Privacy PolicyIn effect
Initial version — effective 2026-06-30.
Privacy Policy
In effect — v1.0, effective 2026-06-30. This Policy reflects the actual data practices of the prod stack; any infrastructure change that alters data collection, sub-processors, or retention must round-trip back here (material change → version bump + re-acknowledgement). Self-drafted, not reviewed by outside counsel; a counsel review is recommended before high-volume self-serve.
Effective: 2026-06-30 Last updated: 2026-06-30 Operator: PROTUS NW LLC, dba "Kratos7" (the "Company", "we", "us", "our") Service: the Kratos7 cloud-security training platform at https://kratos7.com (the "Service")
This Privacy Policy explains what personal information we collect when you use the Service, why we collect it, who we share it with, how long we keep it, and your rights with respect to it.
1. What we collect
1.1 Information you give us
- Account email. Required to create an account. Used as your login identifier.
- Password. Stored only as a salted hash by AWS Cognito; we cannot read it.
- MFA factors. If you enable TOTP multi-factor authentication, your shared secret is stored in AWS Cognito and is not accessible to us in plaintext. Backup recovery codes are stored as scrypt hashes; we cannot read the originals.
- Billing information. Card number and billing address are collected by Stripe directly; we never see or store your card number. We retain only a Stripe customer ID and subscription metadata (plan, status, billing period).
- Profile fields. Optional fields you fill in (display name, role, learning goals).
- Support tickets and feedback. Anything you submit through in-product support forms or the feedback panel: the message, category, and reply email if different from your account email. A copy of each support ticket is forwarded to a private staff channel on Discord for response triage (see §3) — please do not include passwords, payment-card numbers, or other sensitive data in a support message.
- QA submissions and capstone artifacts. When you submit a quest, lab, or capstone for grading, we store your submission text and metadata so it can be graded and so you can review your own history.
- Consent records. When you accept our Terms, Privacy Policy, and Acceptable Use Policy at signup (or re-accept after a material change), we record your account email, the versions you accepted, a timestamp, and — as a forensic audit trail of your consent — your IP address and browser user-agent. These consent records are retained as a compliance record (see §5 and §6).
1.2 Information collected automatically
- Usage telemetry. Lab/drill/workout/quest events: which item you opened, when, how long, your answers, your verdict (correct/incorrect), your tier band. Stored in
cloudeng-prod-saas-metrics. - Progress state. Section-level completion state for products and content, so you can resume where you left off. Stored in
cloudeng-prod-saas-user-progress. - Adaptive engine state. Your mastery vector (per-skill BKT estimates), Rasch ability estimate, FSRS scheduling state, ZPD band, calibration scores. Stored in
cloudeng-prod-user-profiles. This is what makes adaptive routing work. - Quest attempt records. Full submissions, verdicts, and tier outcomes for graded sessions. Stored in
cloudeng-prod-quest-attempts. - Access logs. Authentication events, subscription mutations, and access-control actions. Stored in
cloudeng-prod-saas-access-logswith a 90-day TTL. - Web server logs. CloudFront, API Gateway, and Lambda request logs include your IP address, user agent, request path, response code, and timing. Retention as set in CloudWatch (up to 12 months, depending on the log group; authentication and billing request logs are retained longer for security and fraud investigation).
- Webhook idempotency keys. When Stripe notifies us of a billing event, we store the Stripe event ID briefly to prevent double-processing.
- Cookies. We set only strictly-necessary first-party cookies (authentication / session). We do not set advertising or third-party analytics cookies, so no cookie-consent banner is required.
1.3 What we do not collect
- We do not use third-party advertising trackers.
- We do not use third-party analytics (no Google Analytics, no Segment, no Mixpanel). Our analytics are first-party only and stay in our AWS account.
- We do not sell personal information.
- We do not share personal information with data brokers.
- We do not collect precise geolocation (only the approximate region inferable from an IP).
- We do not collect children's information knowingly (see §7).
2. Why we use it
We process your information to:
- Operate the Service (authenticate you, serve the content you've paid for, grade your submissions, route adaptive content).
- Process payments via Stripe.
- Detect abuse and enforce the Acceptable Use Policy (e.g., bot signup, shared accounts, scraping).
- Improve the Service (analyze aggregated usage patterns to fix bugs and prioritize features).
- Communicate with you about your account, billing, and material policy changes.
- Respond to your support requests.
- Comply with legal obligations.
We do not process your information for any other purpose without first updating this policy and re-acknowledging it with you.
3. Who we share it with
We share personal information only with the following categories of service providers ("sub-processors"), each of whom processes data on our behalf under their own privacy commitments:
| Sub-processor | Purpose | Data accessed |
|---|---|---|
| Amazon Web Services, Inc. (us-west-2 region) | Hosting, compute, storage, identity (Cognito), encryption (KMS), logs (CloudWatch), event delivery (EventBridge / SQS / SNS), transactional email (SES — account verification, password reset, MFA) | All categories in §1 |
| Stripe, Inc. | Payment processing, billing portal, subscription management, refund issuance | Email, name, card details (Stripe-direct), subscription metadata |
| Discord, Inc. | Forwarding a copy of submitted support tickets to a private staff Discord channel for response triage | Support ticket content + your reply email |
We do not use third-party analytics, advertising, marketing-automation, or data-broker providers. If we add a new sub-processor, we will update this policy and re-prompt you to acknowledge it before access continues.
