Effective Date: July 23, 2026
This Privacy Policy explains how SubImage Inc. ("SubImage", "we", "us", or "our") collects, uses, shares, and protects information in connection with our websites, services, cloud security products, and customer-authorized integrations. Our website is https://www.subimage.io. You can contact us at privacy@subimage.io.
This policy is not a Data Processing Agreement or Terms of Service. Customer data processing may also be governed by a separate customer agreement, Data Processing Agreement, order form, or similar contract. If there is a conflict between this Privacy Policy and a signed customer agreement for customer-provided data, the signed agreement will control for that customer data.
This Privacy Policy applies to SubImage's websites, services, cloud security products, and integrations. SubImage customers may authorize integrations with third-party cloud, SaaS, identity, code, collaboration, security, and infrastructure platforms so SubImage can provide security visibility, asset inventory, risk analysis, reporting, remediation guidance, and related security and compliance functionality.
Customer-authorized integrations may include Atlassian, Jira, Confluence, Google Workspace, Google Cloud, GitHub, AWS, Okta, Microsoft Entra, and other connected SaaS or cloud platforms depending on the customer's configuration and the permissions granted.
We collect information from customers, users, administrators, visitors, and customer-authorized third-party systems. The categories of information we collect may include:
SubImage is designed for enterprise security and infrastructure visibility. Customers control which integrations they connect and which permissions they authorize.
When you visit our website, we use analytics and visitor-identification services, including PostHog and Snitcher, to understand website usage, diagnose performance, improve our website, and identify businesses that may be interested in SubImage. These services may collect IP addresses, browser and device metadata, referring pages, pages viewed, timestamps, interactions, approximate location, and company-level information inferred from an IP address.
Snitcher processes visitor IP addresses and website activity to identify the business associated with a visit. Our Snitcher tracker uses session storage before cookie consent. If a visitor grants consent for persistent storage, Snitcher may use a cookie named SNID to distinguish visits across sessions. You may contact privacy@subimage.io with questions or to object to this processing.
We use information to:
SubImage only accesses third-party data after an authorized user or administrator grants permission or configures an integration. We request scopes intended to be reasonably necessary to provide the applicable SubImage service or integration functionality.
Customers may revoke access through the third-party provider's authorization, app, or admin settings, or by contacting SubImage at privacy@subimage.io. Revocation may limit or disable the related SubImage functionality.
OAuth tokens, API keys, and integration credentials are protected using appropriate security controls, including access controls, encryption where appropriate, and operational safeguards. Data from integrations is not sold. Data from integrations is not used for advertising. SubImage does not use customer data from integrations to train general-purpose AI models unless the customer expressly agrees in writing.
When customers provide integration credentials directly, SubImage stores them in an encrypted, tenant-scoped managed vault. For supported integrations, customers may instead keep credentials in their own AWS Secrets Manager account and provide SubImage with a secret ARN and limited cross-account role. SubImage retrieves those credentials at runtime and does not store their values in its managed vault.
If SubImage accesses Google user data, SubImage's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
SubImage uses Google API data only to provide customer-authorized security visibility, asset inventory, risk analysis, reporting, and related customer-requested functionality. Customers can revoke Google access through Google account or administrator settings, or by contacting SubImage.
When a customer authorizes an Atlassian, Jira, or Confluence integration, SubImage may access Atlassian account, site, project, issue, group, permission, and configuration metadata depending on the scopes granted and the customer's configuration. SubImage uses this data only to provide security analysis, visibility, reporting, and related customer-requested functionality.
Customers can revoke the integration from Atlassian's app or authorization settings, or by contacting SubImage at privacy@subimage.io.
We may share information with:
SubImage does not sell personal data. SubImage does not share personal data for cross-context behavioral advertising.
SubImage maintains a security program designed to protect systems, data, and customer environments. Our safeguards include encryption in transit and, where appropriate, encryption at rest; access controls based on least privilege; multi-factor authentication for company systems; logging and monitoring; vendor and security review practices; secure software development practices; vulnerability management; and incident response processes.
Production customer environments are isolated from one another in separate AWS accounts with separate security graph databases.
No security program can guarantee absolute security. Customers should configure integrations using appropriate administrative controls and promptly notify SubImage of suspected unauthorized access involving SubImage services.
SubImage retains customer data only while needed to provide the service or as required by applicable law or a written customer agreement. For this section, customer data includes data ingested from customer-authorized integrations, resulting security graphs and findings, integration configurations, and SubImage-managed credentials.
When a customer terminates the service or submits a verified deletion request, SubImage promptly disables the customer environment and integrations and initiates deletion. Unless a shorter period is required by a written customer agreement, SubImage completes deletion within 90 days. Deletion includes the customer's tenant infrastructure and storage, security graph, integration configurations, and SubImage-managed credentials.
Residual copies may remain inaccessible in encrypted backups or provider-managed recovery systems until their scheduled deletion within that period. SubImage does not use those copies to provide the service. SubImage may retain limited billing, contractual, security, or audit records where required by law, but not the customer's ingested environment data or integration credentials.
Revoking an integration stops future collection from that provider but does not automatically delete previously processed data. Customers may request deletion and written confirmation of completed offboarding by contacting privacy@subimage.io.
Customers are responsible for obtaining all necessary rights, consents, permissions, and authorizations before connecting third-party systems to SubImage. Customers are also responsible for configuring integrations appropriately, selecting scopes and permissions suitable for their environment, managing their users' access to SubImage, and complying with laws and third-party provider terms that apply to their connected systems.
SubImage is based in the United States. Information may be processed in the United States and other locations where SubImage or its service providers operate. These locations may have data protection laws different from those in your jurisdiction. Where required, SubImage uses appropriate safeguards for international transfers.
Depending on your location and applicable law, you may have rights to access, correct, delete, port, restrict, or object to certain processing of your personal data, and to appeal or complain to a regulator. California and other U.S. state privacy laws may also provide rights related to access, correction, deletion, portability, and opting out of certain sharing or sales. SubImage does not sell personal data or share it for cross-context behavioral advertising.
For personal data that SubImage processes on behalf of a customer, the customer is typically the controller or business responsible for responding to privacy rights requests. If you are an end user of a SubImage customer, please contact that customer directly. You may also contact us at privacy@subimage.io, and we will route the request as appropriate.
SubImage services are intended for business and enterprise use and are not directed to children. We do not knowingly collect personal data from children.
We may update this Privacy Policy from time to time. When we make changes, we will update the Effective Date above. Material changes may be communicated through the website, product, or other appropriate channels.
For privacy questions, requests, or concerns, contact SubImage at privacy@subimage.io.