**Privacy Policy**
_Last updated: May 28, 2025_
1. **Introduction**
RedShield (“we”, “us”, “our”) is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your choices.
2. **Information We Collect**
- **Personal Data:** Email address, name, account credentials.
- **Usage Data:** Device identifiers, IP address, crash logs, feature usage.
- **Third-Party Data:** Breach information from HaveIBeenPwned, payment details via Stripe (only last-4 and subscription status, no raw card numbers).
3. **How We Use Your Data**
- To create and manage your account.
- To send you security alerts about leaked credentials.
- To process payments and manage subscriptions.
- To improve and troubleshoot our service.
4. **VPN Service**
If you choose to enable our in-app VPN feature:
- **What it does:**
Routes your network traffic through our secure proxy to help protect you on untrusted Wi-Fi and mask your IP.
- **Data collected:**
We do **not** log your DNS queries, browsing history, or transferred content. We only collect:
1. Timestamp of connection start/stop
2. Amount of data transferred (bytes)
3. Your source IP (to establish the tunnel)
- **Why we collect it:**
- To monitor service health and enforce fair-use.
- To troubleshoot connection issues.
- **Retention & deletion:**
Logs are retained for **30 days** then automatically purged. You can request deletion of your VPN logs at any time via your account settings or by emailing privacy@redshield.app.
- **Your choice:**
Enabling VPN is 100% optional. You can turn it off in settings at any time without impacting other features.
5. **Sharing & Disclosure**
We never sell your data. We share it only with:
- Stripe (for billing)
- HIBP (read-only breach lookups)
- Google Cloud (for hosting; data stored in your region)
6. **Security**
All traffic between your device and our servers is encrypted with TLS. Our VPN tunnels use modern cipher suites (AES-256, ChaCha20).
7. **Your Rights**
- **Access:** Request a copy of your data.
- **Deletion:** Request account or log-data deletion (see section 4).
- **Correction:** Ask us to correct inaccurate data.
8. **Children**
Our service is not intended for anyone under 13. We do not knowingly collect personal data from children.
9. **Changes to This Policy**
We may update this policy. We’ll post a notice on our website and bump the “Last updated” date.
10. **Contact Us**
privacy@redshield.app
https://redshield.app/contact
''';
