Privacy Policy
Breachday LLC · breachday.io
Version 1.4 · Effective Date: October 5, 2026
Breachday LLC ("Breachday," "we," "us," or "our") provides a business-to-business cybersecurity and business continuity tabletop exercise platform. This Privacy Policy explains what personal information we collect, why we process it, how we protect and retain it, and the choices available to individuals.
This Policy applies to registered Account holders and organization users, Exercise Participants who join sessions without an Account, visitors to breachday.io, and users of the public scenario builder at breachday.io/build.
1. Privacy Roles and Contact
Breachday LLC is the controller of personal information it processes for its own business purposes, including Account administration, billing, website operation, security logging, support administration, and legal compliance.
For Customer Data entered into the Service, the Customer organization generally determines the purposes and means of processing and acts as controller; Breachday acts as processor under the DPA. Where an MSP or consultant uses the Service for a Client, the Client is generally the controller, the MSP acts as processor, and Breachday acts as the MSP's subprocessor.
Privacy and security contact: compliance@breachday.io
2. Information We Collect
2.1 Account Holders and Organization Users
When users create an Account or accept an invitation, we may collect:
- Name and business email address
- Password credential managed through Supabase Auth; Breachday does not store plaintext passwords
- Email verification status
- Organization name and slug
- User role within the Organization
- Two-factor authentication data, including TOTP secret and backup-code hashes, if enabled
- Profile image URL, if provided
- MSP role and client relationships, where applicable
- Platform administration status for authorized Breachday staff accounts
2.2 Billing and Subscription Data
Subscription and billing functions are provided through Stripe. Breachday may store Stripe customer and subscription identifiers, active price identifier, Subscription Term dates, subscription status, and lifecycle flags. Payment card numbers, CVV data, and bank account details are processed by Stripe and are not stored by Breachday.
2.3 Customer-Entered Organizational Data
Organizations may enter operational, security, business continuity, and program data that can describe real systems, processes, vendors, and personnel. Examples include:
- IT asset inventory, criticality, RTO/RPO targets, tags, and descriptions
- Vendor records, which may include business contact names, email addresses, phone numbers, and service terms
- Business Impact Analysis process records and dependencies
- Scenario narratives, injects, simulated artifacts, vote options, facilitator notes, and exercise responses
- Crisis communication templates
- Playbook PDF files and organization logos
- Lessons-learned records, including owner, status, and due dates
- Support ticket messages, including Customer-visible messages and internal support notes
Customer-entered content is Customer Data owned or controlled by the applicable Customer under the Terms of Service.
2.4 Exercise Participant Data
Participants join with a room code and optional password and are not required to create a Breachday Account, provide a legal name, or provide an email address. During a session, Breachday may process:
- Display name chosen by the Participant
- Role-seat selection
- Action responses and free-text submissions
- Votes and confidence-slider responses
- Hotwash sentiment and free-text feedback
- Session metadata such as room code, timestamps, pause duration, and facilitator identifier
- Participant session identifiers stored in browser storage for reconnection
- Technical request information such as IP address, request path, response status, and timestamp as described in Section 2.6
Participant records are associated with the Organization's Exercise Session. Breachday does not require direct identity information beyond the display name a Participant chooses, but technical information may constitute personal data under applicable law.
2.5 Public Scenario Builder (/build)
Drafts created in the public scenario builder are stored in browser local storage. Breachday does not persist those drafts as Customer Data. When a user requests a PDF or DOCX export, draft content is sent to Breachday transiently to generate the file and is not retained after generation. JSON exports may be generated locally in the browser.
2.6 Automatically Collected Technical Data
When the Service is used, Breachday may collect server and security logs such as IP address, HTTP method, request path, response status, timestamp, authentication and security events, and limited diagnostic information. Server and security logs are generally retained for up to 90 days unless a longer period is reasonably necessary to investigate a security event, enforce the Agreement, or comply with law. Public endpoint rate-limiting data may be retained only for the applicable rate-limiting window.
Breachday does not currently use third-party advertising trackers, retargeting pixels, or behavioral product-analytics SDKs to profile users across services.
The public marketing site (breachday.io) uses Google Analytics (gtag.js) to measure aggregate visitor traffic; see Section 4 (Cookies and Browser Storage).
2.7 Transactional Communications
Breachday uses Resend to deliver transactional communications such as email verification, password reset, organization invitations, support-ticket notifications, payment-failure notices, subscription lifecycle notices, and data-deletion reminders. Resend processes recipient email addresses and message content needed to deliver those communications.
