Legal

Privacy Notice

Version 2026-08-02 · effective 2 August 2026

BreachIQ is a training environment. It stores your account, the decisions you make inside simulated incidents, and the records needed to score those decisions and improve the product. This notice states plainly what is held, why, for how long, and what you can ask us to do about it.

This notice is a product-specific starting point prepared for the founder beta. It is accurate to how the product works today and should be reviewed by your own legal adviser before wider release.

Who is responsible

BreachIQ operates this service and decides how personal data here is used — in data protection terms, the controller. Reach us at contact@breachiq.ai.

What we collect, and why

  • Account data — email address, name, and optionally your role, experience level and organisation. Used to give you an account and to tailor difficulty. Lawful basis: performance of our agreement with you.
  • Simulation data — the free-text decisions you write during a run, the resulting scores, debriefs and skill map. Used to run the product and show your progress. Lawful basis: performance of our agreement with you.
  • Ratings and feedback — realism and enjoyment ratings, comments, and anything you send through the feedback widget. Used to judge whether the product works. Lawful basis: legitimate interest in improving it.
  • Pricing interest — the email address, price band and comments you submit on the pricing page, plus the version of these documents you accepted. Lawful basis: your consent, given on that form.
  • AI telemetry — for each AI turn we record the model used, timings, token counts, cost and safety outcome, linked to your session. Used for reliability, safety review and cost control. Lawful basis: legitimate interest in operating the service safely.
  • Technical logs — standard request and error records generated by our hosting provider, used to keep the service up and to investigate abuse.

We do not collect payment details anywhere on BreachIQ today, and we do not run advertising or third-party tracking cookies. The only browser storage we use is what is needed to keep you signed in.

Do not put real incident data here

Scenarios are synthetic. Please do not enter real customer names, real hostnames, credentials, or genuine confidential incident detail into a run. If you do, it is stored like any other free text you write, and you can ask us to delete it.

How long we keep it

  • Account, run history, scores and skill map: for as long as your account exists.
  • Ratings, product feedback and pricing interest: kept for the founder beta, and deleted when you delete your account or ask us to remove them.
  • AI telemetry: the link to your account is removed automatically after 90 days by a daily scheduled job. The de-identified record remains for reliability and cost analysis.
  • Safety records: the link to your account is removed automatically after 12 months by the same job. The de-identified record remains for abuse review.
  • Technical logs: kept by our hosting provider on their standard short retention.

When you delete your account, your profile, runs, decisions, debriefs, skill map, feedback and pricing interest are deleted immediately, and your sign-in record is removed. AI and safety telemetry is not deleted but is stripped of any link to you at the same moment, so it no longer identifies you. We keep it on the basis of our legitimate interest in operating the service safely and reliably.

Who processes data for us

We use a small number of providers, each acting on our instructions:

  • Hosting, database and authentication — application hosting and the managed database that stores your account and run history.
  • AI model providers — reached through a single gateway, used to generate incident turns and to score decisions. Your written decisions are sent to them to produce a response.
  • Email delivery — used to send sign-in, confirmation and beta communications.

Some of these providers operate outside the European Economic Area. Where that is the case, transfers rely on the European Commission's standard contractual clauses. A current named list of sub-processors is available on request from contact@breachiq.ai.

Your rights

If you are in the UK or the EEA you can ask for access to your data, correction, deletion, a portable copy, restriction of processing, or object to processing we base on legitimate interest. Where we rely on consent, you can withdraw it at any time without affecting what happened before.

Access and portability, and erasure, are self-service: sign in and use Download my data or Delete my account on your profile page. The export is a single JSON file containing your profile, runs, decisions, debriefs, skill map and feedback.

For correction, restriction, objection, or anything the self-service actions do not cover, email contact@breachiq.ai and we will action the request within 30 days. You also have the right to complain to your local data protection authority.

Security and reporting a problem

Access to your data is restricted per account at the database level, traffic is encrypted in transit, and operator access is limited to named administrators. No system is perfect — if you find a security issue, report it to support@breachiq.ai with enough detail to reproduce it. We aim to acknowledge within two working days and will not pursue good-faith research.

Changes to this notice

If we change how data is used in a way that matters, we will update the version at the top of this page and tell beta participants by email. See also the Terms of Service.