Privacy Policy
1. Introduction
This Privacy Policy (the "Policy") describes the information collection, use, storage, and disclosure practices of RTRGRD LLC (referred to herein as "Company," "we," "us," or "our") in connection with the RTRGRD desktop application (the "Application" or "Service"). The Application is an AI-assisted terminal workspace designed for network engineering professionals.
The Company is committed to protecting user privacy. The Application employs a local-first architecture wherein the majority of data processing occurs on the user's local device, and transmission to external services is minimized.
By downloading, installing, or using the Application, you acknowledge that you have read, understood, and consent to the practices described in this Policy. If you do not agree to this Policy, you must discontinue use of the Application.
2. Information Collection
2.1 Information Provided Directly by User
The following information is collected directly from users:
- Account Credentials. Email address and authentication tokens provided through Google OAuth or Microsoft Azure AD OAuth during account registration. Both authentication methods are facilitated through Google Firebase Authentication.
- Subscription Information. When subscription payments are enabled, payment and billing information will be processed through our third-party payment processor, Lemon Squeezy. The Company does not store complete payment card details.
- Bug Reports. If you submit a bug report through the Application, the information you provide (category, severity, summary, reproduction steps, and expected behavior) is transmitted to Company systems for issue tracking purposes.
2.2 Information Collected Automatically
The following information is collected automatically during use of the Service:
- Cloud AI Query Counts. Daily counts of cloud-based AI requests, used for quota enforcement and billing.
- Per-Query AI Metadata. For each cloud AI request, the Application records the AI model used, input and output token counts, processing mode, and timestamp to the user's account record. This data is used for billing, quota enforcement, and service monitoring.
- Cumulative Token Consumption. Total AI tokens consumed, tracked for billing and usage cap enforcement.
- Subscription Status. Tier classification (Core or Apex) and associated usage quotas.
- Anonymous Rate Limiting. For users who have not signed in, a one-way truncated cryptographic hash of the user's IP address is stored temporarily alongside a daily request counter. The Company does not store or retain raw IP addresses; only the truncated hash is persisted. The hashed identifier is used solely to enforce rate limits on anonymous cloud AI requests, and is automatically deleted on a recurring basis when no longer needed for rate-limit enforcement.
Not Collected. The following activities are tracked exclusively on the user's local device and are not intentionally transmitted to Company servers during normal Application operation: workflow executions, device profiling operations, terminal command history, learned command patterns, and all other local feature activity.
2.3 Information Stored Locally
- Network Credentials. SSH passwords, private keys, and enable passwords, stored using the Electron safeStorage API with operating system-level encryption.
- Device Configurations. Running configurations, interface states, and routing tables captured during device profiling operations.
- Terminal Session Data. Command history and terminal output, retained in volatile memory during active sessions.
- User Knowledge Base. User-uploaded PDF documents, learned command patterns, and custom workflows.
- Local AI Models. Machine learning models for local inference, including Google Gemma model variants and the Nomic embedding model.
- MCP Activity Records. A recent in-memory log of requests made through the MCP Server, and a local list of read-command families run outside the Application's command catalog (operating system and command family only). See Section 4.4.
3. Use of Information
3.1 Primary Purposes
The Company uses collected information for the following purposes:
- Service Delivery. To authenticate users, process subscription payments, and provide access to Application features according to subscription tier.
- AI-Assisted Features. To provide command suggestions, troubleshooting analysis, and workflow automation. When cloud-based AI features are used, the Application applies an automated Sanitization Service that is designed to detect and redact network credentials, cryptographic keys, and other sensitive data from prompts before they are sent to the AI provider. Users may enable Privacy Mode to process all AI queries locally with no external transmission.
- Security and Fraud Prevention. To detect and prevent unauthorized access, abuse, or circumvention of usage limitations.
- Service Improvement. To analyze aggregate usage patterns for the purpose of improving Application functionality.
3.2 Data Processing for AI Features
When users engage cloud-based AI features, including the Copilot sidebar, War Room analysis, and Command Deck automation, the Application transmits contextual information to third-party AI providers after applying automated sanitization.
