Privacy policy
Last updated: 3 October 2026
This policy explains what personal data Shadelyt ("we", "us") collects, why, where it is kept, for how long, and the choices you have. It covers our website shadelyt.com, our portal and sign-in page, and Roger Shadelyt, the software and hosted service we provide.
The short version
- Our website sets no cookies, runs no analytics or trackers, and loads nothing from other companies.
- Roger Shadelyt checks what people send to AI tools on their own PC. The text itself is never sent to us or stored anywhere.
- A customer's events, people and policies stay in that customer's own console and database. We see licence information only.
- We don't sell personal data, and we don't use anyone's data to train AI models.
Who we are
Shadelyt makes Roger Shadelyt and runs shadelyt.com. We are based in India. For anything about this policy or your data, write to reachus@shadelyt.com. The same address reaches our grievance officer under India's Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
Visiting our website
shadelyt.com sets no cookies and runs no analytics or advertising code. The "try it" box and the exposure self-check run entirely in your browser: what you type there is never sent to us. Like every web server, ours receives your IP address and the page you ask for in order to answer; it keeps no log of website visits.
If you email us, we receive your address and what you write, and keep it as long as we need to answer and follow up (see how long we keep it).
If your company is our customer
To provide the service and bill for it, we keep:
| What | Why |
|---|---|
| Your company's name and country, and the contact people you give us (name, work email, phone) | Contracts, setup, support and billing |
| The work email addresses you license for your hosted console, and their roles | To send invitations and sign-in links only to those people |
| Your plan, number of PCs, paid-until date, payments and invoices | Billing, and keeping your licence valid |
| What your console reports to us every hour: its licence key, version, host name and the address it connects from; how many PCs it has, how many are active and protected; agent versions; and how many PCs are healthy, offline or not protected | To keep your licence valid, offer updates, and spot problems early |
| A record of the changes we make to your account (who, what and when) | Accountability |
This is the only information about your company that reaches us. It contains no events, no content, and no names or details of your employees or their PCs.
Inside Roger Shadelyt
Roger Shadelyt runs on your company's PCs and in your company's console. When someone sends something to an AI tool, it is checked on their own PC. If something sensitive is found, the console records what was found (the kind of data, how many, and a masked value), the AI tool, the person and the PC, and what happened. The text itself is not stored or sent anywhere.
We run your console at yourcompany.shadelyt.com, and it keeps everything in a PostgreSQL database that
your company provides and controls. Our staff can't sign in to your console unless one of your owners turns on support
access, for the time and with the permissions that owner chooses. Every such visit is recorded in your console's audit
log.
For this data your company is the data fiduciary (the controller), and we act as its data processor, only on its instructions. If you are an employee whose PC runs Roger Shadelyt, please contact your employer about how your data is used. We give employers a data processing agreement on request, and a notice they can use to tell their employees about the tool.
Our portal and sign-in page
When someone asks for a sign-in link on login.shadelyt.com, we look up the address they typed. If it isn't licensed for any console, we keep the address typed, the IP address the request came from and the time, as a security alert: it helps us spot attempts to find out who our customers are. These alerts are kept for at most 13 months, and for at most 6 months once we have reviewed them.
For our own staff's portal accounts we keep sign-in times and addresses, and failed sign-in attempts. Our portal and sign-in page also keep short technical logs (IP address, time and the address asked for) to keep them secure and working; these are overwritten automatically.
Where data is kept, and who helps us
| Who | What for | Where |
|---|---|---|
| Our hosting provider | Our servers: the website, our portal, the sign-in page and hosted consoles | India |
| Our backup provider | A regular backup copy of our portal's records (customers, licences, payments, our staff accounts and alerts), sent over an encrypted connection. No console data. | Singapore |
| Our email provider | Our email, and the invitations, sign-in links and reminders we send | Its own data centres |
| Our payment provider, if you pay by card | Card payments. We never see full card numbers. | Under its own privacy policy |
Each provider is bound by contract to protect the data and use it only for us. Customers can ask us for their names. A hosted console's own data is in the PostgreSQL database its company chose, wherever that company keeps it. Where personal data is kept outside India (the backup in Singapore), we do so as the Digital Personal Data Protection Act allows. We will update this list before we add a kind of provider that handles personal data.
How long we keep it
- Customer accounts, contracts, invoices and payments: while you are a customer, then as long as Indian tax and company law requires (generally eight years).
- Emails and support conversations: up to two years after the matter is closed.
- Sign-in page alerts: at most 13 months (6 months once reviewed).
- Hosted consoles: when the service ends we remove your console and the keys we held for it. Your data is in your own database and stays yours.
- Backups follow the same periods: each backup replaces the previous one.
How we protect it
Encrypted connections, two-step sign-in for our staff and for every owner of a hosted console, access only for the people who need it, a record of who did what, and a security review of every release. If you find a security problem, please tell us as described on our contact page.
Your rights
Under India's Digital Personal Data Protection Act you can ask us for a summary of your personal data and how we use it, to correct, complete or update it, to erase it, to nominate someone to act for you, and to have a grievance addressed. Where we rely on your consent, you can withdraw it at any time. If the GDPR or UK GDPR applies to you, you can also ask us to restrict or stop using your data, object to it being used, or receive a copy in a portable format.
Write to reachus@shadelyt.com. We answer within 30 days. If your request is about data in a customer's console, we pass it to that customer, who decides about it. If you are not satisfied with our answer, you can complain to the Data Protection Board of India, or to your local data protection authority.
Children
Our website and services are for businesses, not for children, and we don't knowingly collect children's data.
Changes to this policy
When we change this policy we update the date at the top. If a change matters to our customers, we tell them by email before it takes effect.
Contact
Privacy questions and requests: reachus@shadelyt.com. Security issues: security@shadelyt.com.