Privacy Policy
1. Introduction
This Privacy Policy describes the information collection, use, storage, and disclosure practices of RTRGRD in connection with the RTRGRD desktop application. The Application is an AI-assisted terminal workspace designed for network engineering professionals.
The Company is committed to protecting user privacy. The Application employs a local-first architecture wherein the majority of data processing occurs on the user's local device, and transmission to external services is minimized.
2. Information Collection
2.1 Information Provided Directly by User
- Account Credentials. Email address and authentication tokens provided through Google OAuth during account registration.
- Subscription Information. Payment and billing information processed through our third-party payment processor, Lemon Squeezy.
2.2 Information Collected Automatically
- Usage Metrics. Aggregate counts of feature usage, including daily query counts
- Subscription Status. Tier classification and associated usage quotas
- Token Consumption. Aggregate AI token usage for billing purposes
2.3 Information Stored Locally (Never Transmitted)
- Network Credentials. SSH passwords, private keys, and enable passwords (encrypted using Electron safeStorage)
- Device Configurations. Running configurations, interface states, routing tables
- Terminal Session Data. Command history and terminal output
- User Knowledge Base. User-uploaded PDF documents, learned command patterns
- Local AI Models. IBM Granite and Google Gemma models
3. Sanitization Service
When you engage cloud-based AI features, the Application transmits contextual information to third-party AI providers after applying automated sanitization.
The Sanitization Service applies over 30 industry-standard pattern-matching algorithms to detect and redact:
- Passwords in all formats (plaintext, Type 5, Type 7, Type 8, Type 9, bcrypt, scrypt)
- RSA, ECDSA, and Ed25519 private keys
- SNMP v1/v2c/v3 community strings and passwords
- BGP, OSPF, and IS-IS routing protocol authentication keys
- Bearer tokens, JWT secrets, API keys
LIMITATION OF LIABILITY FOR SANITIZATION: THE SANITIZATION SERVICE RELIES ON HEURISTIC PATTERN MATCHING AND CANNOT GUARANTEE 100% DETECTION OF ALL SENSITIVE DATA. THE COMPANY HEREBY DISCLAIMS ALL LIABILITY FOR ANY DATA LEAKAGE, EXPOSURE OF CREDENTIALS, OR SECURITY BREACHES RESULTING FROM THE FAILURE OF THESE SANITIZATION ALGORITHMS.
Defense in Depth: To further mitigate the risk of any potential sanitization bypass, RTRGRD utilizes Google Vertex AI Enterprise APIs. In accordance with Google's Enterprise terms, customer data is not used to train foundation models. Consequently, any data inadvertently transmitted remains isolated to your session and is not incorporated into the public model knowledge base.
4. Third-Party AI Providers
The Application utilizes Google's Cloud AI services (Vertex AI). By using the cloud features, you acknowledge that processed data is sent to Google under the following protections, as defined in the Vertex AI Data Governance Policy:
- Zero Training Policy: "Google does not use customer data to train its foundation models." Your prompts and code snippets are never used to improve Google's public models.
- Data Ephemerality: Data is processed in memory for the duration of the prediction request.
- Ownership: You retain full ownership of all inputs (prompts) and generated outputs.
5. Your Data Control
RTRGRD is designed for local-first privacy. Most of your data never leaves your machine. You can:
- Delete – Uninstall the application to remove all local data
- Restrict – Enable Privacy Mode to route all AI queries locally (RTR-Apex)
- Inspect – The Guardian Orb displays exactly what data is sanitized per request
For data-related questions, use the bug reporter (bottom-right corner of any page).
6. Contact & Governing Law
RTRGRD is developed and maintained by a solo developer. For support, questions, or bug reports, use the Bug Reporter widget available on every page.
Governing Law: State of New Mexico, United States