Privacy
Draft · last reviewed 31 August 2026
Not yet in force. This is a working draft describing how the RadarCipher software actually behaves. It deliberately does not name an operating company, a registered address, a governing jurisdiction or a supervisory authority, because those have not been established. It must be completed and reviewed against the production hosting arrangements, sub-processors, payment flow and operating entity before RadarCipher is offered commercially.
What this covers
This describes what the RadarCipher software stores and does with it. It covers this website and the RadarCipher application. Everything below is a statement about how the product is built, and can be checked against it.
What this website collects
Nothing. This site sets no analytics cookies, no advertising cookies and no tracking pixels, and it embeds no third-party scripts. Fonts are served from the site itself rather than from a font provider, so reading this page does not tell anybody else that you did.
Whoever hosts the site will keep ordinary server logs — an IP address, a timestamp, a requested path — as any web server does.
Needs confirmation before launch: The hosting provider, the regions the site is served from, and how long their request logs are retained.
What the application stores about you
Your account: your name, email address, a hash of your password (never the password), your locale and timezone, and a record of the devices signed in as you. A second authentication factor, if you set one up, is stored encrypted.
Your organisation: its name, country, timezone, working hours, currency, the people in it and their roles, and its subscription state.
Operational data from the systems you connect: this is the substantial part. To find what has not happened, RadarCipher reads and stores a canonical record of messages, calendar events, companies, contacts, deals, quotes and tasks from the systems you connect — including message content, because a commitment somebody made in writing cannot be detected from a subject line.
What it derives: findings, the evidence behind them, risk scores, drafted actions, approvals, and the audit history of who did what.
Why it stores it
To do the one thing the product does: notice that something expected has not happened, and be able to show you why it thinks so. A finding without its evidence is an assertion, and the evidence is the underlying records.
Your organisation decides what RadarCipher may read by choosing which systems to connect and approving the access scopes at the provider. Every scope RadarCipher requests is a read scope.
Who can reach it
Your organisation’s data is bound to your organisation in the database itself, under PostgreSQL row-level security that the application’s own database role cannot switch off. Within your organisation, what each person can see and do is decided by their role.
Nobody operating RadarCipher can open your organisation by default. Support access must be granted explicitly, is read-only, expires, is recorded in the audit history, and is visible while it is in use.
Who else is involved
The systems you connect — Google, Microsoft or HubSpot — are the sources of the data. RadarCipher reads from them; they are not recipients of anything.
Payment processing is carried out by PayFast through VirtualCoreX, which develops RadarCipher. Card details are handled by the payment provider. RadarCipher never receives or stores a card number.
Email delivery is used to send you account mail, notifications and digests.
AI processing is used for specific tasks — reading a thread to identify a commitment, and drafting a reply for a person to approve. The relevant content is sent to the model provider for that purpose.
Needs confirmation before launch: The named sub-processors, their locations, the contractual terms with each of them, and a published sub-processor list.
Where it is kept and for how long
Audit history is retained for the period your plan defines, and is append-only: it can be read but not rewritten. Cancelling a subscription does not delete your data — the account becomes read-only rather than disappearing.
Needs confirmation before launch: The hosting region or regions, backup retention and location, and the deletion timetable that applies after an account is closed.
Your rights
You can read, correct and export what RadarCipher holds, and you can ask for it to be deleted. Write to support@radarcipher.com.
Needs confirmation before launch: The legal basis, the operating entity and its jurisdiction, the applicable data-protection regime, the supervisory authority you may complain to, and whether a data protection officer is required.
Cookies
This website sets none. The application sets a session cookie when you sign in, which is what keeps you signed in; it is necessary for the service and is not used for tracking.
Questions about this document: support@radarcipher.com.