OdinEye
← Home

Legal

Privacy policy

14 August 2026 · OdinEye Ltd

TL;DR

This section is a summary only. The full policy below is what legally applies. If anything here seems to conflict with the detailed sections, the detailed sections control.

  • What it does: OdinEye looks inside the memory of programs running on your Windows computer to spot malware, hacking tools, or tampering. The OdinEye website shows you progress and results on the same machine.
  • What we collect: A unique ID for your device, facts about the computer (including its name and the Windows account running the scan), information about the programs we inspect, and your IP address. If something suspicious is found, we may also collect a full snapshot of that program's memory, encrypted before it is sent to us. If you mark an alert as a false positive, we store that report. If you enter an email after a scan to save results to a dashboard, we store that email with a user and organisation ID.
  • What stays on your device: Process icons and the live scan display in the website. Those are not uploaded.
  • Why: To detect and investigate malware and attacks on your device, operate the service, and improve detection accuracy. We don't use this data for advertising, and we don't sell it.
  • Where it goes: To our scan service in the United Kingdom (Amazon Web Services). Encrypted memory snapshots are stored in AWS S3 in the UK. Connection metadata may be processed by Cloudflare in front of the API.
  • How long we keep it: We do not currently auto-delete scan data, device profiles, memory snapshots, IP/location metadata, false-positive reports, or dashboard signup emails. We keep them until we delete them or action a valid erasure request, unless the law requires us to keep them longer.
  • An important caveat: Because we look at real memory contents, we can incidentally see sensitive things that happen to be open in a scanned program, for example text in a document, a password, or a login token. We don't go looking for this deliberately, but we can't fully rule it out. See Section 6.4.
  • Who's responsible: If you installed and run this yourself, OdinEye Ltd is the controller of your data. If your employer or organisation deployed it on a work device, they are usually the controller and we act on their instructions as a processor. See Section 4.
  • Your rights: You can ask what we hold, ask us to correct or delete it, or object to how it's used. Contact privacy@odineye.io. See Section 12.

1. Who we are

OdinEye Ltd ("we", "us", "our") provides OdinEye, a Windows application that inspects programs running on your computer for signs of malware, tampering, and related evasion techniques.

Contact and data protection enquiries: privacy@odineye.io

We have not appointed a Data Protection Officer. Use the address above for all privacy requests.

2. Scope of this policy

This policy describes personal and device-related data processed by:

  • OdinEye on your Windows computer,
  • Our scan service, which receives and analyses scan data from your computer, and
  • The OdinEye website and companion scan UI that displays scan progress and results on your device.

3. Summary of data we process

CategoryWhat it covers
Device identifierA unique ID derived for your device so we can recognise it across scans
Device and system informationComputer name, Windows account name, domain (if joined), operating system and hardware details, locale/timezone, and firmware identifiers such as serial numbers
Scan dataInformation about programs running on your device, including memory-inspection data used to detect malware and tampering
Alert memory snapshotsIf a scan raises an alert, a full, encrypted snapshot of that program's memory, for investigation
Connection informationYour IP address and an approximate location (country, region, city) derived from it by our network provider
False-positive reportsIf you flag an alert in the UI, the detection IDs, device ID, scan ID, and process ID you reported
Dashboard signup emailIf you enter an email after a scan to save results to a dashboard, that email address plus the user and organisation IDs we generate for it
Local UI displayProcess names, icons, progress, and alerts shown in the website on your computer. Icons are not sent to us

We do not sell this data, and we don't use it for advertising.

4. Who is responsible for your data: controller and processor roles

OdinEye is used in two different ways, and who is responsible for your data depends on which applies to you:

4.1 Direct / individual use

If you personally downloaded, installed, and run OdinEye on your own device (not on behalf of an employer or organisation), OdinEye Ltd is the data controller for the personal data processed by OdinEye, the scan service, and the companion UI. This policy is our notice to you, and Sections 5 to 15 apply to you in full.

