Legal
Stronghold Intel — Privacy Policy
Last updated: August 4, 2026
1. Who we are and what this covers
Stronghold Intel LLC ("Stronghold Intel," "we," "us") operates a personal threat intelligence platform. We monitor open, deep, and dark web sources for exposures affecting individuals under protection, and deliver findings, briefs, and alerts to those individuals and to the organizations that protect them.
This policy covers:
- strongholdintel.com and any marketing or informational pages we publish
- The Stronghold Intel platform at https://stronghold-intel-platform.vercel.app
- Our email and SMS notification programs
- Business communications with prospective and current partner organizations
It does not cover the practices of the executive protection firms, family offices, or wealth management firms who engage us. Those organizations maintain their own privacy policies governing their relationships with their clients.
2. Our two roles
We handle personal information in two distinct capacities, and your rights differ depending on which applies.
As a service provider. When a partner organization engages us to monitor an individual, we collect and analyze personal information about that individual, and in some cases about their household members, staff, and advisors, on the partner's behalf and under written contract. We process that information only to deliver the contracted service. We do not use it to build products for other clients, we do not sell it, and we do not use it for our own marketing. Requests to access or delete that information are directed to the partner organization, and we assist them in responding.
As a business acting for ourselves. When you visit our website, create a platform account, provide your own mobile number for SMS alerts, or contact us directly, we determine how that information is used. This policy governs those activities, and you may exercise the rights in Section 11 with us directly.
3. Personal information we collect
Using the categories defined by California law:
| Category | Examples in our service |
|---|---|
| Identifiers | Name, email address, postal and residential address, telephone number, IP address, Auth0 account identifier |
| Customer records | Contact details, account and billing records for partner organizations |
| Commercial information | Subscription tier, service history, deliverables issued |
| Internet or network activity | Platform sign-in and access logs, pages and reports viewed, administrative audit records |
| Geolocation data | Primary and secondary residence addresses, travel itineraries and destination data submitted for travel risk briefings |
| Professional or employment information | Role and employment details for household staff, vendors, and third-party advisors included in an engagement's risk scope |
| Financial and digital asset identifiers | Public cryptocurrency wallet addresses and related on-chain exposure data |
| Sensitive personal information | Account credentials and passwords appearing in breach corpora, government identification numbers appearing in exposure data, precise location information |
| Inferences | Risk scores, exposure severity ratings, and threat profiles derived from the above |
About sensitive information specifically. We do not ask you to give us credentials or government identifiers. They reach us because they appear in breach corpora and criminal marketplace listings that we monitor on your behalf, which is the entire purpose of the service. We use that information only to detect, report, and help you remediate the exposure. We do not use or disclose sensitive personal information for any purpose other than performing the service, and we do not use it to infer characteristics about you.
4. Where the information comes from
- Directly from you, when you complete account setup, provide a mobile number, submit travel plans, or contact support
- From the partner organization that engaged us, during onboarding
- From public and commercial intelligence sources, which may include public records, data broker listings, social platforms, breach and credential corpora, and criminal marketplaces and forums. The specific sources we query change as the threat landscape does, and any provider that receives personal information from us is named in Section 7
- Automatically from your use of the platform, including access logs and device and browser information
Information about household members, staff, advisors, and other third parties comes from the partner organization or from the intelligence sources above, not from those individuals themselves. Section 12 explains how they can reach us.
5. Why we use it
- To detect and report exposures affecting the individuals we are engaged to protect
- To generate briefs, reports, risk scores, and remediation guidance
- To deliver alerts and notifications by email, SMS, and in the platform
- To authenticate users and control access to client information
- To maintain audit records showing who accessed what and when
- To operate, secure, support, and improve the platform
- To meet legal, regulatory, and contractual obligations
We do not use client information to serve advertising, and we do not use it to train publicly available or third-party AI models.
6. Mobile information and SMS
If you enroll in Stronghold Intel Security Alerts, we use your mobile number solely to send the transactional security notifications described in our SMS Terms of Service.
No mobile information is sold, rented, or shared with third parties or affiliates for marketing or promotional purposes. Your number is disclosed only to the telecommunications provider that transmits the message on our behalf.
Enrollment requires your own affirmative consent, given by you, for your own number. No partner organization or administrator can enroll a number on another person's behalf. Consent is optional and is never a condition of receiving the service. You can withdraw it at any time by replying STOP to any message or through your account settings, and doing so does not cancel any other part of your service.
