Legal
Privacy policy
Last updated September 10, 2026
Scope
This policy explains how Witen Labs LLC handles information when you visit witenlabs.com, create a Witen account, use the hosted service, or connect Witen software such as the WordPress plugin or Warden. A website operator using Witen remains responsible for that operator's own privacy notices and legal obligations to its visitors and users.
Information we collect
- Account information: email address, name if supplied, authentication records, session records, plan, and account settings.
- Billing information: subscription and transaction identifiers. Payment-card details are handled by our payment processor rather than stored by Witen.
- Security telemetry: source IP addresses, event time and category, login outcome and sometimes username, request path and method, response status, user agent, referrer, query information, detection evidence, enforcement outcome, sensor identity, hostname, software version, and service-health signals. The exact fields depend on the connected software and event.
- Files you deliberately submit: malware samples or backup content only when you enable and use the relevant feature. Malware sample submission is not automatic.
- Website and operational data: IP address, browser and device information, request time, error records, and email-delivery status needed to operate and secure the service. We do not currently use advertising trackers.
Optional website analytics
We use Google Analytics to understand visits to public website and documentation pages. For visits identified as coming from the United States, analytics is on by default unless you turn it off or your browser sends Global Privacy Control or Do Not Track. For other locations, or when we cannot determine the country, the Google tag loads only after you allow analytics. An existing decline takes precedence over the regional default. You can turn analytics off through “Analytics preferences” on any public page.
We estimate the country from your IP address on our server using a locally stored database. We do not send your IP address to a separate geolocation service for this lookup. Location data is approximate, and a VPN can affect the result. This site uses IP geolocation by DB-IP, licensed under CC BY 4.0.
When enabled, Google Analytics uses cookies and receives page-view information, browser and device information, and the network information needed to process the request. We omit URL query strings, fragments, and referrer URLs from our page-view events. We do not send account or admin page views, account identifiers, or security telemetry to Google Analytics. Global Privacy Control and Do Not Track turn analytics off even if you previously allowed it.
Advertising signals and ad personalization are disabled. Analytics cookies have a 60-day lifetime, and your choice is remembered in this browser for up to 180 days. Use “Analytics preferences” on a public page to change your choice. Declining stops measurement and removes the analytics cookies set by this integration. Essential authentication and security storage is unaffected. See Google's privacy policy for how Google handles information.
How we use information
We use information to authenticate users and sensors; provide dashboards, detection, correlation, backups, and enforcement features; identify coordinated attacks; maintain service reliability; prevent abuse; provide support; process subscriptions; satisfy legal obligations; and improve Witen's security decisions.
Login-success signals remain security evidence. They can reveal a compromise when the same address previously attacked another owned sensor, so Witen does not discard them merely because an address is locally trusted or excluded from banning.
Shared threat intelligence
Witen may use observations from participating sensors to produce shared security intelligence, including hostile IP reputation, classifications, confidence, and timing. Shared output is designed to omit the contributing customer, account, sensor, hostname, username, raw log line, and request content. Customer-specific controls, allowlists, login successes, and policy-only blocks are not published as evidence that an address is globally malicious.
We do not sell personal information or use it for cross-context behavioral advertising.
Service providers and disclosure
We disclose information to infrastructure, database, email-delivery, and payment providers only as needed to operate Witen. We may also disclose information when required by law, to protect users or the service, or in connection with a corporate transaction subject to appropriate safeguards. We do not give service providers permission to use Witen customer data for their own advertising.
Retention and deletion
Security history is a core part of the product. While an account is active, we retain useful account and security history rather than applying a blanket 180-day deletion rule. We may bound or aggregate high-volume technical records when the detailed form no longer adds security value. Session, delivery, and diagnostic records are kept for shorter operational periods.
When we complete an account-deletion request, we revoke further sensor ingestion and remove tenant-attributed records from the account database, event store, analytics store, derived customer pivots and statistics, credentials, configurations, submitted backups, and event archives. Rotating production backups are kept in seven daily and four weekly generations and normally expire within 35 days. A separate deletion tombstone is reapplied before any restored backup can return to service.
We may retain records required for legal obligations, fraud prevention, security, or legal claims. We may also retain threat intelligence that has been stripped of customer and account linkage as described above. We will explain an applicable exception when the law permits us to do so.
Your choices and privacy rights
Depending on where you live, you may have rights to know or access information, correct it, delete it, receive a portable copy, object to or restrict processing, or appeal a decision. You may also have the right not to receive discriminatory treatment for exercising a privacy right. We verify requests before acting to protect the account and security data.
To make an access, correction, export, or deletion request, email privacy@witenlabs.com with the subject “Privacy request.”
Security and international use
We use access controls, encryption in transit, scoped credentials, auditing, and tested backup procedures intended to protect Witen data. No system can guarantee absolute security. Witen is operated from the United States, and information may be processed in the United States or other places where our service providers operate.
Children and policy changes
Witen is a business security service and is not directed to children. We may update this policy as the product, providers, or legal requirements change. We will change the date above and provide additional notice when a change materially affects how we handle information.