Sanitization Service. The Company has implemented a sanitization layer as a commercially reasonable measure to reduce the risk of sensitive network credentials being included in data transmitted to third-party AI providers. Prior to transmission, the Sanitization Service applies numerous pattern-matching algorithms designed to detect and redact common credential formats. This service represents a best-effort safeguard and does not constitute a guarantee that all sensitive information will be detected or redacted.
The following categories of secrets are targeted for automatic redaction:
Authentication Credentials:
- Passwords in all formats (plaintext, Type 5, Type 7, Type 8, Type 9, bcrypt, scrypt)
- Enable secrets and privilege escalation credentials
- TACACS+ and RADIUS shared secrets
- LDAP bind credentials and Active Directory service account passwords
Cryptographic Materials:
- RSA, ECDSA, and Ed25519 private keys
- X.509 certificates containing private key material
- IKE/IPsec pre-shared keys and Phase 1/Phase 2 secrets
- TLS/SSL private keys and certificate signing request private components
Network Authentication Secrets:
- SNMP v1/v2c community strings (read-only and read-write)
- SNMP v3 authentication and privacy passwords
- BGP, OSPF, and IS-IS routing protocol authentication keys
- VRRP, HSRP, and GLBP authentication strings
- MACsec connectivity association keys (CAK/CKN pairs)
Access Tokens and API Keys:
- Bearer tokens and JWT secrets
- API keys and webhook signing secrets
- Cloud provider access credentials
- OAuth client secrets and refresh tokens
Transparency and Auditability. Each sanitization operation is logged to a local audit trail accessible through the Application's Privacy Shield panel. Users may review the count of secrets redacted, categories detected, and timestamps in real time. This transparency enables users to verify that the sanitization layer is actively protecting their data.
DISCLAIMER OF WARRANTY. NOTWITHSTANDING THE FOREGOING, THE SANITIZATION SERVICE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. THE COMPANY DOES NOT WARRANT THAT THE SANITIZATION PROCESS WILL DETECT OR REDACT ALL SENSITIVE INFORMATION. Users are expressly advised of the following inherent limitations:
- Custom credential formats or proprietary authentication mechanisms may not match predefined patterns.
- Obfuscated or encoded secrets (e.g., Base64-encoded passwords in configuration comments) may evade detection.
- Contextual secrets embedded in natural language descriptions or non-standard formats may not be recognized.
- The Company cannot anticipate every possible credential format across all network vendors and software versions.
User Responsibility. Users remain solely responsible for reviewing AI prompts before submission and for ensuring that sensitive information is not inadvertently disclosed. The sanitization layer is a technical safeguard designed to reduce risk, not eliminate it.
Privacy Mode. Users who wish to prevent AI-related data from being transmitted to external services may enable Privacy Mode. When active, Privacy Mode routes all AI inference to local models running entirely on the user's device. Privacy Mode is designed to prevent external data transmission for AI processing purposes. The Company does not warrant that Privacy Mode will prevent all forms of network communication by the Application or the underlying operating system.
4. Third-Party AI Providers
4.1 Google Cloud / Vertex AI
The Application utilizes Google's Gemini API through the Vertex AI platform for cloud-based AI inference. The Company maintains a paid commercial relationship with Google Cloud.
According to Google's published terms for paid API tiers as of the date of this Policy:
- No Training on User Data. Google states that user prompts, responses, and contextual data submitted through paid API tiers are not used to train, tune, or improve Google's generative AI models.
- Compliance Certifications. Google Cloud reports compliance with SOC 1, SOC 2, and SOC 3 standards.
- Data Processing. Google processes data pursuant to its Data Processing Addendum, available at https://cloud.google.com/terms/data-processing-addendum.
THE COMPANY DOES NOT WARRANT OR GUARANTEE THE ACCURACY, COMPLETENESS, OR CONTINUED APPLICABILITY OF GOOGLE'S POLICIES. Google's terms are subject to change without notice from the Company. Users are encouraged to review Google's current data handling terms independently.
