Effective date: June 19, 2026
Balanced Security, LLC. (“us”, “we”, or “our”) operates the https://academy.balancedsec.com website (the "Service").
This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.
We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, terms used in this Privacy Policy have the same meanings as in our Terms and Conditions.
Service means the https://academy.balancedsec.com website.
Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).
Usage Data is data collected automatically either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
Cookies are small pieces of data stored on your device (computer or mobile device).
Data Controller means the natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal information are, or are to be, processed.
For the purpose of this Privacy Policy, we are a Data Controller of your Personal Data.
Data Processor (or Service Provider) means any natural or legal person who processes the data on behalf of the Data Controller.
We may use the services of various Service Providers in order to process your data more effectively.
Data Subject is any living individual who is using our Service and is the subject of Personal Data.
We collect several different types of information for various purposes to provide and improve our Service to you.
Personal Data While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”). Personally identifiable information may include, but is not limited to:
First name and last name Email address Cookies and Usage Data We may use your Personal Data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you.
You may opt out of receiving any, or all, of these communications from us by following the unsubscribe link or instructions provided in any email we send or by contacting us.
Usage Data We may also collect information that your browser sends whenever you visit our Service or when you access the Service by or through a mobile device (“Usage Data”).
This Usage Data may include information such as your computer's Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.
When you access the Service by or through a mobile device, this Usage Data may include information such as the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile Internet browser you use, unique device identifiers and other diagnostic data.
Beta Waitlist While the Service is in limited public beta, we offer a waitlist sign-up to receive notification when public access opens. The waitlist captures your email address, the page on the Service from which you joined (e.g., the signup page or the landing hero), any UTM campaign parameters present in the page URL, the page that referred you (HTTP referrer), and a salted hash of your IP address for abuse prevention. We retain this entry until you unsubscribe (via the one-click link in every email we send to the list) or until public access opens and we either send your invite or you opt out.
Because beta access is limited and invitation-based, we may review waitlist sign-ups to assess their fit for the program and to screen for abuse, using publicly available information associated with your email address (such as public professional or developer profiles). To do this we may use third-party verification and enrichment service providers (see "Service Providers" below). We use this information solely to evaluate and prioritize beta invitations and to detect abuse; we do not use it for advertising and we do not sell it. We may store the information we obtain, linked to your waitlist entry, and we delete it when your waitlist entry is removed (for example, when you unsubscribe).
AI Assistant Conversations When you use the in-app AI assistant features — for example, asking the assistant to explain why a practice question was answered incorrectly, or requesting guidance on a concept — we may log the content of those conversations in order to monitor the quality of the practice question bank, evaluate the assistant's responses, and improve the Service.
Before storage, AI assistant conversation logs are de-identified. Stored entries are not linked to your user account; instead, each log row carries an opaque session token and a reference to the practice item being discussed. We also apply best-effort scrubbing to remove direct personal identifiers (such as email addresses, phone numbers, and similar obvious patterns) from your messages before they are stored. The assistant's responses are stored as-is. Because conversation content is free-form text, you may inadvertently include identifying detail in your messages; we do not guarantee that all such detail can be removed by automated scrubbing.
AI assistant conversation logs are retained for 90 days, after which they are automatically deleted. Because stored logs are not linked to your account, we are not able to locate or delete individual entries on request; closing your account and discontinuing use of the AI features ensures that no further entries are created in connection with your activity.
AI features are powered by third-party model providers acting as our service providers, who process your inputs in order to generate the assistant's responses. See "Service Providers" below.
Access and Activity Logging We log the content you access (for example, book chapters), the features you use, and your navigation within the Service, together with timestamps and technical context — the page or route, your device and browser (user-agent), a salted hash of your IP address, and a session identifier — linked to your account. We use these logs to (1) protect our intellectual property and enforce our Terms of Service and other agreements, including establishing the scope and timeline of content accessed; (2) detect and prevent security abuse; and (3) understand which features are valuable so we can improve the Service. Intellectual-property and security logs are retained as long as necessary to operate the Service and protect our legal rights; product-analytics records are retained for a shorter period. Unlike the de-identified AI assistant conversation logs described above, these access logs are linked to your account.
We use cookies and similar tracking technologies to track the activity on our Service and hold certain information.
Cookies are files with small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Service.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
Examples of Cookies we use:
Use of Data Balanced Security, LLC uses the collected data for various purposes:
If you are from the European Economic Area (EEA), Balanced Security, LLC legal basis for collecting and using the personal information described in this Privacy Policy depends on the Personal Data we collect and the specific context in which we collect it.
