ARMORIQ
// LEGAL

Privacy Policy.

ArmorIQ is committed to protecting your privacy and maintaining the highest standards of security, transparency, and trust. This Privacy Policy explains how we collect, use, store, and protect your information when you access our website, platform, and related services (“Services”).

// LAST UPDATED · 22 JUL 2026

1. Information We Collect

1.1 Information You Provide

  • Contact details: name, email address, phone number
  • Organization details: company name, domain, role
  • Account data: login information, profile details
  • Communications: support messages, emails, forms
  • Billing details: payment information (processed by secure third parties)

1.2 Information Collected Automatically

  • Device data: IP address, browser, operating system
  • Usage data: pages visited, features used, interaction logs
  • Cookies & identifiers: for authentication, analytics, and performance

1.3 AI / Model-Related Data

  • Inputs and outputs you send to our models
  • System-level logs for audit, security, and compliance
  • We do not use your data to train AI models without explicit permission.

1.4 Data From Our Client Tools

  • Our client-side products (ArmorClaude, ArmorCodex) transmit product-specific data to our backend when connected with an ArmorIQ API key.
  • See Section 6 (Product-Specific Data Flows) for the exact data types, purpose, and retention per product.

2. How We Use Your Information

  • Deliver, operate, and improve the ArmorIQ platform
  • Authenticate users and maintain account security
  • Detect misuse, verify intent, and enforce policies
  • Provide customer support and communicate updates
  • Analyze product performance to enhance reliability
  • Meet legal, regulatory, and compliance obligations
  • We never sell your personal data.

3. When We Share Your Information

  • Trusted service providers (cloud hosting, analytics, billing)
  • Security & compliance partners (logging, monitoring, encryption)
  • Legal authorities, if required by law or policy enforcement
  • All third parties follow strict confidentiality and data protection standards.

4. Data Security

  • Encryption in transit and at rest
  • Strong access controls and identity verification
  • Continuous monitoring and threat detection
  • Immutable, tamper-resistant audit logs
  • While no system is guaranteed to be fully secure, we continuously improve our defenses.

5. Data Retention

5.1 General Principle

  • We retain data only for as long as necessary to provide our Services, satisfy legal requirements, and enforce agreements.

5.2 Retention Windows

  • Account and billing records: life of the account plus 12 months after account closure
  • Support communications: 24 months
  • Website usage analytics and cookies: 12 months
  • Product-specific data (prompts, intent plans, tool calls, audit logs, observability traces): see Section 6, per-product retention
  • System security logs: 12 months
  • Paid plans may extend audit-log retention by contract. Refer to your order form.

5.3 Early Deletion

  • You may request early deletion of your account or data at any time by writing to license@armoriq.io.
  • We honor deletion requests within thirty (30) days, subject to any legal obligation to retain specific records.

6. Product-Specific Data Flows

6.1 Defined Terms

  • "Inputs" means prompts and intent plans you submit through the plugin.
  • "Tool-Call Records" means the parameters and results of tool calls the plugin observes on your behalf.
  • "Audit Logs" means the enforcement metadata for each tool call (which rule matched, whether the call was allowed, blocked, or held).
  • "Observability Traces" means the step-by-step execution traces of the plugin's enforcement decisions.

6.2 ArmorClaude: When Data Is Sent

  • ArmorClaude transmits data to the ArmorIQ backend when connected with an ArmorIQ API key.
  • The data types below describe what is sent while connected.

6.3 ArmorClaude: What We Collect

  • Captured prompts and intent plans: the plan Claude declares before it acts, and the associated prompt content.
  • Tool-call parameters and results: the arguments and responses of each tool call the plugin observes, evaluated against the registered plan.
  • Per-tool audit logs: metadata about every tool call, including whether it was allowed, blocked, or held for approval, and the policy rule that decided the outcome.
  • Observability execution traces: step-by-step traces of the plugin's enforcement decisions. Observability is enabled by default.
  • Environment metadata: plugin version, host OS name and version, Claude Code version, and a stable per-installation identifier. No file paths, source code, or working-directory contents outside the intent plan and tool calls are collected.

6.4 ArmorClaude: Why We Collect It

  • Policy enforcement across intent plans and stored rules.
  • Audit and compliance records for AI agent activity (supports internal governance and standards such as SOC 2 and ISO 27001).
  • CSRG cryptographic proofs binding each tool call to its declared plan.
  • Dashboard visibility for your workspace members.
  • Aggregated, non-identifying metrics for product improvement. We do not use Inputs, Tool-Call Records, Audit Logs, or Observability Traces to train our models, unless: (1) they are flagged for security review of the ArmorIQ platform itself, (2) you explicitly report them to us in a support request, or (3) you have explicitly agreed to their use.