4.2 Enterprise / organisational deployment

If OdinEye was installed on your device by, or at the direction of, an employer or organisation (for example as part of an endpoint security programme), that organisation is normally the data controller, and we act as a data processor, handling data only on their documented instructions under a separate Data Processing Agreement. In that case:

  • The organisation's own privacy notice to you, not this document, is the primary source of your data protection rights and should be your first point of contact.
  • We process data under contract with that organisation and do not use it for our own independent purposes, except as needed to operate and secure the service and as described in this policy where we remain a controller (for example service security and abuse prevention).
  • Some sections of this document (for example Section 12, "Your rights") describe rights you should generally direct to your organisation's administrator or privacy contact first, who can in turn contact us.
  • Depending on the facts of a given deployment, we and the organisation may instead be joint controllers; where this applies, the organisation's notice should say so and describe the arrangement.

Because OdinEye can be installed by anyone, we cannot know in advance which scenario applies to a given installation. If you are unsure whether your use falls under 4.1 or 4.2, contact privacy@odineye.io and we will clarify.

5. Legal bases for processing (UK / EEA)

Where UK GDPR or EU GDPR applies, we rely on the following bases depending on context:

ProcessingTypical lawful basis
Malware detection and security of your device and our serviceLegitimate interests (Article 6(1)(f))
Processing necessary to provide the service you or your organisation requestedPerformance of a contract (Article 6(1)(b))
Compliance with legal obligationsLegal obligation (Article 6(1)(c))

Our legitimate interests are: detecting and preventing malware, intrusion, and fraud affecting your device and our service; maintaining the security and reliability of the OdinEye service; preventing abuse; and improving detection accuracy. We have assessed that these interests are not overridden by your rights and freedoms, taking into account the sensitivity of the data involved and the safeguards described in this policy.

Where processing involves special category data (see Section 6.4), a lawful basis under Article 6 alone is not sufficient. See Section 6.4 for the additional condition we rely on.

Organisations deploying OdinEye in an enterprise environment may be the controller or joint controller for their deployment. See Section 4.

6. What we collect, and why

6.1 A device identifier

When OdinEye starts, it generates a unique 64-character identifier for your device. It is a SHA-256 hash of the Windows MachineGuid, the system volume serial number, and CPU feature information. The identifier does not on its own tell us your name. It exists so we can recognise the device across scans, keep results separate, rate-limit the API, encrypt alert memory snapshots, and prevent one client from reading another's results.

The raw MachineGuid, volume serial, and CPUID material are not sent as the device identifier: only the hash is. See Section 6.2 for a related exception in the device profile.

6.2 Device, account, and system information

On the first scan of each session, OdinEye sends a device profile to the scan service. This includes:

  • Identity: computer name (hostname), Windows user name of the account running OdinEye, and directory / Azure AD domain name if the machine is joined.
  • Software and hardware: Windows version and edition, OdinEye version, CPU model, RAM size, logical processor count, and whether the machine appears to be a virtual machine.
  • Locale: keyboard layouts, user and system locale, UI languages, timezone, and the country/region from Windows regional settings (not GPS).
  • Firmware / SMBIOS identifiers: manufacturer, product, serial numbers, asset tags, and system UUID. These can be device identifiers under privacy law. We use them for inventory, environment matching, and fraud-resistant device recognition.
  • Organisation identifier: an identifier that associates the installation with an OdinEye organisation.

If firmware serial number or UUID fields are missing or are generic OEM placeholders, OdinEye may currently fill those profile fields with the Windows MachineGuid. In that situation the MachineGuid is included in the device profile we receive, not only in the hashed device identifier.

6.3 Information about the programs being scanned

When you run a scan (including from the website), OdinEye inspects processes owned by the Windows account that is running it. It does not scan other users' processes by default. The scan covers the eligible processes on the machine for that run; it is not a keylogger and it is not an always-on background monitor unless you run it again.

For each scanned program we collect identifying details (name, full path, process ID, publisher / Authenticode signature) and technical indicators from memory, threads, modules, stacks, timers, exception handlers, and related runtime state: the kind of data that distinguishes normal software from malicious or tampered software.

