ENIGMA BYTE, LLC
Privacy Policy
Effective August 30, 2026
What we collect
We process your email address, account and purchase records, named API-token metadata, server labels, public SSH host keys submitted for fingerprinting, derived fingerprints, UTC timestamps, and the request IP observed by our edge. The observed IP is contextual telemetry and is clearly marked as observational in reports.
How data is used
We use this information to authenticate you, deliver fingerprint reports, prevent abuse, operate credit accounting, process payments, support users, and maintain service security. Raw public SSH keys are used only to derive fingerprints and are not stored.
Encryption and retention
Email addresses, token names, and retained fingerprint-report details are encrypted at the application layer. API tokens and authentication secrets are stored only as keyed or one-way digests. Encrypted report details are purged after 30 days; accounting records may remain after their details are purged. Session, magic-link, security, purchase, and legal records are retained only as needed for their purpose and applicable obligations.
Processors and disclosure
Cloudflare provides compute, database, security, and email-delivery infrastructure. Stripe processes card payments. We may disclose information when required by law, to protect the service, or as part of a business transaction subject to appropriate safeguards. We do not sell personal information.
Your choices
You can revoke API tokens from the console. For access, correction, or deletion requests, email hey@sshfingerprint.com. Some records may be retained where legally or operationally required.