Privacy policy

Last updated: August 5, 2026

PermitUSB is a USB device control platform built and operated by JJMK Studios, LLC ("JJMK", "we", "us"), an Oregon company. The product has two halves: a Windows agent that your IT team installs on company endpoints, and a cloud dashboard and API at permitusb.com. This policy explains what we collect, why we collect it, where it goes, how long we keep it, and how to get it deleted. It is written to be read, not skimmed past; if anything is unclear, email privacy@permitusb.com.

1. Who this policy covers

Three kinds of people interact with PermitUSB:

  • Subscribers - the company that creates an account, pays for the service, and installs the agent on its endpoints. The Subscriber decides what to monitor and controls the data the agent collects. In data protection terms, the Subscriber is the data controller of endpoint and employee data.
  • Admin users - the individual people (usually IT staff) who sign in to the dashboard under a Subscriber's account.
  • Endpoint Users - the Subscriber's employees whose Windows machines run the PermitUSB agent. We have no direct relationship with Endpoint Users; we process data about them on the Subscriber's behalf, as a data processor. If that is you, see section 11, "Notice to Endpoint Users".

This policy covers the permitusb.com website, the cloud dashboard, the API, and the endpoint agent.

2. Information you provide directly

  • Account data. When you sign up we collect your email address, a password, and your company name. Passwords are handled by our authentication provider (Supabase Auth) and stored only as a cryptographic hash; we never see or store plaintext passwords. If you sign in with Google or Microsoft instead, we receive your email address from that provider. We also store each admin user's role and MFA status.
  • Teammate invitations. When you invite a teammate we collect and store the invitee's email address.
  • Billing data. Payments are processed by Stripe. Stripe collects your company name, billing contact, billing address, and payment instrument. Card numbers never touch our servers; we store only Stripe's customer and subscription identifiers and your subscription status.
  • Content you enter in the dashboard. Policy names, rule definitions, endpoint group names, device nicknames, webhook URLs, and similar configuration are stored as entered. Free-text fields such as device nicknames may contain personal information if you choose to include it (for example, naming a device "Joe's thumb drive"); what you type is what we store.
  • Support and other email. If you email us, we keep the correspondence.

3. Information the endpoint agent collects

The agent exists to enforce your USB policy and report what happened. Everything below is collected from endpoints the Subscriber enrolled, is visible to the Subscriber's admins in the dashboard, and exists so the product can function.

  • Enrollment data. When an endpoint enrolls, the agent sends the machine's hostname, Windows edition and build number, the agent version, and two hardware fingerprints used to recognize re-enrollment of the same physical machine. Both fingerprints are SHA-256 hashes computed on the endpoint (one of the Windows MachineGuid, one of the SMBIOS system UUID); the raw identifiers never leave the machine.
  • Check-in data. The agent checks for policy updates roughly every 10 minutes and reports its hostname, OS version, agent version, and the Windows account name of the currently signed-in user (for example, CORP\jsmith).
  • Device events. For each USB plug, unplug, or policy decision, the agent reports: the device's USB vendor and product identifiers (VID/PID), device class, friendly name (for example, "Kingston DataTraveler 3.0"), and serial number when the device exposes one; the action taken (allow, block, and so on) and the policy rule that matched; the Windows account name of the signed-in user at the time (blank if the machine was at the login screen); the endpoint's local IP addresses at capture time; a timestamp; and the full Windows Plug and Play property record for the device as reported by the operating system, which includes device hardware identifiers and the computer name.
  • Server-captured IP. When the agent reports events, our servers record the public IP address the report arrived from.
  • Kernel crash fingerprints. If a Windows crash implicates the PermitUSB driver, the agent reports a fingerprint only: the stop code and its four parameters, the faulting module name and offset, the driver version, the crash time, and the dump file name. The agent reads only the crash dump's fixed-size header; memory contents never leave the machine.
  • Tamper and health signals. The agent reports self-protection signals such as event flooding or rate-limit trips, with minimal accompanying detail.
  • Local offline buffer. When an endpoint is offline, events are spooled in a local database on the endpoint and uploaded when connectivity returns. The uninstaller can purge this local data (the PURGE_DATA=1 install option).