Because this involves looking at what is actually in a running program's memory, it is possible to incidentally capture other information present at that moment, for example document text or credentials temporarily stored in memory. OdinEye does not intentionally collect keystrokes, clipboard contents, browsing history, or your files as files; its purpose is limited to identifying malicious behaviour in running programs.

6.4 Special category data: how it can arise, and our approach

Because of the inspection described above, it is possible for our processing to incidentally include special category data under Article 9 UK/EU GDPR, for example health information visible in an open document, or content revealing religious belief, political opinion, sexual orientation, or trade union membership, if such content happens to be present in a scanned program's memory.

We want to be direct about this:

  • We do not target special category data. Detection looks for technical indicators of tampering and malicious behaviour, not for the meaning of text in memory.
  • We cannot fully exclude it. We cannot reliably filter it out before collection without undermining the security purpose of the scan.
  • Our Article 9 condition: where special category data is incidentally processed in the course of malware and intrusion detection, we rely on the condition for processing necessary for reasons of substantial public interest in the prevention or detection of unlawful acts, including fraud and cybercrime (UK GDPR Schedule 1, Part 2; equivalent EU member state law where applicable), together with the safeguards in this policy.
  • Minimisation and safeguards: the fuller alert memory snapshots in Section 6.5 are collected only when a scan raises an alert, are encrypted before they leave your device, and access is restricted to people who need it to run and support the service.

If you believe a scan has captured special category data about you specifically and you would like it deleted, contact privacy@odineye.io.

6.5 Alert memory snapshots

If a scan identifies a high-confidence sign of malware or tampering, OdinEye may capture a full-process memory dump of that program, compress it, encrypt it with AES-256-GCM using a key derived from your device identifier, and upload it to Amazon S3 in the UK using a short-lived URL issued by our scan service.

Because it is a full snapshot, it may include highly sensitive information that happened to be in that program's memory, for example login details, encryption keys, or personal communications. Encryption protects the file in transit and at rest from third parties. OdinEye can decrypt these snapshots using key material derived from the device identifier held in the service, so that we can investigate the alert.

6.6 Connection and location information

As with any internet connection, our scan service receives your device's IP address. We read this from Cloudflare, together with country, region, and city codes Cloudflare derives from that IP. OdinEye itself does not look up your location or use GPS. We use this for security, abuse prevention, and service operation, not to precisely track you.

6.7 The companion website / UI

The OdinEye scan website talks to OdinEye over a local WebSocket on your computer (OdinEye listens on port 1337 by default). That channel is meant to stay on your machine. You should restrict network access to that port so other devices cannot reach it.

The UI shows scan progress, process names, signing information, alerts, and application icons. Process icons are kept locally and are not uploaded to the scan service.

If you mark an alert as a false positive, the UI sends the device identifier, scan ID, process ID, and detection IDs to the scan service so we can record the report and stop treating that detection as an alert for your device.

If you choose to save a scan to a dashboard, the UI sends the email address you enter to the scan service. We store it with a generated user ID and organisation ID. The website does not collect account logins or advertising/analytics identifiers.

7. What we do not collect

In particular, we do not:

  • Collect the contents of your files from disk, beyond what is needed to verify a program's authenticity and compare in-memory code with the on-disk image.
  • Access your camera, microphone, or precise location services.
  • Run as an always-on background monitor. A scan happens when you run OdinEye (including from the UI).
  • Use the data for advertising, or embed third-party advertising or behavioural analytics tools in OdinEye or this website.
  • Set advertising or analytics cookies on this website. OdinEye is native desktop software and does not use cookies.

