Privacy Policy
Effective: July 6, 2026 · GreenStacks LLC · Atlanta, GA
GreenStacks LLC ("GreenStacks," "we," "us") operates the iMagic Shield, Brain Shield HR/Legal, and Deep Audit software-as-a-service products. This Privacy Policy describes the personal information we collect, how we use it, the limited circumstances in which we disclose it, and the choices available to you. This policy applies to visitors of our marketing site, licensed subscribers of the Client Portal, and third-party subjects whose public-profile data is processed by the Deep Audit engine.
1. Information We Collect
Account & billing data: legal entity name, signer name/title, business email, last 4 of payment method, Stripe customer ID, subscription tier, and seat count.
Portal telemetry: IP address, user-agent, session timestamps, and hash-key usage events, retained for breach forensics.
Bring-Your-Own-Key credentials: third-party AI provider keys (OpenAI, Anthropic, Google) are encrypted at rest with AES-256-GCM using a per-tenant HKDF-SHA256 derived key and are never logged in plaintext.
Deep Audit inputs: subscriber-declared authorized handles, ownership-verification tokens (OAuth, DNS TXT, or bio-code), and signed Acceptable Use / Data Processing acknowledgments.
Public follower metadata: handle strings and numeric authenticity scores extracted from platforms subscribers have verifiably authorized. We do not collect direct messages, phone numbers, real names, or private profile fields.
2. How We Use Information
To provision and secure your subscription, deliver hash keys via one-time redemption links, enforce anti-weaponization guardrails on the Deep Audit service, respond to support requests through owner@greenstacksllc.com, comply with tax law (Stripe txcd_10103001), and defend the platform against fraud, brute-force attempts, and unauthorized access.
3. Deep Audit Compliance & Federal Regulations
The Deep Audit engine is a federally sensitive workflow. Before any extraction runs, every subscriber MUST satisfy the following verifications enforced in code and audited by GreenStacks:
- Signed Deep Audit Agreement: a 4-factor acknowledgment covering the Acceptable Use Policy, Data Processing Addendum, Anti-Harassment clause, and Indemnification. Timestamps are captured per acknowledgment.
- Handle Ownership Proof: the subscriber must prove control of each target handle via OAuth token exchange, DNS TXT record on a verified domain, or a temporary bio-code token displayed on the live public profile.
- Admin Approval: a human GreenStacks reviewer manually flips the contract to
approvedafter cross-checking the legal entity, signer identity, and handle-ownership evidence. - 30-Day Cool-Down: a database trigger blocks repeat extraction of the same (platform, handle) target within 30 days, preventing weaponization of the service.
- Row-Level Watermarking: every exported follower row is SHA-256 watermarked with a per-job seed so leaks are traceable to the licensee.
These controls are designed to align with the federal-contracting standards our government subscribers require: 44 U.S.C. § 3552 (FISMA) definitions of information system boundaries, NIST SP 800-53 rev. 5 controls AC-2 (Account Management), AC-6 (Least Privilege), AU-2 (Audit Events), and IA-5 (Authenticator Management); FTC Section 5 prohibitions on unfair or deceptive data practices; and Section 230(c)(2) good-faith moderation. GreenStacks does not represent Deep Audit as a certified FedRAMP or CMMC service; it is a self-serve licensed tool designed to be operable inside a subscriber's compliance envelope.
4. How We Verify Subscribers of Deep Audit
Prior to approval, GreenStacks reviews:
- Legal-entity name matched against public state-of-incorporation records or a federal SAM.gov CAGE code where applicable.
- Signer email domain matched against the legal entity's registered domain (webmail is escalated for live verification).
- Handle ownership evidence (OAuth callback receipt, DNS TXT re-check, or bio-code visible on the live profile).
- Payment method last-4 tied to a business card or ACH on the same legal entity.
- For government and enterprise tiers: a recorded Google Meet identity confirmation with the signer prior to first extraction.
Verification artifacts are retained for the life of the subscription plus 7 years for audit response. Verification failures are logged, and the subscriber is notified via the signer email of record.
5. Sharing & Disclosure
We do not sell personal data. We share data only with (a) Stripe for billing, (b) Supabase (Lovable Cloud) for hosted storage under a DPA, (c) the subscriber's own AI provider using BYOK, and (d) law enforcement pursuant to a lawful process where required. Deep Audit extraction results are visible ONLY to the requesting subscriber and to GreenStacks admins running verification.
6. Retention & Deletion
Chat conversations and portal telemetry: 24 months. Deep Audit CSV exports: 7-day signed URL, purged from storage after 30 days. Ownership-verification tokens: destroyed on success or 14 days after issuance. On subscription termination, a written deletion request to owner@greenstacksllc.com will trigger removal of tenant PII within 30 days, excluding records required for tax and audit retention.
7. Your Rights (GDPR / CCPA / CPRA)
You may request access, correction, deletion, portability, or restriction of your personal data by emailing owner@greenstacksllc.com. We verify requests using the signer email of record and, for high-risk requests, a live video confirmation. We do not discriminate against users who exercise their rights.
8. Security
Encryption in transit (TLS 1.2+), encryption at rest (Supabase-managed AES-256), tenant-scoped Row-Level Security on every public table, AES-256-GCM envelope encryption for API keys and hash-key issuance tokens, and 24/7 kill-switch recovery via /recover-hashkey.
9. Contact
GreenStacks LLC · owner@greenstacksllc.com · Atlanta, GA · Response window: 24–48 hours.