Back to product

Infralock Systems

Legal

Privacy Policy

Effective 12 September 2026

Support info@infralocksystems.cloud · infralocksystems.cloud

Who we are

Infralock Systems operates CROOK. This policy describes how account, session, and console data is handled when you continue with Google or X and arm the console.

Data we collect

From your sign-in provider we receive the identity needed to open a session: display name, email address, and profile image when the provider supplies them. The console also stores session tokens, email-verification state for credential accounts, per-user analyst reports, and engine events generated in this browser (intercepts, verdicts, quarantine objects, and module policy).

How we use it

We use this data to authenticate you, arm the console, apply protection modules, keep reports scoped to your account, and show the analyst views you request. We do not sell account or telemetry data.

Sign-in providers

Continue with Google or Continue with X is federated through those providers. Their own terms and privacy policies apply to the account you choose. CROOK receives a brokered identity; it does not see your provider password.

Storage and retention

Session cookies are host-scoped to this app. Analyst reports and verification records are stored with your user id and kept while the account remains active. You can sign out at any time; that ends the local session.

Requesting account deletion is handled through info@infralocksystems.cloud or visit infralocksystems.cloud.

Cookies

CROOK sets host-scoped session cookies after you continue with Google or X so the console can keep your session. The preference center lets you accept all, keep necessary only, or save a custom mix of functional storage and telemetry. Session cookies are required to stay signed in. We do not set advertising or cross-site tracking cookies.

Cookie questions can be sent to info@infralocksystems.cloud or visit infralocksystems.cloud.

Sharing

We share data only with the sign-in providers required to authenticate, with infrastructure needed to run the console, or when required by law. Enrolled fleet sensors send hostname, OS, check-in time, browser hardware hints (cores, memory class, GPU, screen, battery, storage quota, platform, architecture), local addresses the browser exposes, this-tab destinations and transfer sizes, and objects you scan on that device. They do not read the disk, OS process list, listening ports, or NIC traffic. Extra analysts you invite can see that estate telemetry. SIEM destinations you add receive the detection and incident payloads you subscribe them to. Billing contact details (company, billing email) are used to invoice the estate. Card payments are processed by Stripe; we receive payment status, customer id, and subscription id — not the card number.

Your choices

You may decline to continue, sign out, export reports you created, and ask us to delete stored account records. You can change cookies from the banner, the preference center, or Configure. Protection modules you disarm stay local to this console unless tamper protection blocks the change.

Children

CROOK is an endpoint operations console. It is not directed at children under 16.

Changes and contact

We will post updates on this page with a new effective date. For support, email info@infralocksystems.cloud or visit infralocksystems.cloud.