8. How we use the data

PurposeDescription
Threat detectionIdentify malware and tampering in programs running on your device
Alert investigationAnalyse memory snapshots associated with high-confidence alerts
Device recognitionDistinguish endpoints from one another and bind results to the submitting device
Rule matchingApply detection rules appropriate to your device's environment
Service operationPrevent abuse, rate-limit the API, version OdinEye, and support the service
Product improvementTune detection accuracy and measure scan performance, including learning from alerts and confirmed false positives
Dashboard signupCreate a user and organisation record from the email you enter after a scan, so results can later be associated with a dashboard

9. Sharing and subprocessors

We share data only as needed to operate the service:

RecipientWhat they doLocation
Amazon Web ServicesHost our service and store scan dataUnited Kingdom
CloudflareProtect and deliver the serviceCloudflare's global network

We do not sell personal data.

OdinEye personnel who operate the service can access scan results and memory snapshots solely to run, secure, and support the service.

For a current subprocessor list, contact privacy@odineye.io.

10. International transfers

Our scan database and alert-snapshot storage are hosted on Amazon Web Services in London (eu-west-2). Core scan data described in this policy is not routinely stored outside the UK.

Cloudflare operates a global network. Limited connection information (Section 6.6) may be processed outside the UK or EEA. Where that happens, we rely on appropriate safeguards (for example the UK International Data Transfer Addendum or EU Standard Contractual Clauses) and, where required, a transfer risk assessment. Details are available on request from privacy@odineye.io.

If our hosting arrangements change to include storage locations outside the UK/EEA, we will update this section.

11. Retention

We do not currently operate timed auto-deletion for the records below. Until we do, the following applies:

Data typeRetention period
Scan data and resultsKept until we delete it, or until we action a valid erasure request, unless we are legally required to retain it longer
Device identifier and device profileKept while we hold records for that endpoint, until we delete it or action a valid erasure request
Alert memory snapshotsKept until we delete the object, or until we action a valid erasure request, unless we are legally required to retain it longer
Connection / IP / geo metadataStored on the device record with the profile; kept on the same basis as the device profile. Server logs are operational and may be retained as needed for security investigation
False-positive reportsKept until we delete them or action a valid erasure request
Dashboard signup emailKept until we delete it or action a valid erasure request
Information displayed locally in the UI (Section 6.7)Remains under your control on your device; we do not store process icons or the live UI session

We intend to introduce defined retention periods. This section will be updated when those are in operation. To request deletion sooner, contact privacy@odineye.io.

12. Your rights

Depending on your location, you may have rights to:

  • Access personal data we hold about you or your device.
  • Rectify inaccurate data.
  • Erase data (subject to legal and security exceptions).
  • Restrict or object to certain processing.
  • Data portability where applicable.
  • Withdraw consent where processing is consent-based. Our core scanning is not based on consent.
  • Complain to a supervisory authority (for example the ICO in the UK).

We do not currently offer an in-product deletion button. Rights requests are handled by email.

Enterprise users should normally direct requests through their organisation's administrator. See Section 4.

To exercise rights: contact privacy@odineye.io. Please include enough detail for us to identify the device (for example the device identifier, if you have it).

13. Automated decision-making

Whether a scan is flagged as an alert is determined automatically by our detection service, without human review at the moment the determination is made. Depending on how an alert is acted on in your deployment (for example whether it only notifies you versus triggering an automatic response such as device isolation), this may constitute automated decision-making with a legal or similarly significant effect under Article 22 UK/EU GDPR.

Direct/individual use (Section 4.1): alerts are informational. We do not take an automatic account or device action based solely on an alert.

Enterprise deployment (Section 4.2): whether an alert triggers an automated response (for example network isolation) is configured and controlled by your organisation, not by us. Your organisation's own notice should explain any such effects and how you can request human review.

If you believe a decision has been made about you solely by automated means with a significant effect, and you have not been given an adequate explanation, contact privacy@odineye.io or your organisation's administrator to request human review.

14. Children

OdinEye is not directed at children. We do not knowingly collect data from anyone under 13 (the UK's age of digital consent for information society services) or the applicable age of digital consent in your country, without appropriate authority.

15. Changes to this policy

We may update this policy when OdinEye, the scan service, or website changes. Material changes will be communicated by publishing the updated policy on this page. The "Last updated" date at the top will be revised accordingly.