2.8 AI-Assisted Features
The AI Scenario Builder sends scenario prompts and structural parameters through OpenRouter to an eligible inference provider. Breachday configures OpenRouter routing to require Zero Data Retention (ZDR) eligible endpoints and to deny provider data collection where supported. ZDR prevents eligible inference providers from persistently retaining prompt and response content after processing, but it does not prevent transient processing and does not prevent OpenRouter from retaining non-content request metadata under its own policies. Weekly Scenario Recommendations may use publicly available threat-intelligence headlines and Breachday template metadata. Breachday does not use Customer Data to train or fine-tune AI models.
3. How We Use Information
Breachday processes information for the following purposes:
- Providing, operating, authenticating, and securing the Service
- Delivering real-time exercises, report generation, and export functionality
- Managing subscriptions, billing, renewal, cancellation, and data lifecycle
- Providing customer support and communicating about support requests
- Sending account, security, billing, renewal, and deletion notices
- Preventing fraud, enforcing tenant isolation, rate limiting, investigating abuse, and verifying contractual plan or MSP usage
- Administering MSP client organizations and authorized staff access
- Maintaining backups, reliability, diagnostics, and business continuity
- Complying with law, lawful orders, accounting obligations, and legal claims
- Improving the Service using operational information that does not include using Customer Data to train AI models
Breachday does not sell personal information, rent personal information, or share personal information for cross-context behavioral advertising. Breachday does not use Customer Data for targeted advertising.
4. Cookies and Browser Storage
| Mechanism | Purpose | Persistence |
|---|---|---|
| Supabase authentication cookies (httpOnly) | Authentication and session management | Session / sliding expiry |
| Platform administration organization-choice cookie | Authorized Breachday staff tenant context | Session |
| localStorage: UI theme preferences | Light/dark theme preference | Persistent until cleared |
| localStorage: public builder draft | Stores /build draft locally on the user device | Persistent until cleared |
| localStorage: dashboard preferences | Table/card and similar UI preferences | Persistent until cleared |
| localStorage: participant rejoin data | Participant session identifier, role-seat identifier, and display name on the user device | Persistent until cleared |
| sessionStorage: participant session ID | Active room reconnection on page reload | Browser session |
| sessionStorage: realtime presence / UI flags | Realtime session presence and exercise-flow state | Browser session |
| Google Analytics cookies (_ga, _gid, _ga_*) | Aggregate visitor traffic measurement on the public marketing site (breachday.io) | Up to 2 years (_ga) / 24 hours (_gid) |
Authentication cookies are necessary for authenticated Service operation. Browser storage may be cleared through browser settings, but doing so can reset preferences or participant reconnection state.
The public marketing site uses Google Analytics cookies (_ga, _gid, _ga_*) to measure aggregate visitor traffic. Breachday does not use advertising trackers, retargeting pixels, or sell personal information.
5. Third-Party Service Providers and Subprocessors
Breachday uses service providers to operate the platform. Their roles and data access are limited to the services Breachday has engaged them to perform, subject to applicable contractual and legal obligations.
| Provider | Role | Data Processed |
|---|---|---|
| Supabase | Postgres database, Auth, Realtime, and Storage | Application data, authentication data, organization files, and real-time session events |
| Vercel | Next.js application hosting and serverless compute | HTTP request metadata and application request/response data passing through the hosting layer |
| Cloudflare | Backup and disaster-recovery storage | Encrypted backup copies of application data and stored files |
| Stripe | Payment processing and subscription management | Billing contact information, payment data held by Stripe, invoices, and subscription records |
| Resend | Transactional email delivery | Recipient email addresses and transactional message content |
| OpenRouter | AI model routing | AI Scenario Builder prompts/outputs and related request metadata; ZDR-eligible provider routing required for prompt/response content |
The current subprocessor list is maintained at breachday.io/subprocessors. Contractual subprocessor-change notice rights are described in the DPA.
6. Data Hosting and International Transfers
Breachday configures its primary application database, application deployment, and designated disaster-recovery storage for U.S. regions where supported by the applicable provider. Some service providers operate distributed or global infrastructure, and transient processing, network routing, fraud prevention, or support-related processing may occur in other locations consistent with the provider's services and Breachday's contractual controls.
Breachday currently targets U.S.-based customers. Breachday will not intentionally begin processing Customer Personal Data in a manner that constitutes a Restricted Transfer under the EU GDPR, UK GDPR, Swiss FADP, or similar law unless the parties have implemented an applicable legal transfer mechanism, such as Standard Contractual Clauses or another recognized mechanism, before the Restricted Transfer begins. The DPA governs those requirements.