4.2 Local AI Models
The Application includes local AI models that execute entirely on the user's device:
- Google Gemma 4 family (E2B, E4B, 12B, 26B-MoE) (licensed under Apache License 2.0)
- Nomic Embed Text v1.5 (bundled with the installer, licensed under Apache License 2.0)
When operating in Privacy Mode, AI inference is performed locally. Privacy Mode is designed to prevent the transmission of user data to external AI services for processing purposes. The Company does not warrant that Privacy Mode will prevent all forms of network communication by the Application or the underlying operating system.
For local AI model troubleshooting purposes, the Application writes diagnostic logs from the initialization phase only of each local model run to a file in the user's application data directory (path varies by operating system; on Windows: `%APPDATA%\puttmarks\logs\gemma-init.log`). These logs capture model metadata (model name, GPU device names, context size, initialization step status, and error messages) and do not capture inference content (user prompts, model responses, or terminal output). Logs are local-only, are not transmitted to the Company or any third party, and may be deleted manually by the user at any time without affecting application functionality.
4.3 Bring Your Own Key (BYOK): User-Provided API Keys
The Application includes a feature that allows Apex-tier subscribers to provide their own API keys for third-party AI services, including but not limited to Google Gemini, OpenAI, Anthropic, xAI (Grok), and Groq (the "BYOK Feature"). When BYOK is active, user prompts, contextual data, and associated content are transmitted directly from the Application to the third-party AI provider designated by the user's API key.
Data Routing. When using the BYOK Feature, the Application routes AI requests directly to the third-party provider's API endpoints using the user's provided API key. These requests bypass the Company's cloud infrastructure entirely.
Sanitization. The Company's automated Sanitization Service (described in Section 3.2) is applied to all outbound AI requests, including those routed through the BYOK Feature. The same credential redaction and sensitive data detection measures are applied before data is transmitted to the third-party provider. The limitations of the Sanitization Service described in Section 3.2 apply equally to BYOK requests.
Key Storage. User-provided API keys are stored locally on the user's device using operating system-level encryption (Electron safeStorage API). API keys are never transmitted to Company servers.
Third-Party Privacy Policies. When using the BYOK Feature, your data is subject to the privacy policy, terms of service, and data handling practices of the third-party AI provider associated with your API key. THE COMPANY HAS NO CONTROL OVER, AND ASSUMES NO RESPONSIBILITY FOR, HOW THIRD-PARTY AI PROVIDERS PROCESS, STORE, RETAIN, OR USE DATA TRANSMITTED THROUGH USER-PROVIDED API KEYS.
Users are solely responsible for:
- Reviewing and understanding the privacy policy and terms of service of their chosen third-party AI provider.
- Ensuring that their use of third-party API keys complies with their organization's security and data governance policies.
- Understanding the data retention, training, and usage policies of their chosen provider, which may differ from the Company's arrangements with its own AI providers.
- Any costs, charges, or fees incurred through the use of their own API keys.
No Liability for Third-Party Data Handling. THE COMPANY EXPRESSLY DISCLAIMS ALL LIABILITY FOR ANY DATA LOSS, UNAUTHORIZED ACCESS, DATA BREACH, OR OTHER ADVERSE CONSEQUENCE ARISING FROM THE TRANSMISSION OF DATA TO THIRD-PARTY AI PROVIDERS THROUGH THE BYOK FEATURE. Users acknowledge that the Company cannot guarantee the security, privacy, or confidentiality practices of third-party providers.
4.4 Model Context Protocol (MCP) Features - Local Server and External Connectors
The Application includes two optional features built on the Model Context Protocol ("MCP"), an open standard for connecting software tools to AI assistants. Both are off by default, are available only to qualifying subscription tiers, and are disabled while Privacy Mode is on, subject to the Privacy Mode limitations described in Section 3.2. Both features move information between the Application and software the Company does not operate, and are described separately below. While these features are designated as experimental, they may be less stable or subject to change without notice; see Section 7.4 and Section 12.5 of the Terms of Service.
