1. Scope and controller
Sentinel Graph LLC, a Texas limited liability company, controls the information described in this notice. It covers the public website, briefing requests, authentication, pilot administration, support, and authenticated application.
2. Information we handle
Contact and commercial records
We receive the name, work email, organization, title, requested use case, and message supplied through the contact form or direct communications. Contracts, invoices, billing addresses, payment status, and tax or exemption records are maintained for accepted pilots. Stripe handles card information; Sentinel Graph LLC does not receive complete payment-card numbers.
Account, access, and security records
We handle authentication identifiers, work email, organization, pilot role, access status, invitation and expiration dates, IP and device metadata, security events, routes, status codes, and sanitized error fingerprints. We do not intentionally log request bodies, source records viewed, or customer-sensitive content in application error events.
Public-source records
The service organizes lawfully obtained public records that may identify people, providers, organizations, addresses, telephone numbers, officials, exclusions, and professional relationships. A public record or shared field may be incomplete, stale, ambiguous, or associated with a different person. It is not by itself evidence of wrongdoing.
AI-assisted Help and Ask
DigitalOcean processes bounded questions and grounded context to provide the optional Help and Ask features. SentinelGraph records usage metadata such as model, token counts, latency, user identifier, and timestamp, but does not store the user prompt or generated response in its application database. Do not enter PHI, medical records, confidential client information, or non-public investigative material.
3. Purposes
- respond to briefing requests and administer pilot accounts;
- authenticate users and enforce named-user, seat, term, and permitted-use controls;
- provide source-linked investigative lead intelligence and product support;
- secure, monitor, troubleshoot, back up, and improve the service;
- maintain contracts, invoices, tax records, and required business records; and
- comply with law, investigate misuse, and protect rights and safety.
We do not sell account information or investigative search histories for advertising, and we do not use pilot activity to make credit, employment, housing, insurance, eligibility, or other adverse decisions.
4. Service providers and processing locations
We use Clerk for authentication; Vercel for web hosting, deployment, logs, and observability; Stripe for invoicing, payments, receipts, and tax handling; Resend for internal contact-form and operational email; DigitalOcean for bounded AI inference; and infrastructure providers for database hosting, encrypted backups, source jobs, and monitoring. These providers process information under their own terms and privacy obligations to provide services to Sentinel Graph LLC.
Providers may process information in the United States and other countries where they operate. Laws in those locations may differ from those in the user's jurisdiction.
5. Retention
- Unconverted contact inquiries: 24 months.
- Account and access records: the pilot term plus 90 days.
- Security, application, and AI usage metadata: 12 months.
- Support communications: three years after closure.
- Contracts, invoices, tax records, and exemption certificates: seven years.
- Encrypted operational backups: 90 days.
- Public-source releases and provenance manifests: while the corresponding product release is supported for reproducibility.
We may retain information longer when reasonably necessary for a legal hold, dispute, security investigation, or other legal obligation. Backup deletion follows the backup rotation rather than immediate record-by-record removal.
6. Security and recoverability
We use access controls, invitation-only application access, encryption in transit, encrypted operational backups, logging controls, credential management, and tested recovery procedures appropriate to a controlled pilot. No system is completely secure, and the pilot is not represented as providing an enterprise security certification or production service-level agreement.
7. Requests and source corrections
To request access, correction, or deletion of account information, or to report a potentially inaccurate source-linked record, email probert@sentinelgraph.com. We may need to verify identity and authority. Public-source correction requests may require review of the original publisher; Sentinel Graph LLC cannot alter an upstream government record.
8. Children and sensitive submissions
The service is for professional users and is not directed to children under 18. Do not provide PHI, medical records, confidential case data, protected client information, government-classified material, payment-card numbers, or Social Security numbers.
9. Changes and contact
We may update this notice prospectively and will post a new effective date. Questions and privacy requests should be sent to probert@sentinelgraph.com.