RedLens AI is committed to protecting your privacy and handling your data with the care and transparency required in the healthcare and law enforcement sectors. This policy explains how we collect, use, and protect information.
When you register for RedLens AI or book a demonstration, we collect your name, business email address, organization name, job title, and phone number.
When you run a security assessment, we collect the AI system descriptions you provide, attack results and vulnerability findings, scan configurations and methodology selections, and compliance mapping outputs.
We collect standard technical information including IP addresses, browser type, pages visited, session duration, and feature usage patterns to improve our platform and troubleshoot issues.
The free POC assessment tool runs on our servers, not in your browser. An earlier version of this policy said the opposite; that was true when the tool ran entirely client-side, and it stopped being true when the assessment engine moved server-side. To run a free assessment, the following is transmitted to us:
We store your contact details, the industry and target model you selected, and a summary of the outcome (risk score, number of vulnerabilities confirmed, and whether the assessment completed). The system prompt, attack prompts, and pasted AI responses are used to produce your report and are not written to our database. They are sent to Anthropic's API, our AI sub-processor, to generate attack prompts and analyze responses — see Section 7.
Free POC leads are not covered by the subscription-based retention window in Section 4; we keep them until you ask us to delete them. You may request deletion at any time by contacting support@redlens.ai.
Please do not paste sensitive data into the free tool. It is a proof-of-concept aid, not a governed assessment environment. Do not paste API keys or credentials, Protected Health Information, criminal justice information, or any other regulated or confidential data into the system prompt or response fields. Customers who need assessments run under a BAA or DPA should use the RedLens AI platform rather than the free tool.
If you enter your email address into the signup form on our Insights, blog, or Threat Intel pages, we store that address, the page you submitted it from, the time you submitted it, and the IP address the submission came from. The IP address is kept as a record that the signup was real and to investigate automated abuse of a public form; it is not used for advertising or profiling.
We add an address to this list only when someone types it into that form and presses the button. There is no pre-checked box, no signup bundled into account creation, and no imported list. We use the address for one thing: telling you when we publish a new post. It is not shared with anyone, and there is no third-party email or analytics provider involved. The list lives in our own database.
Every email we send carries an unsubscribe link that works with one click and keeps working indefinitely. Unsubscribing marks the address as opted out and stops the emails; we keep the record itself so a later signup cannot quietly re-add you. If you would rather have the address deleted outright, email support@redlens.ai and we will remove the record.
RedLens AI runs its own Runtime Guard against the AI features inside this product — the in-platform copilot, the MSSP partner copilot, and the sales copilot on this website — so that we prove our defensive tooling against real traffic rather than only against synthetic examples. This monitoring observes; it does not intervene. It records what the guard would have flagged, and it never blocks, alters, or delays an answer you receive.
When an interaction triggers a detection, we store one excerpt of at most 500 characters of the text around the match, so a member of our staff can review it and label whether the detection was correct. Interactions that trigger nothing are counted but not stored, and we never keep the full question or the full answer. Because you can paste anything into a copilot box, an excerpt can in principle contain personal data — including, for a healthcare customer, Protected Health Information — so please treat those fields accordingly.
Stored excerpts are readable by RedLens AI platform staff only; customer, partner, and unauthenticated sessions cannot retrieve them at all. Excerpt text is automatically deleted 30 days after it is recorded, leaving only the non-text record of the detection — its category, severity, and any reviewer label — as security evidence. Excerpts are stored without a link back to the originating account. That means they are not identifiable to us, but it also means they cannot be located by a deletion or data-subject request; the resulting exposure is bounded to the 30-day window above.
If you run an AI agent that calls tools — a database lookup, a records API, a payments call — our monitoring SDK can accept a record of what your agent invoked, so we can tell you when an agent acted outside the scope you granted it. This is optional and off unless your integration chooses to send it. Each record is limited to the tool's name, an optional classification and resource label, a status, and at most 2,000 characters each of the arguments passed in and the result returned, with no more than 20 tool calls recorded per request.
Tool arguments and results are more sensitive than prompt text, and you should treat them that way. Where a question typed into a chat box is what a person chose to write, a tool argument is the actual value your agent passed into a system of record — a patient or case identifier, a query filter, the contents of a returned row. For a healthcare or criminal-justice customer that should be assumed to be Protected Health Information or criminal justice information by default. Send only what you are willing to have monitored, and redact on your side before sending if you are unsure.
What we do with it today: nothing is stored. RedLens AI currently accepts and validates these records but does not write them to our database, does not use them in any detection, and does not retain them — they are discarded once the request that carried them completes. When that changes, the change will be described here before it takes effect, and any tool-call text we begin storing will be governed by the same rules as the excerpts above: RedLens AI platform staff only, and automatically deleted after 30 days.
These statements describe the systems we assess. They do not describe what you type into RedLens AI's own interfaces: text you enter into a RedLens AI copilot may be excerpted for the security monitoring described above, and what you enter into the free POC tool is transmitted to us as described above.
We do not sell your data. We do not share your assessment results, vulnerability findings, or organizational data with third parties for advertising or marketing purposes.
RedLens AI operates as a Business Associate under HIPAA for customers in the healthcare sector. We execute Business Associate Agreements (BAAs) with all healthcare customers upon request. Contact support@redlens.ai to initiate a BAA.
Our HIPAA compliance posture includes:
Assessment results and vulnerability findings are retained for the duration of your subscription plus 90 days following termination, unless you request earlier deletion. You may request deletion of your data at any time by contacting support@redlens.ai. We will process deletion requests within 30 days.
The retention window above is tied to a subscription and therefore does not apply to leads and results from the free POC assessment tool, which we keep until deletion is requested. See Section 1.
One narrow exception: if you used our third-party AI vendor assessment feature, we retain the resulting authorization record (who authorized the assessment and of what target) even after your account and other data are deleted. This is our own record that we had lawful authorization before testing a system we don't operate, kept for our own accountability — not your operational data, and not covered by the deletion described above. See our Data Processing Agreement §8 for the full explanation.
RedLens AI employs the following security measures to protect your data:
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data. You may also have the right to object to or restrict certain processing. To exercise any of these rights, contact us at support@redlens.ai. We will respond within 30 days.
We use the following sub-processors to deliver our services:
For privacy questions, data requests, or to request a BAA: support@redlens.ai
South 301 LLC DBA RedLens AI
Last updated: August 2026
Legal Notice: This privacy policy is provided as a professional template for RedLens AI. Organizations handling regulated data should have legal counsel review this document for their specific requirements.