MCP Server (sharing device sessions with a client program you choose). When you turn the MCP Server on, the Application listens only on your own computer's loopback interface (127.0.0.1), which is not directly reachable from your network. If you forward, tunnel or otherwise expose that port, you do so at your own risk and the Company is not responsible for the result. A client program (for example, an AI coding assistant running on the same computer) can connect only after you generate a short-lived pairing secret in the Application and then approve that specific client in the MCP panel; you may revoke any client at any time. You choose which terminal sessions are shared, per session or per group. The server is designed to be read-only, meaning it is not intended to make persistent configuration changes; its tools still interact with device state and generate network traffic. It exposes only tools that list the sessions you shared, run a bounded set of read-only show commands, run ping and traceroute with fixed limits, compare the output of a read across shared devices, and answer questions from the Application's built-in knowledge base. No tool it exposes changes device configuration, and commands that are not reads are designed to be refused. THE COMPANY DOES NOT WARRANT THAT THIS RESTRICTION WILL PREVENT EVERY UNINTENDED DEVICE INTERACTION, AND YOU REMAIN SOLELY RESPONSIBLE FOR THE DEVICES YOU CHOOSE TO SHARE.
How a read reaches the device. To run a read without disturbing your interactive terminal, the Application uses an isolated channel on your existing device connection. On operating systems that do not support a separate command channel, this means the Application opens an additional hidden session on that same connection and may issue the device's standard pager-disable and privilege-escalation commands on it, using the credentials you already provided for that session. Where a device refuses an additional session, you may turn on a further per-share setting that lets a read be typed into your own interactive terminal for that session only while you are not using it: the Application first checks that no key has been pressed for several seconds and that the terminal is at an ordinary command prompt, writes a visible marker line, pauses your keyboard input for the duration of the read, and cancels the read if you press a key. Operating systems and situations for which none of these paths is available are refused rather than read. You are responsible for ensuring that the accounts used for shared sessions carry only the privileges you intend.
What the client receives. Output from a shared device is processed by the Company's automated Sanitization Service (described in Section 3.2) before it is returned to the paired client, and the same limitations described in Section 3.2 apply. Device output, hostnames and commands returned to a paired client are transmitted only to that client on your computer; they are not transmitted to Company servers by the Application. The server also hands the client a fixed instruction text describing its own rules and limits; that text contains no user or device data, is descriptive product information rather than a warranty, and does not modify this Policy or the Terms of Service. THE PAIRED CLIENT IS THIRD-PARTY SOFTWARE THAT YOU SELECT, CONFIGURE AND AUTHORIZE. THE COMPANY DOES NOT CONTROL THAT CLIENT, ANY AI AGENT OPERATING THROUGH IT, OR THE CLIENT'S SELECTION, SEQUENCING OR INTERPRETATION OF TOOL CALLS, AND ASSUMES NO RESPONSIBILITY FOR HOW IT STORES, TRANSMITS OR FURTHER PROCESSES THE INFORMATION IT RECEIVES (INCLUDING ANY TRANSMISSION TO AN AI PROVIDER USED BY THAT CLIENT). The client's storage, onward transmission and other downstream handling are governed by its own privacy policy and terms; this Policy continues to govern the Application's own processing before information is delivered to the client.
Extended reads (per-share consent). By default the server runs only commands present in the Application's command catalog. You may separately turn on "extended reads" for an individual share, which permits additional read-only show and display commands that pass the Application's read gate: on operating systems for which the Company maintains a verified command list, listed command families receive typed-argument checks; other read commands are screened by a deny list of configuration dumps, credential and key material, command history and diagnostic bundles, and by the Company's per-operating-system rules. Verified command families are checked against a laboratory device or, where the Company has no such device, against vendor documentation; this is an internal quality process and not a warranty of correctness or of device behaviour. Extended reads include reading sections of the device's running configuration (for example one interface or one routing process). This per-share authorization (the "extended reads" switch; it is not a statutory privacy consent) is recorded per share and is designed to be cleared automatically if the Company's rules for that operating system widen, so that you are asked again.
Full configuration reads (separate per-share setting). Reading a device's whole running configuration in one response is off unless you turn it on for that share yourself; the Application does not enable it for you, and turning extended reads off turns it off with it. Startup configurations, saved configurations, archives, checkpoints and technical-support bundles are not returned over the MCP interface in any setting. Full configuration output passes through the Sanitization Service like all other output, and a full configuration is the densest place for a secret the Sanitization Service does not recognize, which is why this setting is separate and off by default. Long results are returned in pages; the Application keeps the sanitized result in memory for a short period so the client can request the next page without the device running the command again. Turning it off, unsharing, revoking a client, stopping the server or enabling Privacy Mode ends the client's access. A command that is already in flight is cancelled within a few seconds, and its output is not released to the client; the device may already have begun executing it.
