KRATOS7 Terms·Privacy·AUP kratos7.com →

Privacy PolicyIn effect

Version 1.0  ·  Effective 2026-06-30

Initial version — effective 2026-06-30.


Privacy Policy

In effect — v1.0, effective 2026-06-30. This Policy reflects the actual data practices of the prod stack; any infrastructure change that alters data collection, sub-processors, or retention must round-trip back here (material change → version bump + re-acknowledgement). Self-drafted, not reviewed by outside counsel; a counsel review is recommended before high-volume self-serve.


Effective: 2026-06-30 Last updated: 2026-06-30 Operator: PROTUS NW LLC, dba "Kratos7" (the "Company", "we", "us", "our") Service: the Kratos7 cloud-security training platform at https://kratos7.com (the "Service")

This Privacy Policy explains what personal information we collect when you use the Service, why we collect it, who we share it with, how long we keep it, and your rights with respect to it.


1. What we collect

1.1 Information you give us

1.2 Information collected automatically

1.3 What we do not collect

2. Why we use it

We process your information to:

We do not process your information for any other purpose without first updating this policy and re-acknowledging it with you.

3. Who we share it with

We share personal information only with the following categories of service providers ("sub-processors"), each of whom processes data on our behalf under their own privacy commitments:

Sub-processor Purpose Data accessed
Amazon Web Services, Inc. (us-west-2 region) Hosting, compute, storage, identity (Cognito), encryption (KMS), logs (CloudWatch), event delivery (EventBridge / SQS / SNS), transactional email (SES — account verification, password reset, MFA) All categories in §1
Stripe, Inc. Payment processing, billing portal, subscription management, refund issuance Email, name, card details (Stripe-direct), subscription metadata
Discord, Inc. Forwarding a copy of submitted support tickets to a private staff Discord channel for response triage Support ticket content + your reply email

We do not use third-party analytics, advertising, marketing-automation, or data-broker providers. If we add a new sub-processor, we will update this policy and re-prompt you to acknowledge it before access continues.

We do not sell your personal information. We do not share it for cross-context behavioral advertising.

We may disclose information if required to do so by law, court order, subpoena, or other valid legal process. We will challenge requests we believe to be overbroad or improper, and will notify you of any disclosure unless legally prohibited.

3.2 Business transfer

If we are involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you and give you a chance to delete your account before the transfer.

4. Where we store it

All your data is stored in the United States, in AWS region us-west-2 (Oregon). We do not currently use any other region.

Stripe processes payment data through its own global infrastructure. See Stripe's privacy policy at https://stripe.com/privacy.

Discord stores forwarded support-ticket copies on Discord's infrastructure. See Discord's privacy policy at https://discord.com/privacy.

5. How long we keep it

Category Retention
Account record (email, hashed password, MFA, profile) Until you delete the account, plus 30 days for backups
Stripe customer ID + subscription metadata Until you delete the account; we retain transaction records as required by tax / accounting law (typically 7 years)
Usage telemetry, progress state, adaptive engine state Until you delete the account, plus 30 days for backups
Quest attempt records (your submissions and verdicts) Until you delete the account
Support tickets and feedback Retained until you delete your account or request deletion
Access logs 90 days (auto-expire)
Web server logs (CloudFront, API GW, Lambda, CloudWatch) Up to 12 months depending on log group; auth/billing logs retained toward the upper end for security investigation
Legal-acceptance records (cloudeng-prod-legal-acks) Indefinite — required for audit of consent. You may request deletion; we retain a derivative record showing only "user X deleted their account on date Y"

We may retain aggregated, de-identified data (no email, no IDs, no quasi-identifiers) indefinitely for product analytics. This data cannot be re-associated with you.

6. Your rights

6.1 All users

You can:

6.2 California residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended:

To exercise these rights, email support@kratos7.com. We verify CCPA requests by confirming you can authenticate to the account or by other reasonable means.

6.3 EU / UK residents

We do not currently offer the Service to residents of the European Economic Area, the United Kingdom, or Switzerland. If you appear to be resident there, Stripe will refuse the charge.

If we expand to those regions, we will publish a separate addendum with the rights provided by GDPR / UK GDPR and execute appropriate data-transfer mechanisms.

7. Minors

The Service requires all users to be at least 18 years old. It is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If we learn that an account belongs to someone under 18, we will delete it. If you believe someone under 18 has created an account, please email support@kratos7.com and we will remove it.

(For the avoidance of doubt, and consistent with the Children's Online Privacy Protection Act, we likewise do not knowingly collect personal information from children under 13.)

8. Security

We implement security measures appropriate to the type of data we process:

No system is perfectly secure. If we confirm a breach affecting your personal information, we will notify affected users without unreasonable delay and within the timeframe required by applicable law (in Washington, no later than 30 days after discovery).

9. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes — including changes to the categories of data we collect, why we collect it, who we share it with, or how long we keep it — take effect 14 days after we notify you via your account email and a banner in the Service. Continued use after the effective date constitutes acceptance.

Non-material changes (typos, link fixes, formatting) take effect immediately.

Each version is identified by a version field and an effective_date. Prior versions are preserved in our repository commit history.

10. Contact

For privacy questions, requests, or complaints:

For legal process: support@kratos7.com.

For general support: support@kratos7.com.