Privacy policy.

Effective 16 August 2026 · last revised 16 August 2026 · Disponible en español

The short version

  • If you fill in our contact form, we get what you typed, by email, through our form-processing provider. We use it to reply to you.
  • If you use the breach-lookup tool, which appears on our security, scams, family and surveillance pages, the address you type passes through our server to Have I Been Pwned so it can be checked. We do not write it to our application database or to analytics, and we do not add it to any list.
  • We run Google Analytics with ad personalization and Google Signals switched off. It records pages viewed and derived completion results, such as a quiz score and tier, but not your individual answer selections, free text, name, email address or organization name. Google also processes standard network, device and pseudonymous analytics data.
  • Four recipients can receive data because of how this site and our client communications work: Google (analytics and fonts), our hosting and form-processing provider, Have I Been Pwned (the breach lookup) and our email delivery service. Each is described below, and each processes data only on our behalf.
  • We do not sell your information, we do not run advertising pixels, and there are no accounts on this site.
  • To see, correct or delete what we hold, email info@mutiny-labs.com.

Who we are

Mutiny Labs is a technology studio based in Puerto Rico. This policy covers www.mutiny-labs.com and the pages served from it, including the public Support & Education library. It is written to meet Puerto Rico’s Ley 39-2012, which requires a commercial website that collects personal information from Puerto Rico residents to publish a policy that is clear, concise, conspicuous and unambiguous, stating what is collected and the persons or entities with whom it may be shared.

You can reach us at info@mutiny-labs.com, at +1 888 449 4466, or by mail at 1666 Ponce de León Ave, Suite 208, San Juan, PR 00909.

What this site collects

1. The contact form

The form on our home page collects exactly these fields: your name, your organization, your email address, your message, and how you heard about us. It also records the choices you click for which world you are in, project type, budget range and timeline, plus a hidden field noting which version of the site you saw.

The form is processed by our hosting provider's form service and delivered to us. We use it to reply, to prepare for a conversation, and to keep a record of enquiries. We do not add contact-form addresses to any marketing list.

The form includes a hidden anti-spam field. If a bot fills it in, the submission is discarded.

2. The breach-lookup tool

On our security, scams, family and surveillance pages you can type an email address to check whether it appears in known data breaches. It is the same tool and the same handling on all four. Here is exactly what happens to it, including the part that is less comfortable to write:

  • The address is sent from your browser to our own server-side function, which forwards it to Have I Been Pwned and returns the result.
  • We do not write it to application storage, a database, or analytics, and we do not add it to any list.
  • It does transit our server. Transient operational logs may exist somewhere in that delivery chain, at our hosting provider or at Have I Been Pwned, and we cannot promise those away. Anyone who would rather avoid that can use haveibeenpwned.com directly, which the tool tells you.
  • Our function applies a short-term rate limit using the requesting IP address, held in memory only, to stop abuse.

3. Two optional email forms

Every page, tool and download in the library is free to use without giving us anything. Two optional forms exist alongside them, and both are opt-in by definition: you only appear in them if you fill one in.

The quarterly brief. On the AI threat record, the library and the home page you can ask for the next revision by email. We collect your name and email address, plus a hidden field noting which page you signed up from and which version of the site you saw. We use it to send that one mailing and nothing else. Unsubscribe by replying or writing to us, and one request is enough.

Email me my report. After the hygiene quiz, the infrastructure assessment or the Puerto Rico website check produces a result, you can ask us to email it to you. We collect your name, your email address, an optional opt-in checkbox for occasional Support & Education updates, which is unchecked unless you tick it, and a compact text summary of the result already on your screen: the score and tier, or the percentage and weakest area, or the counts of gaps, open questions and possible triggers. That summary carries the same derived result our analytics already receives and nothing further. Your individual answer selections are not included, and no free text is collected by these tools because they do not have any.

If you do not tick the optional box, we use your address to send that one report and for nothing else.

Both forms are processed by Netlify Forms and delivered to us, and the report and confirmation emails are sent through a specialist email delivery service, which processes your name and address for that delivery. Both forms carry a hidden anti-spam field; if a bot fills it in, the submission is discarded.

4. Analytics

We use Google Analytics 4. Our configuration sets allow_google_signals to false and allow_ad_personalization_signals to false, to limit Google Signals association and advertising-personalization signals. Those two flags really are set; what Google does with them is Google’s documented behaviour, and that behaviour and any consent configuration can change. We do not run advertising or remarketing pixels.

Analytics receives: pages viewed, which sections you scrolled to, scroll depth, time on page, clicks on links and calls to action, outbound link domains, and any campaign parameters in the URL you arrived with. Google derives an approximate location from your IP address as part of its normal operation.

The interactive tools also send a derived completion result so we know they are being used. These carry no individual selections and no free text:

  • The hygiene quiz sends a score and a tier label.
  • The infrastructure assessment sends a percentage, a count of weak areas, and the name of the weakest category.
  • The Puerto Rico website check sends counts of items returned as gaps, open questions and possible triggers.
  • The incident drill sends which scenario was started or completed.
  • The breach lookup sends only an outcome word and the number of breaches found. It never sends the email address or the names of the breaches.