Local records only. The Application keeps a recent activity log of MCP requests in the Application's memory only (including the client, the tool, the shared-session identifier, the outcome, byte and redaction counts, and a one-way digest of the command, never the command text or the device output; a digest of a common command could in principle be matched against a guess, so it is not a guarantee of anonymity); it is limited to a recent window, is viewable in the MCP panel, and is discarded when the Application closes. The Application also keeps a small local file listing which read-command families were run outside the catalog (operating system and command family only; never the command arguments, hostnames or output); individual entries can be removed in the Application. Per-tier usage counters used to enforce daily limits are likewise kept locally, together with a one-way digest of the signed-in account identifier used to attribute them. None of these records is transmitted to the Company or to any third party by the Application during normal operation. Because they are stored locally and are not held in Company systems, the Company generally cannot retrieve or delete them in response to a server-side privacy request; you manage them through the Application or your device.
Remote controls. The Company may change which subscription tiers can use the MCP Server, adjust its limits, or disable it remotely through the Application's hosted configuration, for example in response to a security issue, at any time and without notice.
MCP Connectors (connecting the Application to external MCP servers). Qualifying subscribers may connect the Application to MCP servers operated by third parties or by your own organization (for example, a network monitoring system). When you use an external connector, the Application sends the requests you initiate (tool calls and their parameters, which are passed through the Sanitization Service before they leave the Application) to that server, and the results it returns may be included as context in your AI requests, where they are handled in the same way as other AI request content under Sections 3.2, 4.1 and 4.3, including sanitization before transmission to an AI provider. Any credentials or OAuth tokens you provide for an external server are stored locally using operating-system-level encryption (Electron safeStorage API) and are not transmitted to Company servers by the Application. THE COMPANY HAS NO CONTROL OVER, AND ASSUMES NO RESPONSIBILITY FOR, EXTERNAL MCP SERVERS OR HOW THEY PROCESS, STORE OR USE DATA YOU SEND TO THEM.
Users are solely responsible for:
- Selecting, vetting and securing any client program they pair with the MCP Server, and any external MCP server they connect.
- Reviewing and understanding the privacy policy, terms of service and data-handling practices of that client or server, including any AI provider it transmits to.
- Choosing which terminal sessions to share, and with which device accounts and privilege levels.
- Configuring and supervising any paired client or AI agent, reviewing the access granted to it, and accepting responsibility for tool calls it initiates within that access.
- Ensuring that pairing a client or connecting an external server complies with their organization's security, data-governance and change-control policies, and with any authorization required for the devices involved.
- Any costs, charges or fees incurred through their chosen client, external server or its AI provider.
No Liability for Paired Clients or External MCP Servers. THE COMPANY EXPRESSLY DISCLAIMS ALL LIABILITY FOR ANY DATA LOSS, UNAUTHORIZED ACCESS, DATA BREACH, DEVICE DISRUPTION, OR OTHER ADVERSE CONSEQUENCE ARISING FROM A CLIENT PROGRAM PAIRED WITH THE MCP SERVER, FROM AN EXTERNAL MCP SERVER CONNECTED BY THE USER, OR FROM ANY AI PROVIDER USED BY EITHER. Users acknowledge that the Company cannot guarantee the security, privacy, or confidentiality practices of any such client, server, or provider, and that a paired client operates with whatever access the user has granted it.
5. Disclosure of Information
The Company does not sell, rent, or trade user information to third parties for marketing purposes.
Information may be disclosed in the following circumstances:
- Service Providers. To third-party vendors who perform services on our behalf, including cloud infrastructure (Google Firebase), payment processing (Lemon Squeezy), and AI inference (Google Cloud).
- Legal Compliance. When required by applicable law, regulation, legal process, or governmental request.
- Protection of Rights. To protect the rights, property, or safety of the Company, its users, or the public.
