Privacy Policy

Last updated: June 27, 2026

DruxShield is operated by Drux Inc., a Canadian company. We take privacy seriously — bot protection should never come at the cost of your users' privacy. This policy explains what we collect, why, and how we protect it.

1. Information We Collect

Account data: When you create an account, we collect your email address, name, and (optionally) company name.

Request metadata: To score traffic, we process IP addresses, user-agent strings, HTTP headers, TLS fingerprints, and request paths. IP addresses are hashed after 30 days and never stored in plaintext in block logs.

Usage data: We collect aggregate analytics on how you use the dashboard to improve the product.

2. How We Use Your Data

We use request metadata solely to detect and classify automated traffic. We use account data to provide the service, send important notices, and respond to support requests. We do not sell your data to third parties.

3. Third-Party Threat Intelligence

To enrich bot scoring, IP addresses may be checked against third-party threat intelligence providers including IPQualityScore, AbuseIPDB, and CrowdSec. These providers receive only the IP address being scored, never personally identifiable information.

4. Data Residency & Security

Primary data is stored in Canada (AWS ca-central-1). All data is encrypted in transit (TLS 1.2+) and at rest. We never store raw IP addresses in block logs — they are hashed using SHA-256 with a per-installation salt.

5. GDPR & Your Rights

If you are in the EU/EEA, you have the right to access, correct, export, or delete your personal data. To exercise these rights, email support@drux.space. We do not store PII in block logs, and IP addresses are hashed after 30 days.

6. Data Retention

Block log retention depends on your plan (7 days on Free, 90 days on Pro, 365 days on Business). Account data is retained until you delete your account. Upon account deletion, all associated data is permanently removed within 30 days.

7. Cookies

We use essential cookies for authentication and session management. We do not use advertising or third-party tracking cookies.

8. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated via email or a dashboard notice. Continued use of the service after changes constitutes acceptance.

Questions? Email support@drux.space