4. What the agent never collects

These exclusions are design decisions, not marketing. Specifically, the agent does not collect:

  • File contents. PermitUSB sees that a storage device was plugged in - never what is on it. We do not scan, copy, index, or inspect files on USB media or anywhere else.
  • Keystrokes, screen contents, microphone, camera, or location.
  • Network traffic or browsing activity. We do not proxy or inspect anything.
  • Windows security identifiers (SIDs), or the machine's raw hardware identifiers (only the on-device hashes described above are transmitted).
  • Crash dump memory contents (fingerprint header only, as described above).

5. Information collected on the website and dashboard

  • Authentication cookies. Signing in sets session cookies from our authentication provider (Supabase Auth) and, after multi-factor verification, a first-party MFA cookie. Both are functional cookies required to keep you signed in; they are not used for tracking.
  • Browser storage. The dashboard stores your light/dark theme preference in localStorage and a dismissed-banner flag in sessionStorage. Nothing else.
  • No analytics or advertising. We run no product analytics, no advertising trackers, and no third-party analytics scripts on the website or the dashboard. The marketing site has no signup forms or lead capture; contact happens over plain email.
  • Error monitoring. We use Sentry to capture application errors. It is configured not to collect request headers, cookies, or IP addresses, and session replay is disabled. Error reports are tagged with an internal user ID and tenant ID only - not your email.
  • Security and infrastructure logs. Our hosting provider (Vercel) keeps standard request logs. We temporarily store client IP addresses for rate limiting on the unauthenticated agent enrollment endpoints. Our authentication provider records sign-in history, including sign-in IP addresses, in its own audit trail.
  • Admin audit log. Administrative actions in the dashboard (policy edits, invitations, role changes, security setting changes, and similar) are recorded in a per-tenant audit log visible to the Subscriber's admins. When an admin account is deleted, the audit log retains a record of the deletion including the deleted account's email address, so the trail stays accountable.

6. How we use information

We use the data above to:

  • Provide the service: enforce your USB policies, show device events and endpoint state to your admins, and deliver the alerts you configure.
  • Protect the service: authentication, rate limiting, tamper detection, and driver crash health monitoring.
  • Bill you, via Stripe.
  • Support you when you ask for help.
  • Send transactional and service email to admin contacts: alerts they configured, billing notices, and product or security notices relevant to their account.

We do not:

  • Sell personal information, or share it for advertising. We have no advertising business.
  • Use customer data to train machine learning models.
  • Email Endpoint Users. Ever. Email goes only to the Subscriber's admin contacts, and only for the purposes above.

7. How we share information

  • Sub-processors. We use a small number of infrastructure vendors to run the service (database and authentication, payments, hosting, transactional email, DNS, error monitoring). The current list, with what each vendor sees, is maintained at permitusb.com/legal/sub-processors.
  • At your direction. Subscribers can configure outbound webhooks (for example to Slack, Teams, PagerDuty, or a SIEM), run the on-premises SIEM relay against their own API key, and export events as CSV or JSON. Data sent to destinations you configure is governed by those destinations' terms, and choosing them is your responsibility.
  • Legal requirements. We may disclose information if required by law, subpoena, or other legal process, or to protect the rights, safety, or property of JJMK, our customers, or the public. Where lawful, we will notify the affected Subscriber before disclosing.
  • Business transfers. If JJMK is involved in a merger, acquisition, or asset sale, customer data may transfer as part of that transaction, subject to this policy or a successor policy with equivalent protections.

