Dashboard →
Legal

Privacy Policy

Last updated: June 2026

This Privacy Policy explains how RunTimeAdmin ("we", "us", "our") collects, uses, and protects information when you use SBOMix ("Service"). We are committed to handling your data responsibly.

1. Information We Collect

DataWhy we collect itRetention
Email addressAccount creation, key delivery, service notificationsUntil account deletion
Organisation nameIdentify your account in the dashboardUntil account deletion
SBOM data (components, versions, PURLs)Core service functionality — vulnerability matching, diff, reportingUntil app or account deleted
Vulnerability dataRisk reporting and alertingUntil app or account deleted
API key hashesAuthentication (plaintext keys are never stored)Until key revoked or account deleted
API key last-used timestampsSecurity monitoring, unused key cleanupUntil key revoked
Server logs (IP address, request path, timestamp)Security, debugging, abuse prevention30 days

We do not collect names, payment details (handled by Stripe directly), or browsing behaviour beyond what is logged at the server level.

2. How We Use Your Information

We do not use your SBOM data to train AI models. We do not sell your data to third parties.

3. Third-Party Services

ServicePurposeData shared
ResendTransactional email deliveryEmail address, email content
DeepSeekAI-generated vulnerability explanations (opt-in per request)Vulnerability and component names only
OSV.dev (Google)Open-source vulnerability data enrichmentComponent PURLs
CISA KEVKnown Exploited Vulnerability flag enrichmentNone — we pull a public feed
StripePayment processing (when billing is enabled)Email, billing details

4. Data Security

API keys are stored as HMAC-SHA256 hashes — plaintext keys are shown once on creation and never stored. All data is transmitted over TLS. Access to production systems is restricted to authorised personnel only.

5. Your Rights

You have the right to:

To exercise any of these rights, email privacy@sbomix.com. We will respond within 30 days.

6. Cookies

The Service does not use tracking cookies. The dashboard stores your API key in localStorage solely to keep you logged in — this data never leaves your browser.

7. Children

The Service is not directed at children under 16. We do not knowingly collect data from anyone under 16.

8. Changes to This Policy

We may update this policy from time to time. We will notify registered users by email of material changes. The "last updated" date at the top of this page will always reflect the current version.

9. Contact

Questions about this policy? Email privacy@sbomix.com.