Last updated August 28, 2026. Operator: NetForge. Product: PIIRUS. This Privacy Policy (the “Policy”) is part of our Terms of Service. If they conflict on a privacy point, this Policy controls that point.
1. Who we are; scope
NetForge (“NetForge,” “we,” “us,” or “our”) operates PIIRUS and the websites at piir.us, piirus.com, and successor or related sites we control (the “Site”). This Policy covers Personal Information we handle in connection with the Site, accounts, checkout, downloads, and the PIIRUS Windows software (together, the “Service”).
“Personal Information” means information that identifies, relates to, or could reasonably be linked to you or your household — for example an email address, name, Account ID, payment reference, or a machine ID tied to your Account. It does not include information that has been de-identified so it cannot reasonably be linked back to you.
This Policy does not cover third-party sites we do not control, including Square’s checkout pages, your email provider, or Microsoft Windows.
2. The rule: we do not share
We do not sell Personal Information. We do not rent it. We do not trade it. We do not disclose it to data brokers, advertising networks, social-media platforms, analytics vendors, or “partners” so they can market to you or profile you. We do not run advertising pixels, tracking cookies for ads, or cross-site identifiers for anyone else’s commercial use. We do not operate a “Do Not Sell or Share My Personal Information” link because we do not sell or share in that sense. If that ever changed, we would update this Policy first and, where the law requires, give you a way to opt out before any sale or share.
We do not give mailing lists to SSA, NetForge’s other projects, The White House Facility, or any homepage logo. Those names on the Site are attribution, not a data-sharing arrangement.
What this Rule does not pretend: we cannot operate a paid download site with zero processors. Hosting, DNS, and Square touch bits of data so the Service can run. They are not given your information to use for their own advertising. Section 8 states that limit in contract-level language. Family Alert is you telling the Software to email an address you typed — not us adding that person to a list. Section 6 states that. If a court order, warrant, or other compulsory legal process that we cannot lawfully ignore is served on us, we may produce the minimum required. We do not volunteer Account files to private parties, skip-tracers, or random requesters. Section 9 states that.
3. What we collect on the Site and why
We collect only what we need to run the Account, take payment, count Seats, and let you download. We do not collect extra fields “for later.”
3.1 Account
When you create or use an Account we store: name (if you give one); email address; password hash (not your password in clear text); role (customer or admin); Account timestamps; and whether the Account is active. We use that to authenticate you, reset access, send operational mail (receipts, security, material Policy or Terms changes), and show the dashboard.
3.2 Orders and licenses
We store purchase records: amount, currency, status, provider name, provider reference (for example a Square order id), quantity of Seats, notes we need for support, and grant/expiry of Seats. We use that to fulfill the Order, display license counts, and handle a failed or duplicate charge.
3.3 Devices
When the desktop app signs in, it sends a machine ID and a computer name so we can bind one Seat to one Device and let you release that Seat. The dashboard shows those Devices. We use that solely for license enforcement and your own Device list. We do not use machine IDs to sell advertising or to build a graph for anyone else.
3.4 Support
If you email support@piir.us, we receive whatever you send, including the email address and any attachments. We use that to answer you. We do not add support inboxes to a marketing list — we do not keep a marketing list.
3.5 What we do not collect
We do not ask for Social Security numbers, government IDs, or date of birth. We do not receive your clipboard stream, keystrokes, webcam, microphone, or full process history from the Device, except the narrow Family Alert content described in Section 6 if you turn that feature on. We do not scan your files for advertising. We do not require access to your contacts, photos, or location as a condition of the Account.
4. What stays on your PC
The Software is built to do its job locally. Settings, the safe list, history, PIN hash, Family Alert contacts you enter, and similar configuration live in your Windows user profile on that Device. That data does not come to our servers in the ordinary course.
We do not receive your history log, overlay detections, or clipboard contents unless you enable a feature that transmits an event (Family Alert). If that feature is off, those items stay on the Device. You are responsible for who can open that Windows profile, for disk encryption, and for backups you make.
Uninstalling the Software does not automatically delete server-side Account or Order records. Deleting the Windows profile does not delete your Site Account. See Section 14 if you want Account deletion.
5. Cookies and similar technology
We use a session cookie so you stay signed in on the Site while you use the dashboard and checkout. It is a first-party session cookie, not an advertising identifier. We do not use third-party advertising cookies, fingerprinting for ads, or “like” buttons that phone home to a social network. We do not drop a cookie to retarget you on other sites.
You can refuse cookies in your browser. If you do, you may be unable to stay signed in. Ordinary hosting may generate server access logs (IP address, user-agent, timestamp, URL) for security and uptime. We do not sell those logs. We do not feed them to an ad network. We retain them only as long as needed for security, abuse, and debugging, then they rotate with the host’s ordinary cycle.
6. Family Alert
Family Alert is optional and off unless you turn it on. If you enable it, the Software may send an email to an address you typed when a defined event occurs (for example a remote starts, protection is turned off, lockdown is used, or suspicious clipboard text is seen). The message may include the event type, this PC’s name, and an optional phone number you entered.
That send is your instruction, not our disclosure for our own purposes. We do not take that recipient address and add it to a newsletter, sell it, or share it with a partner. You represent you have the recipient’s consent. Do not enable Family Alert to watch someone who has not agreed. Delivery is not guaranteed (spam filters, provider failure). See the Terms of Service for responsibility.
