of personal data is based on one or more of the following legal grounds:

For business customers, Noct may act as a service provider, processor, or similar role with respect to certain customer-submitted data, depending on the applicable privacy law and the nature of the data.

5. DATA STORAGE AND SECURITY

5.1 Customer Security Data Location and Local Processing

Customer security data, including Target Data, Scan Results, alerts, reports, AI summary inputs, and AI-generated summaries, is stored and processed within the United States on Noct-controlled systems.

Noct does not transfer Target Data, Scan Results, alerts, reports, AI summary inputs, or AI-generated summaries outside the United States.

Noct does not use third-party AI providers, third-party analytics providers, third-party logging providers, third-party monitoring providers, third-party support providers, or third-party infrastructure providers to store, process, analyze, monitor, log, host, or manage Target Data, Scan Results, alerts, reports, AI summary inputs, or AI-generated summaries.

5.2 Operational Vendor Processing

Noct may use limited third-party service providers for operational business functions, including email, billing, customer support, traffic protection, CDN/proxy services, firewall services, anti-abuse services, and basic request logging.

These providers may process limited account, billing, support, usage, traffic, request, device, or technical data as necessary to provide those services.

These providers do not receive Target Data, Scan Results, alert contents, reports, AI summary inputs, or AI-generated summaries unless expressly stated in this Privacy Policy, directed by you, or required by law.

5.3 Encryption

Data transmitted to and from the Services is encrypted in transit using TLS or comparable encryption protocols.

Data stored on our systems is encrypted at rest using industry-standard encryption methods, such as AES-256 or equivalent protections, where technically feasible and appropriate.

5.4 Access Controls

Access to customer data is governed by role-based access controls. Only authorized personnel with a legitimate operational, security, support, or compliance need may access customer data.

We maintain audit logs or security logs for sensitive systems where appropriate.

5.5 Sensitive Data Handling

Sensitive infrastructure data, including credentials, secrets, tokens, or similar sensitive values processed as part of a scan, is handled with additional safeguards.

Where technically feasible, such sensitive data is decrypted only in memory during execution and is not persisted to storage in plaintext.

You should not submit credentials, secrets, private keys, or sensitive tokens to the Services unless the Services specifically request them for a supported scanning or integration feature.

5.6 Security Practices

We maintain administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction.

These safeguards may include encryption, access controls, logging, internal security reviews, vulnerability remediation, infrastructure hardening, and monitoring for suspicious activity.

However, no system is completely secure, and we cannot guarantee that unauthorized access, security incidents, or data loss will never occur.

6. DATA RETENTION

We retain information for as long as reasonably necessary to provide the Services, maintain your account, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and protect the security of the Services.

6.1 Account Data

We retain account information for as long as your account remains active or as necessary to provide the Services.

6.2 Target Data and Scan Results

We retain Target Data, Scan Results, alerts, findings, reports, and related AI-generated summaries for as long as your account is active or as otherwise needed to provide the Services.

If you terminate your account, we will delete or anonymize Target Data and Scan Results within 90 days of account closure, unless retention is required by law, security obligations, backup processes, dispute resolution, fraud prevention, or enforcement of our agreements.

6.3 Billing Records

Billing, invoice, tax, and payment-related records may be retained for the period required by accounting, tax, legal, or compliance obligations.

Billing providers may retain payment-related records according to their own legal, fraud-prevention, and compliance obligations.

6.4 Logs and Usage Data

Usage, technical, audit, request, traffic, and security logs may be retained for security, fraud prevention, debugging, compliance, and operational purposes.

Third-party traffic protection, CDN, proxy, firewall, billing, email, or support providers may retain limited operational data according to their own retention policies.

Usage and technical data may be retained in aggregated, de-identified, or anonymized form after account closure.

6.5 Backups

Deleted data may persist for a limited period in encrypted backups or disaster recovery systems before being overwritten or deleted according to our backup retention practices.

7. SHARING AND DISCLOSURE OF INFORMATION

We do not sell, rent, or trade your personal information, Target Data, or Scan Results to third parties.

We may share information in the following limited circumstances:

7.1 Limited Service Providers

Noct may use limited third-party service providers for operational business functions, including email, billing, customer support, traffic protection, CDN/proxy services, firewall services, anti-abuse services, and basic request logging.

