Privacy Policy
Last updated: August 7, 2026
PacketSpear is a self-hosted microsegmentation platform. This privacy policy explains what data PacketSpear collects and how it is used. Because PacketSpear runs on your infrastructure, most data never leaves your network.
1. What PacketSpear Does NOT Collect
PacketSpear is designed to minimize data collection. The following never leave your infrastructure:
- Network flow data — connection logs, IP addresses, ports, protocols, process names, and TLS fingerprints stay in your PostgreSQL database.
- Device inventory — hostnames, operating systems, versions, and enrollment details are stored locally.
- Policy configurations — your microsegmentation rules, policy bundles, and enforcement settings are never transmitted externally.
- Audit logs — all administrative actions, policy changes, and access events remain on your server.
- User identities — operator accounts, device certificates, and authentication data are local to your deployment.
2. What PacketSpear DOES Collect
PacketSpear Core performs a privacy-preserving license status check ("phone-home") that transmits the following anonymous data:
- Install ID — a randomly generated anonymous identifier (UUID), not tied to any personally identifiable information.
- PacketSpear version — the software version string (e.g., "v0.9.2").
- Device count — an integer count of enrolled devices. No device names, IPs, or metadata are included.
- Entitlement hash — a cryptographic hash of the current license entitlement, used to detect changes.
This data is transmitted to PacketSpear's license server solely to verify license validity and enable enforcement features. No flow data, device names, IP addresses, policy content, or topology information is included.
2.1 License Server Data Retention
The license server retains only the data described above for the duration of the license relationship. This data is used for:
- Verifying license validity and entitlement status
- Monitoring aggregate deployment health (version adoption, device trends)
- Detecting license abuse or unauthorized use
Aggregate, anonymized deployment statistics (e.g., "47% of deployments are on v0.9.2") may be used for product planning. Individual install data is never sold, shared with third parties, or used for advertising.
3. Support Portal Data
When you submit a support ticket, bug report, or feature request through our support portal (/api/v1/support/requests), you may optionally provide:
- Email address — used only to send status updates on your request. Not used for marketing.
- License ID — used to associate your request with your account for priority routing.
- Account identifier — used to link your request to your organization.
Support request data (title, description, type, severity) is retained for the life of the support relationship and may be anonymized for knowledge base article creation. You can submit support requests without providing an email address; in this case, you will need to save your ticket ID and access token to check status.
4. Website Data
The PacketSpear public website (packetspear.com) is a static site hosted on GitHub Pages or equivalent infrastructure. The hosting provider may collect standard access logs (IP address, user agent, timestamp) as part of normal web server operation. PacketSpear does not use third-party analytics, tracking cookies, or advertising pixels on its public website.
5. Data Storage and Security
- Your data stays on your infrastructure. Core, Node, Gate, and Relay components store all operational data in your PostgreSQL database.
- License checks are encrypted in transit via HTTPS/TLS.
- Support portal submissions are transmitted via HTTPS and stored in the PacketSpear Core database.
- License keys are never stored in plaintext server-side — only a SHA-256 hash is persisted.
6. Air-Gapped and Offline Deployments
PacketSpear supports fully air-gapped deployments. In air-gapped mode, license files are transferred manually (via USB, SCP, or configuration management) and validated locally using the baked-in Ed25519 public key. No network communication is required. The privacy-preserving phone-home is skipped entirely in air-gapped configurations.
7. Your Rights
Because PacketSpear is self-hosted, you control your own data. You can:
- Export your data at any time via PostgreSQL tools or the PacketSpear API
- Delete your data by dropping the database or decommissioning the deployment
- Opt out of license phone-home by running in air-gapped mode with a manually installed license file
For data submitted through the support portal, you may request deletion by contacting us with your ticket ID and access token.
8. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be communicated via the PacketSpear website and release notes. The date of the latest revision is shown at the top of this page.
9. Contact
For questions about this privacy policy or PacketSpear's data practices, contact us through the support portal.