7. Payments; Square is a processor, not a marketing partner
Card numbers, CVV, and the billing PAN are entered on Square’s checkout page, not stored by us as full card data. Square is a Payment Processor. It handles the charge under its own terms and privacy notice. We receive back what we need to fulfill: paid/not paid, amount, currency, and a reference id. We store that reference so we can match a Seat to a payment and reverse a true duplicate or error.
We do not receive your full card number. We do not sell payment metadata. We do not use Square as a channel to let other merchants target you. If Square fails or you dispute a charge, Square and the card network will have their own records; that is their processing, not a share we initiated for advertising.
8. Processors who must touch data so the Service exists
We use a small set of service providers who process data only on our instructions to host the Site, send mail we originate, or take payment:
- Web hosting / DNS for piir.us (and related hostnames) — stores the Site, Account database, and ordinary server logs.
- Square — payment checkout and payment status, as Section 7.
- Email transmission for mail we send you (receipts, security) and for Family Alert you trigger — the recipient and contents of that single message.
Those providers are not authorized to use Personal Information for their own advertising, to sell it, or to combine it with other customers’ data for a product we did not ask for. If we add a processor, it will be for operating the Service, not for selling lists. We do not use the homepage “partners” as processors of your Account.
9. Legal process; we do not volunteer files
We do not volunteer Personal Information to private litigants, skip-tracers, employers, or the press. If we receive a subpoena, court order, warrant, or other compulsory process that we determine we must obey, we may disclose the minimum the instrument requires. Where the law allows notice to you, we will try to give it before or after production. We may also disclose information if we reasonably believe it is necessary to prevent imminent serious harm or to defend our legal rights in a proceeding that already involves you and the Account — not as a pretext to share with marketers.
We do not sell access to law-enforcement “portals.” We do not have one.
10. Purpose limitation; no secondary use
We use Personal Information to: create and secure the Account; take and record payment; grant, count, and release Seats; let you download builds; send operational mail; debug abuse and fraud; and comply with law. We do not use it to train a public model we sell. We do not use it to build a credit file. We do not use it for interest-based ads. We do not combine it with purchased broker data to profile you.
11. Retention
We keep Account, Order, and Seat records for as long as the Account is open and as long as we reasonably need them afterward for tax, accounting, chargeback defense, and fraud — typically the longer of the License Term plus seven (7) years or the minimum a tax or payment-network rule requires. Password hashes remain only while the Account exists. Device bindings remain while the Seat is active and for a short period after you release a Device so we can debug a mistaken release. Server access logs follow the host’s rotation. Support emails follow ordinary inbox retention. When we no longer need a record, we delete or de-identify it in the ordinary course. Backups expire on the backup cycle; they are not a live database we query for marketing — we do not market.
12. Security
We use reasonable administrative, technical, and physical safeguards appropriate to a small paid-download service: hashed passwords, session cookies with HttpOnly and SameSite attributes, HTTPS on the Site when the host provides it, and Seat checks on sign-in. No method of transmission or storage is perfectly secure. You are responsible for your password, your email account, and the Device. Notify us at support@piir.us if you believe the Account was opened without you.
13. Children
The Service is not directed to children under 13 (or under 16 where that is the relevant age). We do not knowingly collect Personal Information from children. If you believe we have, email support@piir.us and we will delete it. PIIRUS may be installed by a parent or guardian on a family PC; that adult is the Customer under the Terms.
14. Your rights; access; deletion; correction
You may sign in and correct name or (where the dashboard allows) Device list yourself. For a copy of the Personal Information we hold on the Account, a correction we cannot make in-product, or deletion of the Account, email support@piir.us from the Account address. We will verify it is you. We will not turn that request into a marketing event.
Deletion: we will close the Account and delete or de-identify Personal Information we do not need to keep under Section 11 (for example, payment records we must retain for tax or card-network rules, stored without promoting them). Seats end when the Account is deleted. Uninstall the Software on each Device yourself.
If you are a resident of a jurisdiction that grants additional rights (access, deletion, correction, portability, restriction, or the right to appeal a denial), we will honor those rights to the extent they apply to us and to the Personal Information we actually hold. Because we do not sell or share Personal Information for cross-context advertising, there is no sale or share to opt out of. We will not discriminate against you for exercising a privacy right (no jacked-up price as punishment).
Authorized agents: we may require proof of authority and may insist the request come from the Account email. We will not hand data to a stranger who forwards a screenshot.
15. International; transfers
We operate the Service from the United States. If you access it from elsewhere, you transfer Personal Information to the U.S. We do not run a separate EU representative unless the law later requires it and we update this Policy. Do not use the Service if you are not willing to have Account data processed in the United States under this Policy.
16. Automated decisions
Seat checks and fraud screens may be automated (for example, rejecting a duplicate machine ID). They are not a consumer-credit score and are not used to advertise. You can email us if a Seat lock looks wrong.
17. Changes
We may update this Policy by posting a new version on the Site and changing the “Last updated” date. Material changes that expand collection or that would introduce a sale or share will not be used to sell or share data collected under the prior rule unless the law allows and we have said so clearly in the update. Continued use after the effective date is acceptance of the revised Policy for going-forward collection. If you do not agree, stop using the Service and request deletion under Section 14.
We will not hide a new sharing program in a footer tweak. If we ever sold or shared Personal Information, this Section 2 would have to change first, in plain language.
18. Contact
Privacy questions, requests to access or delete, and reports of a suspected Account breach: support@piir.us. Built by NetForge. © 2026 NetForge. All rights reserved.
We do not have a separate “privacy product” to upsell. This Policy is the whole of our public privacy statement for the Service.