Legal
Privacy Policy
We are a security company. Collecting more than we need would make us part of the problem we were hired to solve. This page says plainly what we collect, what we never collect, and how long we keep it.
Effective 29 July 2026 · Last updated 29 July 2026
Who we are
Rainy Day Security LLC is a managed cybersecurity firm registered in Ohio, United States. We are the data controller for information collected through rainydaysecurity.com, and a data processor acting on our customers' instructions for information handled inside Beam, our security platform.
This website
We do not use advertising trackers, cross-site tracking pixels, or third-party analytics on this website. There is no cookie banner because we set no tracking cookies. Our pages do load their typefaces from Google Fonts, which means Google sees the IP address your browser connects from; nothing else about your visit is shared with them.
If you submit the contact form, we receive your name, email address, organization and message, and we use them for one thing: to reply to you. That email is delivered through Resend, our email provider. We do not add you to a marketing list, and we do not sell or share it.
Beam, our security platform
Customers of our managed service connect Beam to the systems they want us to protect — typically Microsoft 365 or Google Workspace. How much Beam reads depends on the service tier the customer buys and on what their administrator chooses to connect. Across the full service that is:
- Sign-in activity — who signed in, when, from which IP address and the approximate location and network it belongs to, on what device, and whether multi-factor authentication was used.
- Email — where email security is part of the service, Beam examines messages as they arrive and keeps a record of each one: sender, recipients, subject, attachment names, authentication results, and the first 500 characters of the message. For a message Beam judges dangerous it also keeps the full text, so the customer can see what was actually sent to them. Sender addresses and message text are encrypted in our database.
- Configuration and posture — how the tenant is set up: administrator accounts, mailbox and forwarding rules, sharing and access settings, licensing.
- File and sharing activity — records of documents shared outside the organization or accessed unusually, where the customer's licensing makes that visible to us.
- Exposure — whether the organization's own domains, employee addresses or credentials have appeared in criminal breach data, leak sites, or stolen-credential collections.
- Suppliers and internet-facing services — the vendors the organization depends on, and its own public domains and services, so we can warn it when one of them is breached or exposed.
- Incident evidence — if a customer asks us to examine a specific computer after a suspected compromise, the technical evidence collected from it during that investigation.
We use that information to protect that customer, and for nothing else. It is not used to train any model, it is not combined into profiles across customers, and it is not sold.
Each customer's data is segregated. One customer's operators, devices and findings are never visible to another customer. Data is encrypted in transit and at rest, and access by our staff is limited to the people delivering that customer's service.
The one thing that crosses that line is a threat indicator. When we confirm that a site, a sending domain, a link or a file is hostile at one customer, the indicator itself — the address of the bad thing, and nothing around it — is added to the catalog every customer is defended with, so the next customer is protected before they are ever hit. A sender's own email address is added only in a scrambled form that cannot be read back. What is never shared is who received it, who visited it, which customer it was seen at, or anything about the person involved. That is how a security service is supposed to work, and it is the only cross-customer flow we operate.
Where we handle protected health information on behalf of a customer, we do so as a Business Associate under a signed Business Associate Agreement.
Beam Browser Defense (the browser extension)
Beam Browser Defense is a browser extension we provide to customers on our SHIELD service tier. It warns the person using the browser when the page in front of them shows a known sign of a security scam — a fake sign-in page, a paste-to-run instruction, a copycat web address, a dangerous download. It only functions after an administrator connects it with a one-time code issued from that organization's own Beam console; before that, it does nothing and sends nothing.
What the extension never collects
- Not your browsing. There is no browsing history, no page-visit log, and no tracking of where you go. The pages you read are not reported. Three narrow exceptions are described below, and none of them carries anything from the page: a web address that itself looks like a deliberate copycat is sent to be scored; a site whose name coincidentally matches the compressed list of known-bad sites your browser carries has that name checked with us to settle it; and if you choose to send a note about a page, the name of that site goes with your note.
- Not what you type. No keystrokes, no form values, no passwords, no search terms, no payment details.
- Not what you paste. Pasted text is examined inside the browser — both to spot a paste-to-run scam, and to notice when something like a Social Security or bank account number is going into a site that should not receive it. The text itself is never stored and never sent.
- Not page contents. The text, images and links on a page are examined in the browser at the moment of the check and then discarded. They are never stored and never transmitted.
- Not your identity. The extension holds no name, email address or account identifier for the person using the browser.
- Not your location. No geolocation is requested or collected.
What it does send
Detection happens entirely inside the browser. The judgment — the list of scam patterns to look for — is compiled by that customer's own Beam tenant and delivered to the extension as data. Almost everything below is sent only when a warning is raised, so that customer's security team can respond. The two exceptions are marked, and neither carries anything from the page — one sends a suspected copycat address to be scored, the other asks about a single site name the local list was unsure about.
