legal/privacy-policy.md
Effective date: 2026-02-22 · Last updated: 2026-02-22
This Privacy Policy describes how the Tirith project (“we”, “us”, “our”) handles information when you use Tirith software and purchase paid licenses.
Tirith is a local-first security tool. We collect the minimum data necessary to operate the paid service and process payments.
When you purchase a license, Paddle (our merchant of record) collects:
We do not store your payment details. Paddle handles all payment processing as the merchant of record.
We store:
If you enable remote audit log collection (Team plan feature), we receive:
We never receive raw commands, file contents, or unredacted data. All data is redacted locally before transmission.
If you use remote policy distribution, our server logs:
Our website may use privacy-respecting analytics. We do not use third-party tracking cookies.
We share data only with:
We do not sell your data. We do not share data with advertisers.
| Data | Retention |
|---|---|
| Payment records | As required by tax law (~7 years), managed by Paddle |
| License metadata | While active, deleted 90 days after cancellation |
| Remote audit logs | 90 days, then permanently deleted |
| Server access logs | 30 days |
| Support correspondence | 2 years after last contact |
You have the right to:
To exercise these rights, contact: privacy@tirith.sh
We will respond within 30 days.
If you are outside the United States, your data may be transferred to and processed in the United States where our servers are located.
Our Service is not directed to children under 16. We do not knowingly collect data from children.
We may update this policy from time to time. Material changes will be communicated via email. The “Last updated” date at the top reflects the most recent revision.
For privacy questions or to exercise your rights: