Legal
Privacy Policy
Last updated 19 August 2026
What we collect, why, who we share it with, and how long we keep it. The retention periods below are maximums — in practice most data is deleted well before them.
This policy explains how Witina AI LLC ("Witina", "we", "us") handles
information in connection with the Witina AI network management platform (the "Service").
It covers our hosted service at app.witinaai.com, this website, and our
self-hosted trial distribution.
1. Our role: controller and processor
Two different kinds of information flow through the Service, and our obligations differ for each.
- Account information — the names and email addresses of the people who sign in, billing details, and how the product is used. For this we act as a controller: we decide what to collect and why.
- Your network data — everything the Service discovers or records about the networks and devices you connect to it. For this we act as a processor: it is your data, we hold it on your instructions, and we do not use it for our own purposes.
If you are a managed service provider using Witina on behalf of your own customers, you are the controller for your customers' data and we are your processor. Your agreement with your customers governs that relationship; ours with you governs this one.
2. What we collect
Account and identity
- Name, email address, and a hashed password (we never store passwords in readable form).
- Organization, team, and role membership, which determine what each person can see and do.
- Authentication events: sign-ins, failed sign-in attempts, sign-outs, password resets and magic-link use, each with the time, source IP address and browser user agent.
- If you sign in through your own identity provider, the identifier it returns for you.
Your network data
This is the substance of the product. Depending on which features you enable, a gateway you run inside your network collects and sends us:
- Device inventory — hostnames, models, serial numbers, firmware versions, IP and MAC addresses.
- Topology — how devices are connected, learned from LLDP, CDP, and forwarding tables.
- Endpoint inventory — MAC addresses, IP addresses and last-seen times for things attached to your network, including wireless clients. On a corporate network these can identify a person's laptop or phone, and therefore may be personal data in your hands.
- Metrics and health — interface counters, availability, and similar operational telemetry.
- Device configuration snapshots, and records of configuration changes made through the Service.
- Diagnostic artifacts, when you or an administrator explicitly capture them: terminal session recordings, web-session captures (HAR files), and gateway diagnostic bundles. These can contain whatever was on the screen or on the wire at the time, which is why capturing them requires an explicit action and, for web captures, a recorded consent.
Activity log
Every privileged action taken in your organization is recorded: who did it, what they did it to, whether it succeeded, and the source IP address and browser user agent of the request. This exists so that you can answer questions about your own account, and so that a change to your network is attributable. It is described in more detail under retention, because it is kept longer than most other data.
Usage and diagnostics
- Product analytics events — which features are used, in aggregate, to decide what to build.
- Server logs and error reports, used to keep the Service working.
- Billing records: plan, usage counts against your plan, invoices and payment status.
What we do not collect
- Device credential secrets. Passwords, SSH keys and SNMP community strings for your network equipment are encrypted on the gateway you run and never reach our systems. We store only a credential's name, type, description, and which devices may use it. When one gateway shares a credential with another, it is encrypted end to end between them and we relay ciphertext we cannot read.
- The contents of your network traffic, except in the diagnostic artifacts described above, which you capture deliberately.
- Payment card numbers. Those go directly to our payment processor; we never see them.
3. How we use it
- To provide the Service — discovery, monitoring, alerting, and change management.
- To authenticate you and enforce your organization's permissions.
- To notify you about your network, through the channels you configure.
- To bill you, and to measure usage against your plan.
- To keep the Service secure and available, and to investigate abuse or incidents.
- To improve the Service, including by developing analytics and machine learning features. Anything we derive for use beyond your own account is aggregated or de-identified so that it does not identify you, your users, or your network. We do not sell data, and we do not disclose your network data to other customers.
- To contact you about the Service, and — only if you opt in — about other things.
4. Who we share it with
We do not sell personal information. We share it only with service providers who help us run the Service, each bound to use it only for that purpose:
| Provider | Purpose | What reaches them |
|---|---|---|
| Amazon Web Services (SES) | Transactional email | Recipient email address and message content — invitations, alerts, password resets |
| Stripe | Payment processing | Billing contact and payment details, sent directly to Stripe |
| PostHog | Product analytics | Usage events and an account identifier — not your network data |
We may also disclose information where the law requires it, or to protect our rights, safety, or the integrity of the Service. Where we are compelled to disclose your data we will notify you where we are legally permitted and reasonably able to do so.
We may add or change service providers as the Service grows — for example, moving the hosting infrastructure to a cloud provider. Where a change materially affects how your data is handled, we will update this page and give notice as described in section 12 before it takes effect.
5. Where your data is held
The Service currently runs on infrastructure that we operate and control in the United States. Our email and payment providers are also United States based. If we move to a third-party cloud provider, we will name it here first.
6. How long we keep it
The periods below are maximums, not targets. Most of this data is deleted well before the limit shown — several categories in a matter of weeks — but stating a ceiling means we are not quietly keeping anything longer than we told you we might.
| Data | Kept for |
|---|---|
| Account and organization records | While your account is active |
| Network inventory, topology, configuration snapshots | While your account is active, or until you delete them |
| Activity log (queryable) | Up to 12 months |
| Activity log (archive) | Indefinitely — see below |
| Web-session captures | Up to 12 months |
| Gateway diagnostic and profiling artifacts | Up to 12 months |
| Usage records used for billing | Up to 12 months, or longer where tax or accounting law requires |
| Operational and background processing records | Up to 12 months |
The activity log is deliberately different. It is the record of who did what in your account, so it is append-only: entries cannot be edited or selectively deleted through the product, and each is cryptographically chained to the one before it so that tampering is detectable. The one exception is the redaction described in section 8, which removes personal information while leaving the record of the event intact. The queryable copy covers 90 days; a permanent archive is retained as a security record.
After you close your account, we delete your network data and account records. Activity log entries are retained for up to one year after closure, and in the archive beyond that, because they are our record of security-relevant events — including events affecting other parties — and because we may need them to respond to a dispute or a security investigation. See section 8 for how erasure interacts with this.
We may keep information longer where the law requires it, or where we reasonably need it to establish, exercise, or defend a legal claim, to comply with a regulatory or tax obligation, or to honour a legal hold or a lawful request from an authority. In those cases we keep only what is needed for that purpose, and delete it once the obligation ends.
7. How we protect it
- Encryption in transit for everything, and at rest for stored data.
- Device credential secrets are encrypted on your gateway with keys you control, and are never present in our systems in readable form.
- The gateway makes only outbound connections. Nothing needs to be exposed to the internet for the Service to reach your network.
- Access is scoped by organization, division, region and role. Our staff do not access customer network data as a matter of routine; where an administrator does reach into a customer account, that action is recorded in that customer's own activity log.
- Passwords are hashed. API keys and tokens are stored hashed or encrypted.
No system is perfectly secure. If a breach affects your personal information, we will notify you and any regulator that the law requires, without undue delay.
8. Your choices and rights
You can, at any time:
- See and correct your account details in the app.
- Export your activity log.
- Delete network data, devices, and captured artifacts.
- Turn off notification channels you do not want.
- Close your account, which starts the deletion described above.
If your personal information appears in an account belonging to someone else — for example, you are an employee of a Witina customer — please contact that organization first. They control that data; we act on their instructions.
Erasure and the activity log. Where we must erase personal information that appears in the activity log, we redact it, while leaving the record that the event happened. We cannot delete the entries themselves without destroying the integrity of a security record that also concerns other people. If you believe that balance is wrong in your case, contact us and we will look at it.
9. If you are in the EU, the UK, or California
EU and UK
Where the GDPR or UK GDPR applies, our lawful bases are: performance of a contract for providing the Service and billing you; legitimate interests for security, abuse prevention, and keeping the activity log; and consent where we ask for it, which you may withdraw at any time. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to complain to your supervisory authority.
Data is processed in the United States. Where we transfer personal data out of the EEA or UK we rely on Standard Contractual Clauses. A data processing addendum is available on request — write to [email protected].
California
We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding twelve months. California residents may request access to, deletion of, or correction of their personal information, and will not be treated differently for asking. The categories we collect and why are set out in sections 2 and 3.
10. If you run Witina yourself
The self-hosted trial distribution is designed so that nothing about your network reaches us. It has no analytics, no archive to our systems, and no outbound reporting. Your data stays on the machine you run it on, and this policy's collection sections do not apply to it — the only information we hold is whatever you gave us to obtain the distribution.
11. Children
The Service is a business product and is not directed to anyone under 16. We do not knowingly collect their personal information.
12. Changes to this policy
We will post any change here and update the date at the top. For a change that materially affects how we handle personal information — a new category of data, a new purpose, or a new service provider with access to it — we will give reasonable advance notice by email to account administrators or in the app before it takes effect.
13. Contact us
Witina AI LLC
522 W Riverside Ave, Ste N
Spokane, WA 99201
United States
Privacy questions: [email protected]