These providers may process limited information necessary to provide their services, such as account contact information, billing information, payment status, support communications, IP addresses, device information, request metadata, traffic logs, firewall events, and similar operational data.

Noct does not provide these service providers with Target Data, Scan Results, alert contents, reports, AI summary inputs, or AI-generated summaries unless expressly stated in this Privacy Policy, directed by you, or required by law.

7.2 Customer Security Data

Noct does not use third-party vendors to store, process, analyze, monitor, log, host, or manage Target Data, Scan Results, alerts, reports, AI summary inputs, or AI-generated summaries.

Customer security data is handled on Noct-controlled systems within the United States.

7.3 Billing and Payment Handling

Billing and payment information may be processed by third-party billing or payment service providers as necessary to manage subscriptions, process payments, prevent fraud, issue invoices, and complete transactions.

Noct does not provide Target Data, Scan Results, alerts, reports, AI summary inputs, or AI-generated summaries to billing or payment providers.

7.4 Support and Communications

Support and communication providers may process communications you send to us, including your email address, contact details, support messages, and related metadata.

You should not include credentials, secrets, private keys, or unnecessary sensitive infrastructure information in support communications.

7.5 Traffic Protection, CDN, Proxy, Firewall, and Logging Providers

Noct may use providers such as Cloudflare or similar services to route traffic, protect the Services, prevent abuse, improve availability, provide firewall functionality, and maintain basic request logs.

These providers may process IP addresses, device information, request headers, URLs requested, timestamps, firewall events, bot-detection signals, and other traffic or request metadata.

7.6 Business Transfers

If Noct undergoes a merger, acquisition, financing, reorganization, asset sale, bankruptcy, or similar transaction, customer data may be transferred to an acquiring or successor entity.

Where required, we will provide notice before customer data becomes subject to a materially different privacy policy.

7.7 Legal Requirements

We may disclose information if required to do so by law, regulation, subpoena, court order, legal process, governmental request, or similar obligation.

We may also disclose information where we believe disclosure is necessary to protect the rights, property, safety, or security of Noct, our customers, users, third parties, or the public.

7.8 Enforcement and Abuse Prevention

We may disclose information as necessary to enforce our Terms of Service, investigate potential violations, detect and prevent fraud, prevent unauthorized scanning, address security incidents, or protect against malicious activity.

7.9 Customer Instructions

We may share or disclose information at your direction, with your consent, or as necessary to provide features you request, such as exports, notifications, reports, or API access.

We will not disclose your Target Data or Scan Results to third parties except as described in this Privacy Policy, as directed by you, as necessary to provide the Services, or as required by law.

8. YOUR RIGHTS AND CHOICES

Depending on your jurisdiction, you may have certain rights regarding your personal data, including:

To exercise these rights, contact us at [email protected].

We will respond to verified requests within 30 days unless a different response period is required or permitted by applicable law. We may require information to verify your identity and authority before processing a request.

If you are located in the European Economic Area, United Kingdom, or Switzerland, you may have the right to lodge a complaint with your applicable data protection authority.

9. CALIFORNIA PRIVACY RIGHTS

If you are a California resident, you may have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, including:

We do not sell personal information.

We do not share personal information for cross-context behavioral advertising as that term is defined under California privacy law.

We may collect the following categories of personal information, depending on how you use the Services:

To submit a California privacy request, contact us at [email protected].

10. CHILDREN'S PRIVACY

The Services are intended for business use by individuals who are at least 18 years old.

We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have collected personal information from an individual under 18, we will delete it promptly.

11. THIRD-PARTY LINKS AND SERVICES

The Services may contain links to third-party websites, documentation, integrations, or services.

We are not responsible for the privacy practices, security practices, or content of third-party services. This Privacy Policy does not apply to information collected by third parties.

We encourage you to review the privacy policies of any third-party services you access.

12. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time to reflect changes in our practices, Services, technology, legal obligations, or business operations.

When we make material changes, we will notify you by email, through the Services, or by posting a prominent notice before or when the changes become effective, as required by law.

The "Last Updated" date at the top of this Privacy Policy reflects the most recent revision.

Your continued use of the Services after an updated Privacy Policy becomes effective means that you acknowledge the updated Privacy Policy.

13. CONTACT US

If you have questions, concerns, or requests regarding this Privacy Policy or data practices, contact us:

Noct, LLC
Security: [email protected]
Support: [email protected]
Website: https://noct.gg