- Business Transfers. In connection with a merger, acquisition, or sale of assets, subject to the acquiring entity's agreement to honor this Policy.
6. Data Retention
The Company retains information as follows:
- Account Information. Retained for as long as the account is active, and thereafter as the Company determines reasonably necessary.
- Usage Metrics. Retained for as long as reasonably necessary to provide billing, quota enforcement, fraud prevention, and service monitoring, and otherwise as the Company determines appropriate.
- Anonymous Rate Limit Data. Hashed IP counters are automatically deleted on a recurring basis when no longer needed for rate-limit enforcement.
- Subscription Records. Retained as required by applicable tax and accounting regulations.
- Local Data. User-controlled; retained on the user's device until manually deleted by the user.
- MCP Local Records. The MCP activity log is held in memory only and is discarded when the Application closes; the uncatalogued-read list is retained on the user's device, is bounded in size, and may be removed entry-by-entry by the user.
7. Data Security
The Company implements reasonable technical and organizational measures to protect user information, including:
- Encryption at Rest. Local credentials are encrypted using the Electron safeStorage API, which leverages operating system-level encryption facilities.
- Encryption in Transit. The Application is designed to utilize TLS or similar industry-standard encryption for communications with Company servers and third-party services.
- Access Controls. Administrative access to cloud infrastructure is restricted to authorized personnel on a principle of least privilege basis.
- Dependency Monitoring. Open-source dependencies are monitored for known security vulnerabilities.
Notwithstanding these measures, no method of transmission over the Internet or electronic storage is completely secure. The Company cannot guarantee absolute security of user information.
8. User Rights
8.1 General Rights
All users may exercise the following rights:
- Access. Request a copy of personal information held by the Company.
- Correction. Request correction of inaccurate personal information.
- Deletion. Request deletion of personal information, subject to legal retention requirements.
- Portability. Request export of personal information in a machine-readable format.
- Restriction. Limit data processing by enabling Privacy Mode, which prevents cloud AI transmission.
To exercise these rights, contact the Company at scott@rtrgrd.sh.
8.2 European Economic Area and United Kingdom
Users located in the European Economic Area or United Kingdom are entitled to additional rights under the General Data Protection Regulation (GDPR), including the right to object to processing based on legitimate interest and the right to lodge a complaint with a supervisory authority.
8.3 California Residents
Users who are California residents are entitled to additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:
- The right to know what personal information is collected, used, and disclosed.
- The right to delete personal information.
- The right to opt-out of the sale of personal information. The Company does not sell personal information.
- The right to non-discrimination for exercising privacy rights.
9. Children's Privacy
The Application is intended for use by network engineering professionals and is not directed at individuals under eighteen (18) years of age. The Company does not knowingly collect personal information from children. If you believe that a child has provided personal information to the Company, please contact us immediately at scott@rtrgrd.sh.
10. International Data Transfers
User information may be transferred to and processed in the United States, where the Company's service providers maintain infrastructure. For users located in the European Economic Area or United Kingdom, the Company relies on the appropriate transfer mechanisms (such as Standard Contractual Clauses or equivalent safeguards) implemented by its third-party service providers, where such mechanisms are applicable and available. The Company does not independently execute Standard Contractual Clauses with individual users.
11. Updates to This Policy
The Company may update this Policy from time to time to reflect changes in practices or applicable law. The "Last Updated" date at the top of this Policy indicates when revisions were last made. For material changes, the Company will provide notice through the Application interface or via email to registered users.
Continued use of the Application following the posting of changes constitutes acceptance of the revised Policy.
12. Contact Information
For questions regarding this Policy or to exercise your privacy rights, contact:
Privacy Inquiries
Email: scott@rtrgrd.sh
The Company will respond to verified privacy requests as required by applicable law.
13. Governing Law
This Policy shall be governed by and construed in accordance with the laws of the State of New Mexico, United States, without regard to principles of conflict of laws. The exclusive venue for any dispute arising under this Policy shall be the state or federal courts located in Sandoval County, New Mexico.
This Privacy Policy is intended to describe the Company's data practices as of the Effective Date. The Company reserves the right to interpret and apply this Policy in its sole discretion.