IncidentKitBuild Your Exercise

Privacy Policy

Last updated: 2026

What we collect

When you use IncidentKit, we collect: your email address (to deliver your exercise package and receipts), the exercise configuration you choose (organization type, size, scenario, roles, duration, difficulty, and any optional free-text context you provide), and standard technical data (IP address, timestamps) used for fraud prevention and rate limiting.

What we don't want from you

Please do not submit real secrets, credentials, protected health information, complete network diagrams, or other sensitive operational data in the free-text field. Our exercises are designed to work with generic, non-sensitive context only.

How we use your information

We use your information to generate and deliver your exercise package, process payment, send transactional email (receipts and download links), respond to support requests, and improve the service. We do not sell your personal information.

Service providers

We rely on a small number of service providers to operate IncidentKit: Stripe (payment processing — we never see or store your full card details), Resend (transactional email delivery), Anthropic (AI-assisted content generation from your exercise configuration), and our hosting/database providers (Railway and Neon). Each processes data only as needed to provide their service to us.

Data retention

Order and exercise records are retained for accounting and support purposes. Download links expire 7 days after issuance for security, though the underlying files remain associated with your order record. Contact us if you'd like your data deleted, subject to legal recordkeeping requirements.

Security

Download links use cryptographically strong, hashed, expiring tokens. We never store your download token in a retrievable form — only its hash. Access to your files is scoped strictly to your own order. See our Security & AI Use page for more detail.

Contact

Questions about this policy? Contact us.