6.5 ArmorClaude: Retention

  • Captured prompts and intent plans: 12 months
  • Tool-call parameters and results: 12 months
  • Per-tool audit logs: 12 months
  • Observability execution traces: 12 months
  • Environment metadata: 12 months

6.6 ArmorClaude: How to Opt Out

  • To disable observability while connected, set disable_observability: true in the plugin config or run /armor settings inside Claude Code and toggle observability off.
  • Captured prompts, intent plans, tool-call parameters and results, and per-tool audit logs continue to be sent (these are required for policy enforcement and audit), but finer-grained execution traces are not sent.

6.7 ArmorCodex: When Data Is Sent

  • ArmorCodex transmits data to the ArmorIQ backend when a user invokes its policy_read, policy_update, or register_intent_plan tools from ChatGPT or Codex.
  • Read-only reads that hit only public policy metadata do not transmit user content.

6.8 ArmorCodex: What We Collect

  • Policy read requests: the identifier of the policy or workspace queried.
  • Policy update requests: the natural-language rule text or template name submitted, plus the workspace scope.
  • Intent plans: the plan the user registered before running a tool call.
  • Per-request audit logs: which tool was called, when, and by which authenticated identity.
  • Environment metadata: tool version and a stable per-caller identifier.

6.9 ArmorCodex: Why We Collect It

  • Same as Section 6.4: policy enforcement, audit, compliance, dashboard visibility, and aggregated product improvement.

6.10 ArmorCodex: Retention

  • Policy read requests: 12 months
  • Policy update requests and stored rules: lifetime of the workspace (rules are the workspace's own configuration)
  • Intent plans: 12 months
  • Per-request audit logs: 12 months
  • Environment metadata: 12 months

6.11 ArmorCodex: How to Opt Out

  • ArmorCodex operates as a governance layer, so its baseline function requires backend contact.
  • To limit data sent, do not register intent plans and do not invoke policy_update.
  • You can also revoke access to the ArmorCodex plugin from within ChatGPT or Codex to stop all data flow.

6.12 Access Controls for Product-Specific Data

  • Only members of your ArmorIQ workspace can view your workspace's Inputs, Tool-Call Records, Audit Logs, and Observability Traces in the ArmorIQ dashboard.
  • ArmorIQ personnel access this data only for support requests you initiate, security investigations, or when required by law.
  • We do not sell or share this data with third parties.

6.13 Subprocessors

  • ArmorIQ uses the following subprocessors to deliver the Services described in this Section 6:
  • Google Cloud Platform (application hosting, database, storage, logging)
  • Google Workspace (transactional email via Gmail SMTP)
  • Both are operated by Google LLC. Subprocessors process ArmorIQ data only under Google's Data Processing Addendum, aligned with the commitments in this policy.
  • An up-to-date list of subprocessors is maintained on request. Send subprocessor inquiries to license@armoriq.io.

6.14 Enterprise Data Processing Addendum

  • Enterprise customers may request a Data Processing Addendum (DPA) with additional GDPR/CCPA processing terms and audit rights by writing to license@armoriq.io.

7. Your Rights

  • Access the data we hold about you
  • Request corrections or updates
  • Request deletion (the right to be forgotten)
  • Object to or restrict processing
  • Export your data
  • Send privacy requests to license@armoriq.io. We respond within thirty (30) days.

8. Cookies & Tracking Technologies

  • Used for login & authentication
  • Session management
  • Usage analytics
  • Performance monitoring
  • You can control cookies via your browser settings.

9. Children's Privacy

  • Our Services are not designed for or directed toward individuals under the age of 16, and we do not knowingly collect data from minors.

10. International Data Transfers

  • We may process or store data in regions where our cloud infrastructure operates.
  • All transfers include GDPR-compliant safeguards, standard contractual clauses (as applicable), and strong encryption practices.

11. Updates to This Policy

  • We may update this Privacy Policy to reflect product, legal, or regulatory changes.
  • We will notify you of material updates via email or in-product notifications.

12. Contact Us

  • ArmorIQ Technologies Pvt. Ltd.
  • Website: www.armoriq.ai
  • Privacy inquiries: license@armoriq.io
  • General inquiries: through the Book a Demo page.