7. Data Retention and Deletion
| Data Category | Typical Retention | Deletion Trigger / Notes |
|---|---|---|
| Account and Organization data | Active Subscription plus 6-month read-only retention period | Automatic purge at end of retention window or Organization self-deletion |
| Exercise session data | Active Subscription plus 6-month retention period | Earlier deletion if an eligible ephemeral-session policy is enabled |
| Ephemeral-session data | Configurable by Organization; default 48 hours after session completion where enabled | Automated cleanup |
| Playbook PDFs and organization logos | Active Subscription plus 6-month retention period | Deleted on Organization purge |
| Retained report data | Active Subscription plus 6-month retention period | Deleted on Organization purge |
| Billing and transaction records | As necessary for tax, accounting, fraud prevention, contractual, and legal compliance; generally up to 7 years where applicable | Retention may be controlled in part by Stripe and applicable law |
| Backup copies | Up to 7 days on a rolling basis | Encrypted disaster-recovery backups expire automatically; deletions are re-applied after restore |
| Server and security logs | Generally up to 90 days | Rolling deletion; may be retained longer for a specific security investigation or legal obligation |
| Password-reset and verification tokens | Until use or expiry | Deleted or invalidated on use/expiry |
| Unverified signup accounts without billing | Typically 15 days after signup | Automated deletion |
| Public /build draft | User device only; Breachday does not persist the draft | Cleared by user or browser |
When an Organization is deleted or its retention period ends, Customer Data is removed from active systems. Encrypted disaster-recovery copies may remain for up to 7 days, are not used for ordinary support or processing, and expire on the rolling backup cycle. If a backup is restored, recorded deletion requests are re-applied.
8. Security
Breachday maintains technical and organizational safeguards appropriate to the nature of the Service and Customer Data, including TLS for data in transit, encryption at rest through infrastructure providers, role-based access controls, tenant isolation, two-factor authentication support, rate limiting, security headers, backup controls, and privileged-action security logging. Detailed controls are described in the DPA and security documentation.
Breachday has not completed a SOC 2 examination as of this Policy's effective date. Certain infrastructure providers make independent security assurance reports or certifications available under their own programs. Breachday does not represent that a provider's audit report constitutes a Breachday SOC 2 report.
Security vulnerabilities may be reported to compliance@breachday.io. Please avoid public disclosure until Breachday has had a reasonable opportunity to investigate and remediate.
9. Rights and Choices
9.1 Account Access and Correction
Organization ADMINs and users can view or update certain Account information through the Service. Requests to correct information that cannot be self-managed may be sent to compliance@breachday.io.
9.2 Customer Data Requests
For Customer Personal Data processed by Breachday on behalf of an Organization, the Organization is generally responsible for responding to data-subject requests. Breachday will provide reasonable assistance as required by the DPA and applicable law.
9.3 Participant Data
Participants who want to request access, correction, or deletion of session data should ordinarily contact the Organization that conducted the exercise. A Participant may also contact compliance@breachday.io with the Organization name, approximate session date, and display name so Breachday can route or assist with the request where appropriate.
9.4 Applicable U.S. State Privacy Rights
Where Breachday acts as a controller or business and applicable state privacy law grants an individual rights such as access, correction, deletion, portability, opt-out, restriction, or appeal, Breachday will process verified requests as required by law. Requests may be sent to compliance@breachday.io. Breachday does not sell personal information or share it for cross-context behavioral advertising, so Breachday does not currently offer a sale/share opt-out mechanism for those activities. Where applicable law provides an appeal right, an individual may appeal a denied request by replying to the decision notice or contacting compliance@breachday.io.
9.5 Email Communications
Transactional emails required to operate an Account or Subscription cannot be opted out of while the Account remains active. Breachday does not send marketing emails unless the recipient has separately opted in or another lawful basis applies; marketing communications include an applicable unsubscribe method.
10. Sensitive and Regulated Data
The Service is designed for simulation and does not require actual PHI, live payment card data, classified information, real credentials, or other Sensitive Personal Data. Customers should use fictional, anonymized, or minimally necessary data in scenarios and exercise content.
Breachday is not a HIPAA Business Associate by default. Customers must not submit PHI unless Breachday has expressly approved the use in writing and the parties have executed a Business Associate Agreement and any required service-specific terms before PHI is submitted.
11. Children's Privacy
The Service is a business-to-business platform intended for organizational use by individuals 18 years of age or older. Breachday does not knowingly solicit or collect personal information from children. If Breachday learns that a child's personal information was submitted contrary to these requirements, Breachday will take reasonable steps to delete or appropriately handle the information.
12. Changes to This Policy
Breachday may update this Privacy Policy. Material changes will be communicated through email or a prominent in-Service notice before they take effect when reasonably practicable and as required by law. The version and effective date at the top identify the applicable published version.
13. Contact
For privacy, security, access, correction, or deletion inquiries:
compliance@breachday.io
Breachday LLC
breachday.io