Privacy Policy
Last updated: 2026
What we collect
When you use IncidentKit, we collect: your email address (to deliver your exercise package and receipts), the exercise configuration you choose (organization type, size, scenario, roles, duration, difficulty, and any optional free-text context you provide), and standard technical data (IP address, timestamps) used for fraud prevention and rate limiting.
What we don't want from you
Please do not submit real secrets, credentials, protected health information, complete network diagrams, or other sensitive operational data in the free-text field. Our exercises are designed to work with generic, non-sensitive context only.
How we use your information
We use your information to generate and deliver your exercise package, process payment, send transactional email (receipts and download links), respond to support requests, and improve the service. We do not sell your personal information.
Service providers
We rely on a small number of service providers to operate IncidentKit: Stripe (payment processing — we never see or store your full card details), Resend (transactional email delivery), Anthropic (AI-assisted content generation from your exercise configuration), and our hosting/database providers (Railway and Neon). Each processes data only as needed to provide their service to us.
Data retention
Order and exercise records are retained for accounting and support purposes. Download links expire 7 days after issuance for security, though the underlying files remain associated with your order record. Contact us if you'd like your data deleted, subject to legal recordkeeping requirements.
Security
Download links use cryptographically strong, hashed, expiring tokens. We never store your download token in a retrievable form — only its hash. Access to your files is scoped strictly to your own order. See our Security & AI Use page for more detail.
Contact
Questions about this policy? Contact us.