| What is sent | Why |
|---|---|
| The name of the site | So the security team knows where the warning happened. The site's name only — never the rest of the address. Where the warning is about somewhere the page was sending information, or where a download came from, that destination's name is included as well. |
| Which check fired, and why | The name of the check and the short explanation shown on screen. We write those sentences in advance. A few of them name one specific detail where that detail is the evidence itself — the kind of file being downloaded, the address a form was quietly sending to, or the part of a sign-in address that gave it away. Never the page's words, and never anything you typed. |
| What the person chose to do | Whether the warning was heeded, dismissed, or overridden to continue anyway, so the security team knows whether someone is still at risk. Also whether the warning managed to appear on screen at all, and how large it was — some scam pages try to hide it. |
| The kind of sensitive information pasted, and where | If something shaped like a Social Security number, bank details, a payment card or an access key is pasted into a site that should not be receiving it, the security team is told what kind of information it was and the name of the site it went to. Never the information itself. |
| The full web address — the copycat check, before any warning | When an address already looks locally like a deliberate copycat of a site you use, that address is sent to be scored, because the address itself is the evidence. This is the only case where more than a site's name is sent about a page that has raised no warning, and it happens on that check alone. Anything after a “#” is removed first, because that is where some sign-in systems put access tokens. |
| The name of one site, when the known-bad list is unsure — before any warning | Your browser carries the customer's list of known-bad sites in a compressed form, so that it stays small and so that the sites you visit never have to be looked up with us one by one. Compression has a price: a small share of ordinary sites — on the order of one in a few hundred — match it by coincidence. When that happens the extension asks us about that one name to settle it, and in nearly every such case we answer that it is fine and nothing is shown. What is sent is the site's name alone, or the domain it sits under — never the rest of the address, and never anything from the page. We keep a record of which names were asked about and what we answered, for 90 days, because that record is the only way to tell the list is still reaching devices intact. |
| The device's own details | Browser name and version, operating system, extension version, a label the administrator sets, whether it was installed by hand or by your organization's IT policy, and whether protection is switched on for private windows. That is sent once, at setup, so the security team can tell one protected device from another. After that an hourly check-in says only that the device is still alive, and re-sends two things that can change on their own: the extension version and the private-window setting. No site is named on that check-in. |
| Details of a risky browser add-on | If another add-on installed in the browser is dangerous, its store identifier, its name, and — where it updates itself from somewhere other than an official store — the name of the site it updates from are reported so it can be removed. This covers browser add-ons only; no other software on the computer is examined. |
| Anything you write in “report a problem” | If you open the extension and send a note about a page, your security team receives exactly what you wrote, along with the name of that site. Nothing else about the page goes with it. Nothing is sent unless you press send. |
The extension has exactly one network destination — the Beam service at
api.beam.rainydaysecurity.com, operated by us on behalf of that
customer. It contains no analytics tools, no advertising code, and no third-party
services of any kind. It downloads no code: everything it runs is in the package you
installed.
Who sees it
Warnings raised on a customer's devices are visible to that customer's own administrators and to the Rainy Day Security operators delivering their service. No other customer sees them, and they are never sold, rented, or shared with advertisers or data brokers.
The threat-indicator exception described above applies here in one specific way. When people at two or more separate customers are each warned about the same site and each choose to back away from it, that is the strongest evidence a security service can get that the site is genuinely hostile — so the name of that site joins the list of suspect sites every customer's extension checks against. What crosses is the name of the site and nothing else: no person, no device, no customer's identity, and no record that any particular person went there.
How long we keep things
| Contact form messages | Kept while a conversation is active, then for up to 24 months. |
| Findings and alerts | Kept for the life of the customer relationship, then deleted within 90 days of termination unless the customer asks us to hold them longer for their own compliance obligations. |
| The activity records behind them | Pruned automatically well before that. Sign-in, file-activity and breach records are deleted after 12 months; copies of briefings we have already sent, after 90 days. |
| Browser Defense | A warning that became a finding is kept with that customer's other findings. The raw stream of events behind it — including the record of site names checked against the known-bad list, most of which raised no warning at all — is deleted after 90 days. |
| Email we judged clean | The message itself is not retained — it is read, analyzed and discarded. The record of it described above, including the first 500 characters, is kept with that customer's other security data. |
Who we rely on
A small number of providers help us run the service. They process data on our instructions and are bound by contract; none of them is permitted to use it for their own purposes.
- Amazon Web Services — hosting, storage and databases, in United States regions. The language models that draft our plain-English briefings run through Amazon Bedrock inside our own AWS environment, so customer data does not go to a model vendor's own service and is not used to train anyone's model.
- Cloudflare — this website.
- Resend — outbound email.
- Stripe — card payments. Stripe receives billing contact and payment details directly; we never hold full card numbers.
- Security intelligence services — to decide whether something is dangerous, Beam asks outside reputation services about one specific indicator at a time: a web address or attachment found in a customer's email, an IP address someone signed in from, or an employee's email address being checked against breach corpora. Only that indicator is sent, never the message or the page it came from. The services Beam is integrated with are ip-api.com for IP location, XposedOrNot for breach records, and — where enabled for a customer — Google Safe Browsing, VirusTotal and urlscan.io for web address and file reputation. The current list is available on request.
We do not sell personal information to anyone, for any price.
Your rights
You may ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. If you are an employee of one of our customers, we will normally refer your request to that customer, because the data is held on their instructions — we will help them answer it. Write to the address below and we will respond within 30 days.
Children
Our services are sold to organizations and are not directed at children. We do not knowingly collect information from anyone under 16.
Changes
If we change what we collect, we will change this page and move the "last updated" date at the top. Material changes affecting customers are also communicated directly.
Contact
Rainy Day Security LLC · Ohio, United States
Privacy questions: privacy@rainydaysecurity.com
Everything else: hello@rainydaysecurity.com