Last updated: 25 July 2026
RakshaGuard Limited is the data controller for the information described here. Company number 17021517, registered in England and Wales; registered office 5 Fritham Gardens, Bournemouth, BH8 0EL. ICO registration: registered (number available on request). Contact: contact@rakshaguard.com.
Your email address is the only personal information we ask you for. We do not collect your name, postal address, telephone number, job title or payment card details. There is no password to store — sign-in works by emailed link. Alongside your email we hold: one-time sign-in links (expire after 15 minutes, single use); sign-in sessions (expire after 14 days); licence records (which plan, expiry, scans used); and a Stripe payment reference. We do not use tracking cookies, analytics, or advertising identifiers, and our servers do not record visitor IP addresses.
The scan itself runs on your own machine; findings are written to a local file and are not uploaded anywhere unless you use the AI analysis. If you use the AI analysis, findings are sent to our analysis service and from there to Anthropic, which generates the written analysis. Findings describe cloud configuration — resource identifiers, settings, security states — rather than people, though some may include identity resource names (such as IAM role names) where those exist in your account. We do not retain findings after the analysis is returned.
The two systems are separate by design: the analysis service never sees account or licence data. The only link between them is your licence key — a signed token the analysis service verifies without looking anything up.
International transfer: Anthropic processes findings in the United States. The specific transfer safeguard (UK IDTA or SCC addendum) is being finalised; this notice will name it once confirmed.
Stripe (your email and the amount, to take payment); our email provider (your email and message contents, to deliver sign-in links and licence keys); Anthropic (scan findings, only if you use AI analysis); and our hosting provider (data at rest, as our infrastructure). We do not sell your data or share it for advertising.
Licence and payment records are kept for six years after the licence expires, as UK company law requires, then deleted automatically. Sign-in links and sessions are deleted once expired (15 minutes / 14 days). Encrypted daily backups are kept off-site for 90 days, after which deleted data ages out of them. You can ask us to delete your account at any time, except where we must keep a record of a transaction.
You can ask us to provide a copy of your data, correct it, delete it, restrict or object to its use, or provide it in a portable format. Write to contact@rakshaguard.com; we respond within one month. If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office at ico.org.uk or on 0303 123 1113.
We will post any changes here and update the date above.