Legal

PRIVACY POLICY

Effective date: 1 June 2026  ·  Last updated: 1 June 2026  ·  blackbox.fyi
Plain language summary
What we collect
Form inputs for report generation. Payment details (via Stripe, not stored by us). Technical access logs.
What we do not do
We do not sell your data. We do not run advertising. We do not retain report content longer than necessary.
Your rights
Access, correction, deletion, and data portability. Contact us at privacy@blackbox.fyi.
Cookies
Session authentication cookie only. No tracking cookies unless you explicitly consent.
01
Who we are

BlackBox is operated by BlackBox Intelligence Ltd ("we", "us", "our"). This policy explains how we collect, use, store, and protect personal data when you use the BlackBox platform at blackbox.fyi.

We are the data controller for personal data processed through the Service. For GDPR purposes, our lawful bases for processing are contract performance (generating the report you requested) and legitimate interests (platform security and abuse prevention).

02
What data we collect

We collect the following categories of data:

Category Examples Why we collect it
Report inputs Location, operation type, situation brief, subject name, email (if provided) To generate the intelligence briefing you requested
Account data Email address, subscription tier Account management and billing
Technical data IP address, browser type, access timestamps Security, abuse prevention, platform reliability
Payment data Transaction records (payment details handled by Stripe) Billing and fraud prevention, card details are never stored by us
Cookies Session authentication token (bb_auth) Maintaining your authenticated session, no tracking cookies by default

Third-party subject data. When you provide a subject name, email, domain, or other information about a third party for enrichment purposes, you are responsible for ensuring you have a lawful basis to process that information and that its use complies with applicable data protection law in your jurisdiction.

03
How we use your data

We use your data to:

We do not sell your personal data to third parties. We do not use your data for targeted advertising. BlackBox products are ad-free.

04
Data sharing

We share data only with the following categories of third party, and only to the extent necessary:

We will disclose personal data to law enforcement or regulatory authorities where required to do so by applicable law, or to protect the rights, property, or safety of BlackBox, our users, or third parties.

05
Data retention

We retain report inputs and outputs for a limited period for quality assurance, abuse prevention, and legal compliance purposes. We do not retain report content indefinitely. Technical access logs are retained for up to 90 days.

Account data is retained for as long as your account is active, and for a reasonable period thereafter to comply with legal obligations and resolve disputes. You may request deletion of your data at any time (see Your Rights below).

06
Cookies

BlackBox uses a single authentication cookie (bb_auth) to maintain your session after you enter your access code. This cookie is HTTP-only and expires after 7 days.

We do not set tracking, analytics, or advertising cookies by default. If you accept optional cookies via our consent banner, we may set analytics cookies to understand how the platform is used. You may withdraw this consent at any time by clearing your cookies or declining via the banner.

07
Your rights

If you are a resident of the UK, European Union, or California, you have the following rights regarding your personal data:

To exercise any of these rights, contact us at privacy@blackbox.fyi. We will respond within 30 days. Where we cannot satisfy your request, we will explain why.

If you believe we have not handled your data appropriately, you have the right to lodge a complaint with the relevant supervisory authority (in the UK: the ICO; in the EU: your national data protection authority).

08
Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. Access to platform systems is restricted. Sensitive configuration values are stored as environment variables, not in source code.

No method of transmission over the internet is completely secure. We cannot guarantee absolute security, but we take it seriously and will notify you if we become aware of a breach affecting your data.

09
International transfers

Our platform is hosted on infrastructure that may process data in the United States and other jurisdictions. Where we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, including standard contractual clauses or equivalent mechanisms recognised under applicable data protection law.

10
Children

BlackBox is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact us immediately at privacy@blackbox.fyi.

11
Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be communicated via a notice on the platform or by email. The date at the top of this page indicates when it was last updated. Continued use of the Service after changes take effect constitutes your acceptance of the updated policy.

12
Contact

Privacy enquiries: privacy@blackbox.fyi

General enquiries: hello@blackbox.fyi

BlackBox Intelligence Ltd · blackbox.fyi