8. Where data lives

PermitUSB is a US-hosted service. Application data is stored in the United States and all of our sub-processors are US-based. We do not currently offer an EU or UK data residency option. If you are subject to GDPR or UK GDPR, you act as controller and engage us as a processor; contact us with any questions about processing terms before subscribing.

9. Retention and deletion

  • Device events, tamper events, and audit logs: retained for 365 days from capture, then deleted on a rolling basis. We deliberately do not offer retention shorter than 90 days, because that breaks the compliance use cases (such as NIST 800-171 audit trails) our customers rely on; contact support to discuss a shorter window between 90 and 365 days.
  • Webhook delivery logs: retained for 7 days.
  • Expired trials: if a trial ends and the account never converts to paid, the entire tenant and all its data are deleted 30 days after expiry.
  • Account closure: when a Subscriber cancels, data is preserved for 30 days (so you can come back), then deleted.
  • Deletion on request: a Subscriber can request deletion at any time by emailing privacy@permitusb.com. We delete within 30 days and email confirmation when the deletion completes.
  • On the endpoint: uninstalling the agent stops all collection. Uninstalling with the PURGE_DATA=1 option also wipes the agent's local event buffer from the machine.

10. Security

  • All traffic between the agent, the dashboard, and our servers uses TLS 1.2 or higher.
  • Data is encrypted at rest by our database provider.
  • Every customer's data is isolated per tenant, enforced at the database layer with row-level security.
  • Passwords are hashed by our authentication provider. Agent credentials, enrollment tokens, and API keys are stored only as cryptographic hashes.
  • Multi-factor authentication is available to every admin and can be enforced workspace-wide by the Subscriber.
  • Agent binaries are signed with an EV code signing certificate, and kernel components are signed through the Microsoft hardware program.

No security program is perfect. If you believe you have found a vulnerability, email security@permitusb.com.

11. Notice to Endpoint Users

If your work computer runs the PermitUSB agent, your employer (or the organization that manages your machine) chose to install it and controls what it does. In plain terms:

  • It records USB device activity on your machine: what device was plugged in or removed, whether it was allowed or blocked, your Windows account name at the time, and the machine's name and network addresses.
  • It cannot see your files, what you type, your screen, your browsing, or your location - see section 4.
  • We process this data on your employer's behalf and never contact you or send you marketing.
  • Questions about why it is installed, and any requests to access or delete data about you, should go to your employer - they control the data. Their acceptable-use policy governs monitoring on their machines.

12. Government contractors and CUI

Many of our customers use PermitUSB while preparing for CMMC or implementing NIST 800-171. Because the agent does not access file contents, Controlled Unclassified Information (CUI) itself is not intended to transit or be stored in PermitUSB; what we hold is CUI-adjacent metadata (device events and audit logs) processed on the Subscriber's behalf. We do not hold a FedRAMP or DoD authorization and do not claim CMMC certification. A control-by-control mapping of how PermitUSB supports NIST 800-171 is published at permitusb.com/docs/nist-800-171.

13. US state privacy rights

PermitUSB is a business-to-business service, and we act primarily as a processor (or "service provider" under the CCPA) for our Subscribers. We do not sell personal information and do not share it for cross-context behavioral advertising. Where a state privacy law grants you rights over personal information we hold as a controller (such as your admin account data), you can exercise them - access, correction, deletion, or a copy of your data - by emailing privacy@permitusb.com. We do not discriminate against anyone for exercising privacy rights. Requests about endpoint data collected on behalf of a Subscriber should go to that Subscriber; we will refer such requests to them and support their response.

14. Children

PermitUSB is a workplace tool for businesses. It is not directed at children, and we do not knowingly collect personal information from anyone under 16.

15. Changes to this policy

When we change this policy we will post the new version here and update the "Last updated" date at the top. For material changes we will also email Subscriber admin contacts before the change takes effect.

16. Contact

JJMK Studios, LLC, Oregon, USA.
Privacy questions and requests: privacy@permitusb.com
Security reports: security@permitusb.com