These carry derived results: scores, tiers, percentages, counts and category labels. They do not carry your individual selections, your free text, your name, your email address or your organization name. We spell this out because several of those pages make the same promise, and a promise on a page is worth what the policy behind it says.

5. Fonts and hosting

Typefaces load from Google Fonts, which means your browser makes a request to Google servers that includes your IP address. The site is hosted by a professional hosting provider, which keeps standard server logs.

6. What we do not do

  • There are no user accounts and no passwords on this site.
  • We do not sell or rent personal information.
  • We do not use advertising or social-media tracking pixels.
  • We do not collect biometric information, precise geolocation, or payment details on this site.
  • Our Support & Education pages are public and indexable. The Spanish translations under /es/ stay out of search while they are being rebuilt. This policy is deliberately indexable.

Who receives your information

7. Email we send to clients

If you are a Mutiny Labs client, we may send you occasional Support & Education email at the address you gave us in the course of working together. These messages are delivered through a specialist email delivery service, which processes your email address and standard delivery data on our behalf. Links in those emails carry campaign parameters that our analytics recognizes if you visit the site. Every such email includes a way to opt out, and one request is enough: we remove you promptly and do not send again.

These are the recipients that can receive personal information because of how this site works, described by role. Google and Have I Been Pwned are named because you interact with their services directly; our infrastructure providers process data under our instructions, while Google and Have I Been Pwned also operate under their own service terms and privacy documentation rather than solely on our behalf. We will identify our infrastructure providers on request at info@mutiny-labs.com.

RecipientWhat it receivesWhy
Our hosting and form-processing providerContact-form submissions; server logs; requests to our breach-lookup functionHosting, form handling and serverless functions
Google (Analytics)Usage events as described above, and your IP address, from which Google derives approximate locationUnderstanding which pages and tools are used
Google (Fonts)Your IP address and browser details when a font loadsTypography
Have I Been PwnedOnly the email address you type into the breach-lookup tool, and only when you press the buttonPerforming the breach lookup you asked for
Our email delivery serviceClient email addresses and delivery data for the Support & Education emails we sendEmail delivery

We may also disclose information if we are legally required to, or to establish or defend a legal claim. We will not do so quietly if we are permitted to tell you.

How long we keep it

Contact-form submissions are kept for as long as we may reasonably need them for the relationship or enquiry that produced them, and we will delete them sooner on request. Quarterly-brief subscriptions are kept until you unsubscribe. Report requests are kept for up to twelve months so we can answer a question about an email we sent you, unless you asked for updates too, in which case the address stays on that list until you unsubscribe. All of it goes sooner if you ask. Analytics data is retained under Google Analytics’ own retention settings. We do not write the breach-lookup address to our application database or to analytics; it is processed transiently and may appear in short-lived infrastructure logs, as described above.

How to see, change or delete your information

Email info@mutiny-labs.com and tell us what you want. You can ask us to:

  • tell you what we hold about you;
  • correct anything that is wrong;
  • delete what we hold, where we are not required to keep it.

We aim to acknowledge within five business days and to resolve within thirty days. If something will take longer, we will tell you why rather than going quiet. We may need to confirm you are who you say you are before acting, and we will ask for the minimum needed to do that.

To opt out of analytics entirely, you can use Google’s browser opt-out add-on or block analytics in your browser; the site works normally either way.

Children

This site is aimed at businesses and professionals. It is not directed to children, and we do not knowingly collect personal information from them. If you believe a child has sent us information, email us and we will delete it.

Changes to this policy

When we change this policy, we will update the revision date at the top and the change note below, and keep a short description of what changed. Material changes will be noted on the page for at least sixty days. There is no mailing list for policy changes, so the page itself is the record.

↳ revision history

17 August 2026 (rev. 4). The Support & Education library became public and indexable, so the statement that those pages are marked noindex is corrected; the Spanish translations under /es/ remain out of search for now. Two optional email forms are added and described in full: the quarterly brief subscription, and the request to have your own tool result emailed to you. Neither gates anything: every page, tool and download stays free to use without an email address. Retention periods for both new forms are stated, and the email delivery service is named by role alongside our other processors.

16 August 2026 (rev. 3). Clarifications following an external editorial audit. None of them change what this site collects. The breach-lookup tool is now correctly described as appearing on four pages rather than one. The plain-language summary said analytics never receives your answers; it now matches the detailed event list below, stating that analytics receives derived results (scores, tiers, percentages, counts and category labels) but not individual selections or free text, and that Google also processes standard network, device and pseudonymous analytics data. “Only on our instructions” is now “under our instructions”, noting that Google and Have I Been Pwned also operate under their own terms. “Not retained at all” is now the more accurate statement that the address is not written to application storage or analytics and may appear in short-lived infrastructure logs. The description of the two GA4 flags is narrowed to what the flags do rather than what Google guarantees.

16 August 2026 (rev. 2). Infrastructure providers are now described by role rather than by company name; their identities remain available on request.

16 August 2026. First publication. Written alongside an internal review of what this site actually collects; that review also removed the transmission of contact-form budget and timeline selections to analytics, which had been happening on click.

Mutiny Labs · San Juan, Puerto Rico · info@mutiny-labs.com · +1 888 449 4466 · effective 16 August 2026