Balanced Security, LLC may process your Personal Data:
Balanced Security, LLC will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.
Balanced Security, LLC will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.
Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.
If you are located outside the United States and choose to provide information to us, please note that we transfer the data, including Personal Data, to the United States and process it there.
Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.
Balanced Security, LLC will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.
Business Transaction If Balanced Security, LLC is involved in a merger, acquisition or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.
Disclosure for Law Enforcement Under certain circumstances, Balanced Security, LLC may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).
Legal Requirements Balanced Security, LLC may disclose your Personal Data in the good faith belief that such action is necessary to:
The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.
Your Data Protection Rights Under General Data Protection Regulation (GDPR) If you are a resident of the European Economic Area (EEA), you have certain data protection rights. Balanced Security, LLC aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.
If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please contact us.
In certain circumstances, you have the following data protection rights:
The right to withdraw consent: You also have the right to withdraw your consent at any time where Balanced Security, LLC relied on your consent to process your personal information.
The right to data portability: You have the right to be provided with a copy of the information we have on you in a structured, machine-readable and commonly used format.
The right of restriction: You have the right to request that we restrict the processing of your personal information.
The right to object: You have the right to object to our processing of your Personal Data.
The right of rectification: You have the right to have your information rectified if that information is inaccurate or incomplete.
The right to access, update or to delete the information we have on you: Whenever made possible, you can access, update or request deletion of your Personal Data directly within your account settings section. If you are unable to perform these actions yourself, please contact us to assist you. Please note that we may ask you to verify your identity before responding to such requests.
You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).
We may employ third party companies and individuals to facilitate our Service (“Service Providers”), to provide the Service on our behalf, to perform Service-related services or to assist us in analyzing how our Service is used.
These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.
Analytics We may use third-party Service Providers to monitor and analyze the use of our Service.
Google Analytics Google Analytics is a web analytics service offered by Google that tracks and reports website traffic. Google uses the data collected to track and monitor the use of our Service. This data is shared with other Google services. Google may use the collected data to contextualize and personalize the ads of its own advertising network.
For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page.
AI Features We use third-party AI model providers to power the in-app assistant features and other AI-generated content within the Service (such as personalized readiness summaries, per-question explanations, and the AI study assistant).
Anthropic Anthropic, PBC operates the Claude family of large language models. When AI features are used, content such as your messages to the assistant, the practice item being discussed, and relevant performance signals (for example, recent practice results used to generate a readiness summary) is transmitted to Anthropic's API in order to generate the model's response. Anthropic processes this content on our behalf as a service provider, subject to Anthropic's commercial API terms. Anthropic states that it does not use API customer data to train its models and retains inputs only for a limited period for safety and abuse review.
For more information on Anthropic's privacy practices, please see Anthropic's privacy policy.
Verification and Enrichment For the limited beta described under "Beta Waitlist" above, we use third-party verification and enrichment service providers to look up publicly available information associated with a waitlist email address, so that we can assess fit for the program and screen for abuse. These providers process this data on our behalf, subject to their own terms and privacy practices.
We may provide paid products and/or services within the Service. In that case, we use third-party services for payment processing (e.g. payment processors).
We will not store or collect your payment card details. That information is provided directly to our third-party payment processors whose use of your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.
The payment processors we work with are:
Stripe: Stripe Privacy Policy
Links to Other Sites Our Service may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party's site. We strongly advise you to review the Privacy Policy of every site you visit.
We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.
Users under the age of 18 (a “Minor”) shall have their legal guardian or parent agree to these Terms and our Privacy Policy on their behalf, and such legal guardian or parent shall be responsible for all actions taken under the account. We do not share any personal data or personally identifiable information received or collected from the service unless we have your consent, it is required by law, or we are required to do so in order to continue providing our service. Further, we do not knowingly collect or store sensitive data, or personally identifiable information from anyone under the age of 13. Pursuant to COPPA, we do not target or market our services to children below the age of 13. Persons under the age of 13 are not permitted to use the services.
When you create an account with us, you guarantee that you are above the age of 13, and that the information you provide us is accurate, complete, and current at all times. Inaccurate, incomplete, or obsolete information may result in the immediate termination of your account on the Service.
We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Children has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.
We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the “effective date” at the top of this Privacy Policy.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
If you have any questions about this Privacy Policy, please contact us at support@balancedsec.com.
Version 2026-06-16-v1