Legal

Privacy Policy

Last updated: July 9, 2026

This Privacy Policy explains how ShadowCanopy collects, uses, stores, shares, and protects information when you use the website, dashboard, API, command-line agent, package-manager wrappers, AI tool integrations, security feeds, and related services.

ShadowCanopy is operated from Mississippi, United States. This Privacy Policy is intended to address Mississippi, U.S. federal, U.S. state, and international privacy expectations for users of the service.

1. Information We Collect

ShadowCanopy collects information needed to operate a software supply-chain security service.

Account Information

We may collect:

  • Name.
  • Email address.
  • Organization or team name.
  • Login provider identifiers.
  • Role, permissions, and account settings.
  • Billing or plan information if paid plans are used.
  • Communications, support requests, security reports, and consent or preference records.

Agent and Token Information

We may collect:

  • Agent token metadata.
  • Device or agent identifiers.
  • Agent version.
  • Operating system and architecture.
  • Toolchain information reported by scanopy doctor.
  • Policy settings, such as offline mode.
  • Authentication and token usage events.

Package and Dependency Information

We may collect:

  • Package ecosystem.
  • Package name.
  • Package version.
  • Requested install command metadata.
  • Package artifact URL or registry metadata.
  • Lockfile package references.
  • Scan status, verdicts, findings, confidence scores, alternatives, and override decisions.
  • Artifact integrity hashes where supported.

Logs and Usage Data

We may collect:

  • IP address.
  • Timestamp.
  • User agent.
  • API route or dashboard page accessed.
  • Scan request and response metadata.
  • Error logs.
  • Audit log events.
  • Organization and role activity.
  • Feature usage and quota usage.
  • Approximate location inferred from IP address.
  • Cookie, session, and device identifiers.

Optional or User-Submitted Content

Depending on how you use the service, you may submit:

  • Lockfiles.
  • Package manifests.
  • Build metadata.
  • Review notes.
  • Support messages.
  • Security reports.
  • Feedback.

ShadowCanopy should not be used to submit secrets, private keys, passwords, production credentials, or unrelated sensitive personal information.

2. Information We Do Not Intend To Collect

ShadowCanopy does not intend to collect source code unless a user explicitly submits files, lockfiles, manifests, or support materials that contain code or code-like content.

ShadowCanopy does not need environment variables, SSH keys, local credentials, or private source repositories to perform ordinary package checks.

If local integrations or logs accidentally include sensitive information, contact ShadowCanopy so it can be reviewed and removed where appropriate.

3. How We Use Information

ShadowCanopy uses collected information to:

  • Provide package scanning, verdicts, and install-time enforcement.
  • Authenticate users, agents, tokens, and organizations.
  • Maintain allow-lists, deny-lists, scan caches, and security feeds.
  • Verify artifact integrity where supported.
  • Provide dashboards, logs, alerts, reports, and review workflows.
  • Support AI tool integration and policy enforcement.
  • Prevent abuse, fraud, malware distribution, and unauthorized access.
  • Debug, secure, monitor, and improve the service.
  • Provide support and respond to user requests.
  • Comply with legal, security, and contractual obligations.

Where laws such as the EU GDPR or UK GDPR apply, ShadowCanopy relies on one or more lawful bases for processing, including performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, consent where required, and protection of vital interests in limited security or abuse situations.

4. AI-Assisted Analysis

ShadowCanopy may use automated systems, static analysis, behavioral analysis, advisory data, and AI-assisted review to classify packages.

AI-assisted analysis may process package metadata, package contents, install behavior, findings, and related scan data.

AI output is not a guarantee that a package is safe or malicious. Critical findings may require human review or policy-based blocking.

5. Local Agent Behavior

The ShadowCanopy agent runs on user-controlled systems.

Depending on configuration, the agent may:

  • Store local configuration and token data.
  • Cache scan verdicts.
  • Run a local proxy.
  • Rewrite package-manager registry configuration.
  • Create package-manager shims.
  • Configure AI coding tool rules or hooks.
  • Log local diagnostic information.

Users are responsible for reviewing local files, shell configuration, AI tool configuration, Docker images, CI runners, and build logs before installing or deploying the agent.

6. Sharing Information

ShadowCanopy may share information with:

  • Service providers that host, secure, monitor, or operate the service.
  • Payment processors for billing.
  • Identity providers for authentication.
  • Package registries and advisory sources as needed to retrieve metadata or artifacts.
  • Security researchers or review teams where needed to investigate package risk.
  • Legal, regulatory, or law enforcement entities where required by law.
  • Successors in connection with a merger, acquisition, financing, reorganization, or sale of assets.

ShadowCanopy does not sell personal information.

ShadowCanopy does not intend to share personal information for cross-context behavioral advertising. If that changes, this Privacy Policy should be updated before the practice begins, and any legally required opt-out mechanism should be provided.

7. Organization and Audit Logs

If you use ShadowCanopy as part of an organization, organization owners, administrators, reviewers, or authorized team members may see activity related to that organization, including:

  • User email.
  • Agent activity.
  • Package checks.
  • Verdicts.
  • Overrides.
  • Policy changes.
  • Audit events.

Platform operators may access service-wide logs and package review data to operate, secure, and improve the service.

