Privacy Policy
Last updated: August 30, 2026
This policy explains how AuditFetch, LLC (“AuditFetch,” “we,” “us,” or “our”) handles personal information through this website, our subscription and fulfillment services, and the limited cloud services used by AuditFetch Local. It does not govern data that a customer processes entirely within its own Local deployment.
Our local-first boundary
AuditFetch Local runs in the customer's environment. Evidence payloads, integration credentials, screenshots, browser traces, mappings, hashes, and local audit history stay there by default. AuditFetch does not receive that content unless the customer deliberately sends it to us, such as in a support request. Cloud services are limited to licensing, updates, connector templates, fulfillment, optional telemetry, and future optional collaboration features described before they are enabled.
Information we collect
- Contact and inquiry information: email address and anything you include in a message, evaluation request, or subscription-interest form.
- Purchase and fulfillment information: name, email, organization, plan, subscription identifiers, payment status, and operational details needed to issue a license and deliver a signed package. Stripe processes payment-card data; AuditFetch does not store full card numbers.
- Service metadata: the limited licensing, update, and optional telemetry fields documented in the product. Optional telemetry is off by default.
- Website and security data: ordinary request, device, IP-address, user-agent, referral, error, and security logs produced by our hosting and infrastructure providers.
How we use information
We use information to provide and secure the website and services; process subscriptions; fulfill licenses and releases; respond to requests; maintain product integrity; diagnose failures; comply with law; and protect AuditFetch, our customers, and others. We do not sell personal information or use customer evidence to train AI models.
Cookies and analytics
The AuditFetch marketing website does not use advertising or analytics cookies and does not run third-party advertising or behavioral-analytics trackers. Stripe may use cookies and similar technologies on its hosted checkout and customer-portal pages under its own privacy policy.
Service providers and disclosures
We disclose information only as needed to providers that support our operations, including Vercel (website hosting), Stripe (payments and subscriptions), Resend (transactional email), Google Workspace (business email), Amazon Web Services (licensing APIs and release-package storage and delivery), and GitHub Container Registry (delivery of product container images). Those providers process information under their own terms and privacy commitments. We may also disclose information when required by law, to protect rights or safety, or as part of a merger, financing, acquisition, or transfer of assets with appropriate safeguards.
Update checks and optional telemetry
Update checks are separate from optional telemetry. When cloud licensing is enabled, an installation contacts the AuditFetch licensing service when an administrator opens a product surface that requests update status or asks for a fresh check. Successful results are cached for several hours; no background schedule contacts us on its own. The update request carries the selected release channel, the installed version, and the source IP ordinarily visible to any service. License activation is a separate request that carries the license key, installation fingerprint, installation-salt identifier, runtime version, and deployment mode. License refresh uses the activation identifier and secret, current snapshot key identifier, and runtime version. None of these requests carry evidence, connector credentials, control mappings, or audit-log content. Optional product telemetry remains off by default and is controlled separately. Intentionally air-gapped installations can keep cloud licensing disabled, follow the documented offline update process, and receive notices and signed bundles through the approved offline delivery channel.
Retention
We retain personal information only as long as reasonably necessary for the purposes above, including fulfillment, support, security, and dispute resolution. We generally retain subscription, invoice, refund, and related transaction records for seven years to meet legal, tax, and accounting obligations. Customer-controlled Local data follows the customer's configured retention and deletion settings. You may request deletion of eligible information by contacting us.
Security and international processing
We use reasonable administrative, technical, and organizational safeguards, but no system is completely secure. Our providers may process information in the United States and other countries where they operate, subject to applicable safeguards.
Your choices and rights
You may ask to access, correct, or delete personal information, or object to certain processing. Rights vary by location and may be subject to legal exceptions. You can disable optional product telemetry in the product and unsubscribe from non-transactional messages using the method provided in the message.
Children
AuditFetch is a business service and is not directed to children under 13. We do not knowingly collect their personal information.
Changes and contact
We may update this policy and will change the date above when we do. For privacy questions or requests, email info@auditfetch.com.