7. Who we share it with
We disclose personal information to the following categories of service providers, each under contract limiting them to processing on our instructions:
| Function | Provider |
|---|---|
| Application hosting and delivery | Vercel |
| Database hosting | Neon |
| Identity and authentication | Auth0 (Okta) |
| Automated analysis and report generation | Anthropic |
| Transactional email delivery | SendGrid (Twilio) |
| SMS delivery | Twilio |
We do not currently transmit personal information to any third-party threat intelligence provider. If that changes, we will update this policy and notify partner organizations before the change takes effect.
We also disclose information:
- To the partner organization that engaged us, and to the individuals it authorizes, which is the ordinary operation of the service
- To professional advisors, including counsel, accountants, and insurers, under confidentiality
- To law enforcement or regulators, where legally required, or where we believe in good faith that disclosure is necessary to address a credible threat to someone's physical safety
- In connection with a corporate transaction, subject to this policy continuing to apply
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law.
8. Automated processing and the limits of our output
We use automated systems, including large language models, to analyze intelligence data and generate briefs, reports, and risk scores. A human analyst reviews findings in defined categories before release, and any individual may request human review of a finding that concerns them.
Our output is intelligence, not a consumer report. Stronghold Intel is not a consumer reporting agency, our findings are not consumer reports under the Fair Credit Reporting Act, and they must not be used, in whole or in part, as a factor in determining any person's eligibility for employment, credit, insurance, housing, or any other purpose covered by that statute. Partner organizations agree to this restriction contractually.
Our output is informational. If you face an imminent physical threat, contact law enforcement.
9. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the information we hold, including:
- Encryption in transit using TLS, and encryption at rest at the database layer
- Application-level encryption of designated personal information fields using AES-256-GCM, with keys held separately from the data
- Single sign-on with role-based access control, so that each user reaches only the client records assigned to them
- Audit logging of administrative and client-scoped access
- Least-privilege scoping of third-party API credentials
- Separate database branches and access credentials for production and development
No system is perfectly secure, and we do not represent that ours is. We maintain a documented incident response process and will notify affected parties and partner organizations as required by law and by contract.
10. How long we keep it
| Information | Retention |
|---|---|
| Client profile and monitoring data | For the term of the engagement, then deleted within 30 days of termination, unless the partner requests earlier deletion or return |
| Findings, briefs, and reports | For the term of the engagement, then deleted within 30 days of termination. A partner may request an export before deletion |
| Access and audit logs | 1 year from the date of the recorded event |
| SMS consent records | 4 years after consent is withdrawn or the engagement ends, whichever is later, as evidence that consent was validly obtained |
| Website and marketing contacts | Until you ask us to delete them, or 2 years after last contact |
Consent records are deliberately retained after withdrawal. We keep them to prove consent existed, not to contact you.
11. Your rights
Depending on where you live, you may have the right to know what personal information we hold about you, to obtain a copy of it, to correct it, to delete it, to limit our use of sensitive personal information, and to be free from retaliation for exercising these rights. California residents have these rights under the CCPA as amended by the CPRA, and residents of other states have comparable rights under their own laws.
To exercise a right, contact support@strongholdintel.com or (916) 542-9929. We will verify your identity before acting, using information already in our possession, and we will respond within the time your law allows. You may use an authorized agent, with written permission.
If your information reached us through a partner organization, we will acknowledge your request, forward it to that organization, and assist them in responding. We do not delete client information on our own initiative while an engagement is active, because doing so would remove a record that organization is relying on to protect someone.
Some requests are limited by law. We may decline to delete information we need to detect security incidents, prevent fraud or illegal activity, or comply with a legal obligation.
12. If you are not our user
You may appear in our systems without ever having contacted us, as a family member, household employee, vendor, advisor, or a person named in intelligence data. You have the same rights described above. Contact support@strongholdintel.com and we will identify the responsible partner organization, forward your request, and assist in responding. Tell us who you are and what you are asking for. You do not need to know which organization holds the engagement.
13. Children
The platform is not directed to children, and children do not hold accounts. A protective engagement may nonetheless cover a minor member of a household, and information about that minor may be collected and analyzed as part of it. Where it is, we act on the instruction of the partner organization and the consent of the parent or guardian obtained by that organization, we limit collection to what the service requires, and we apply the same protections described in Section 9. A parent or guardian may contact us at support@strongholdintel.com to ask what information about their child we hold.
14. Location of data
Personal information we hold is stored and processed in the United States. Our public website is delivered through a content delivery network with servers in many countries, which caches page content but does not store personal information. If you are located outside the United States, information about you will be transferred to and processed in the United States, where privacy laws may differ from those of your country.
15. Changes
We may update this policy. We will change the date at the top, and for material changes affecting how we use personal information we will provide notice through the platform or by email before the change takes effect.
16. Contact
Stronghold Intel LLC support@strongholdintel.com (916) 542-9929