Privacy Policy
Groundplane · Effective September 2, 2026
What we collect
Account details: your email address, and a name if you give one. Workspace content: the sites, assets, addressing, findings, incidents, tickets and notes you record. Collector telemetry: device addresses, hardware addresses, operating system and patch state, listening ports, firewall and encryption status, and the network fingerprint described below. Operational logs: who changed what and when.
What we deliberately do not collect
Passwords, API keys, pre-shared keys, SNMP community strings, door codes or any other credential. The collector filters these before anything leaves your network, and the platform stores a reference label pointing at your own password manager rather than a secret itself. We do not capture packet contents or file contents.
The network fingerprint
Each collector derives a one-way hash of your default gateway's hardware address. We use it to tell one network apart from another, so that two collectors reporting from the same site are not counted as two environments. It cannot be reversed into an address and it identifies a network, not a person.
Why we process it
To provide the service you asked for: documenting your environment, raising findings, and producing reports. To bill correctly. To keep the service secure and diagnose faults.
Who can see it
Only members of your own workspace. Access is enforced in the database, not in the interface, so a request from a browser cannot reach another customer's rows. If you are a client of a provider using this platform, that provider's operators can see your environment because you engaged them to manage it.
Sharing
We do not sell personal data and we do not share your workspace content with other customers. We use infrastructure providers to host the service, who process data on our instructions.
How long we keep it
Raw collector reports and audit entries are kept for your workspace's retention window, ninety days by default, then deleted automatically. Records you create are kept until you delete them or ask us to archive the workspace.
Your rights
Ask us for a copy of your data, ask us to correct it, or ask us to delete it. Write to the address below and we will respond.
Security
Data is encrypted in transit. Collector tokens are stored only as one-way digests, so a copy of our database cannot impersonate your collector. Revoking a collector takes effect on its next report.
Contact
Questions about this policy go to support@groundplanes.com.