8. Data Retention

ShadowCanopy retains information for as long as needed to provide the service, maintain security, comply with legal obligations, resolve disputes, enforce agreements, and support audit requirements.

Typical retention categories may include:

  • Account data retained while the account is active.
  • Agent and token events retained for audit and security.
  • Package verdicts and cache data retained to improve scan performance and consistency.
  • Logs retained for operational, security, and compliance purposes.
  • Backups retained for a limited period before deletion.

Users may request deletion where legally available, but some data may be retained where required for security, legal, fraud prevention, or legitimate business purposes.

9. Security

ShadowCanopy uses technical and organizational measures intended to protect information, including access controls, token handling, encryption where appropriate, monitoring, logging, and operational safeguards.

No system is perfectly secure. Users should avoid submitting secrets and should rotate tokens that may have been exposed.

If ShadowCanopy becomes aware of unauthorized access to personal information, it will evaluate the incident under applicable law. For Mississippi residents, ShadowCanopy will follow Mississippi breach notification requirements where legally applicable. For users in other jurisdictions, ShadowCanopy will provide notices required by applicable U.S. federal, U.S. state, or international data protection laws.

Security issues can be reported to:

security@shadowcanopy.dev

10. International Processing

ShadowCanopy is based in Mississippi, United States, and may process information in the United States and other countries where its service providers operate.

By using the service, you understand that information may be processed outside your country of residence.

If the EU GDPR, UK GDPR, Swiss data protection law, or similar international transfer rules apply, ShadowCanopy will use an appropriate transfer mechanism where required, such as standard contractual clauses, data processing terms, adequacy decisions, or another lawful transfer basis.

11. Your Choices and Rights

Depending on your location and applicable law, you may have rights to:

  • Access personal information.
  • Correct inaccurate information.
  • Delete information.
  • Restrict or object to processing.
  • Export information.
  • Withdraw consent where processing is based on consent.
  • Appeal or complain to a regulator.
  • Opt out of certain sales, sharing, targeted advertising, or profiling where those rights apply.
  • Limit use or disclosure of sensitive personal information where those rights apply.

Requests can be sent to:

privacy@shadowcanopy.dev

ShadowCanopy may need to verify your identity before fulfilling requests.

Mississippi and U.S. Residents

Mississippi does not currently have a broad consumer privacy law equivalent to the California Consumer Privacy Act. However, Mississippi consumer protection and data breach notification laws may apply, and U.S. federal laws may apply depending on the data type and use case.

ShadowCanopy will honor legally required rights for residents of U.S. states that provide privacy rights, such as access, correction, deletion, portability, opt-out, appeal, or limitation rights where applicable.

California and Other State Privacy Rights

If laws such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act, or similar state privacy laws apply to ShadowCanopy, eligible users may have rights to know, access, correct, delete, port, opt out of sale or sharing, limit use of sensitive personal information, and be free from unlawful discrimination for exercising privacy rights.

ShadowCanopy does not knowingly sell personal information. ShadowCanopy does not knowingly share personal information for cross-context behavioral advertising.

European Economic Area, United Kingdom, and Switzerland

If the EU GDPR, UK GDPR, Swiss data protection law, or similar laws apply, eligible users may have rights to access, rectify, erase, restrict, object, port data, withdraw consent, and complain to a supervisory authority.

ShadowCanopy may act as a controller for account, website, billing, support, security, and service-operations data. ShadowCanopy may act as a processor or service provider when processing organization-controlled scan data, logs, package metadata, or audit records under a customer's instructions.

Where required, ShadowCanopy will provide or enter into appropriate data processing terms before processing customer personal data as a processor.

Data Subject Request Timing

ShadowCanopy will respond to verified privacy requests within the timeframe required by applicable law. If more time is needed, ShadowCanopy may extend the response period where law allows and will provide notice when required.

12. Cookies and Tracking

ShadowCanopy may use cookies or similar technologies to:

  • Maintain sessions.
  • Authenticate dashboard users.
  • Protect against abuse.
  • Remember preferences.
  • Measure service usage.

Browser settings may allow you to block or delete cookies, but some service features may not work without them.

If legally required, ShadowCanopy will provide cookie notices, consent controls, or opt-out mechanisms before using non-essential cookies or similar technologies.

13. Children

ShadowCanopy is not directed to children under 13, and users should not knowingly provide personal information from children.

If you believe a child has provided personal information, contact:

privacy@shadowcanopy.dev

14. Changes To This Policy

ShadowCanopy may update this Privacy Policy from time to time.

The updated version will be posted with a new "Last updated" date. Continued use of the service after changes means you accept the updated policy where permitted by law.

15. Regional and Legal Compliance Notes

ShadowCanopy is intended for software development and supply-chain security use. It is not intended to collect or process protected health information under HIPAA, payment card data under PCI DSS, student education records under FERPA, financial account records subject to GLBA, government classified information, or other regulated datasets unless ShadowCanopy has expressly agreed in writing to support that data type.

Users are responsible for configuring ShadowCanopy so that package checks, AI tool integrations, logs, Docker builds, CI systems, and support submissions do not expose secrets or regulated data unnecessarily.

16. Contact

For privacy questions or requests:

privacy@shadowcanopy.dev