We do not sell your personal information. We do not share it for cross-context behavioral advertising.
3.1 Legal disclosure
We may disclose information if required to do so by law, court order, subpoena, or other valid legal process. We will challenge requests we believe to be overbroad or improper, and will notify you of any disclosure unless legally prohibited.
3.2 Business transfer
If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you and give you a chance to delete your account before the transfer.
4. Where we store it
All your data is stored in the United States, in AWS region us-west-2 (Oregon). We do not currently use any other region.
Stripe processes payment data through its own global infrastructure. See Stripe's privacy policy at https://stripe.com/privacy.
Discord stores forwarded support-ticket copies on Discord's infrastructure. See Discord's privacy policy at https://discord.com/privacy.
5. How long we keep it
| Category | Retention |
|---|---|
| Account record (email, hashed password, MFA, profile) | Until you delete the account, plus 30 days for backups |
| Stripe customer ID + subscription metadata | Until you delete the account; we retain transaction records as required by tax / accounting law (typically 7 years) |
| Usage telemetry, progress state, adaptive engine state | Until you delete the account, plus 30 days for backups |
| Quest attempt records (your submissions and verdicts) | Until you delete the account |
| Support tickets and feedback | Retained until you delete your account or request deletion |
| Access logs | 90 days (auto-expire) |
| Web server logs (CloudFront, API GW, Lambda, CloudWatch) | Up to 12 months depending on log group; auth/billing logs retained toward the upper end for security investigation |
Legal-acceptance records (cloudeng-prod-legal-acks) |
Indefinite — required for audit of consent. You may request deletion; we retain a derivative record showing only "user X deleted their account on date Y" |
We may retain aggregated, de-identified data (no email, no IDs, no quasi-identifiers) indefinitely for product analytics. This data cannot be re-associated with you.
6. Your rights
6.1 All users
You can:
- Access the personal information we hold about you by emailing support@kratos7.com with proof of account control (you must email us from the address on file). We will respond within 30 days.
- Correct inaccurate information by editing your profile in the Service or by emailing us.
- Delete your account at any time. Deletion removes your account, profile, progress state, mastery estimates, and submissions. Some data is retained as noted in §5 (financial records for tax, legal-acceptance audit trail in derivative form, access logs until TTL expiration).
- Export your account data — we will provide a JSON export of account, profile, progress, mastery, and attempt records on request.
6.2 California residents (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended:
- Right to know what personal information we collect, why, the categories of sources, and the categories of sub-processors. This policy provides that information; you may also email support@kratos7.com to request a specific report.
- Right to delete personal information, subject to legal exceptions (see §5).
- Right to correct inaccurate personal information.
- Right to opt out of "sale" or "sharing" of personal information. We do not sell or share personal information for cross-context behavioral advertising.
- Right to limit use of sensitive personal information. We do not use sensitive personal information beyond what is necessary to operate the Service.
- Right to non-discrimination. Exercising any of these rights will not result in a degraded Service or different pricing.
To exercise these rights, email support@kratos7.com. We verify CCPA requests by confirming you can authenticate to the account or by other reasonable means.
6.3 EU / UK residents
We do not currently offer the Service to residents of the European Economic Area, the United Kingdom, or Switzerland. If you appear to be resident there, Stripe will refuse the charge.
If we expand to those regions, we will publish a separate addendum with the rights provided by GDPR / UK GDPR and execute appropriate data-transfer mechanisms.
7. Minors
The Service requires all users to be at least 18 years old. It is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn that an account belongs to someone under 18, we will delete it. If you believe someone under 18 has created an account, please email support@kratos7.com and we will remove it.
(For the avoidance of doubt, and consistent with the Children's Online Privacy Protection Act, we likewise do not knowingly collect personal information from children under 13.)
8. Security
We implement security measures appropriate to the type of data we process:
- All data in transit is encrypted with TLS 1.2 or higher.
- All data at rest in DynamoDB, S3, and CloudWatch is encrypted with AWS-managed or customer-managed KMS keys.
- Passwords are stored only as salted hashes by AWS Cognito.
- MFA secrets and backup recovery codes are stored in a form we cannot read in plaintext.
- Access to production systems requires AWS SSO with multi-factor authentication. No long-lived keys.
- Source code, infrastructure, and access changes are tracked in version control with audit history.
- We log access-control events to an append-only log with 90-day retention.
- We hold a pre-launch security review on file (see
_operations/handover-2026-05-13-pre-launch-security-review.md).
No system is perfectly secure. If we confirm a breach affecting your personal information, we will notify affected users without unreasonable delay and within the timeframe required by applicable law (in Washington, no later than 30 days after discovery).
9. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes — including changes to the categories of data we collect, why we collect it, who we share it with, or how long we keep it — take effect 14 days after we notify you via your account email and a banner in the Service. Continued use after the effective date constitutes acceptance.
Non-material changes (typos, link fixes, formatting) take effect immediately.
Each version is identified by a version field and an effective_date. Prior versions are preserved in our repository commit history.
10. Contact
For privacy questions, requests, or complaints:
- Email: support@kratos7.com
- Operator: PROTUS NW LLC, a Washington limited liability company, dba Kratos7 (registered-agent address available on request via support@kratos7.com)
For legal process: support@kratos7.com.
For general support: support@kratos7.com.