Privacy Policy

Effective Date: May 5, 2026

This Privacy Policy explains how Network Canaries LLC. ("we", "us"), operating the Network Canaries service at https://networkcare.io, collects, uses, and shares personal data when you use the Service. It applies to all visitors, waitlist subscribers, and customers.

1. Data We Collect

We collect and process the following categories of data:

  • Account data: name, email address, password hash, and (if you sign in with Google) the OAuth identifier and basic profile fields returned by Google. We compute an MD5 hash of your email address to fetch a default avatar image from Gravatar — see Subprocessors below.
  • Waitlist data: if you sign up for the private beta waitlist, we store your email address until you are invited or until you ask us to delete it.
  • Billing data: for paid plans, billing address and payment-method metadata. Card numbers are handled exclusively by Stripe; we never see or store them.
  • Configuration data: the targets you choose to monitor (IP, domain, URL), check types, intervals, alert rules, and labels. This may include data that is sensitive in context (for example, a URL that reveals an internal service name).
  • Operational logs: request timestamps, HTTP status codes, error traces, and the SHA-256-truncated hash of source IP addresses. We do not log raw IP addresses in application logs.
  • Cookies: we set the cookies listed in §5 below. None are used for advertising. We do not currently run any analytics or tracking cookies; if we add any in the future, we will update this Policy and notify account holders before doing so.

2. How We Use Data

We use the data above to:

  • Operate and maintain the Service, including running the checks you configure.
  • Authenticate you and secure your account.
  • Bill you and process payments through Stripe.
  • Send transactional email — verification, password reset, alert notifications, and billing receipts.
  • Detect, investigate, and respond to abuse or security incidents.
  • Comply with our legal obligations.

We do not sell your personal data. We do not use your data to train machine-learning models. We do not run advertising on the Service. We do not perform automated decision-making — including profiling — that produces legal or similarly significant effects concerning you.

3. Legal Bases (EEA / UK Users)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (operating the Service you signed up for), legitimate interests (security, fraud prevention, product improvement), consent (where required for optional communications), and legal obligation (tax, accounting, lawful requests).

4. Subprocessors

We use the following third-party service providers ("subprocessors") to operate the Service. Each is bound by a data-processing agreement and processes data only on our instructions.

Subprocessor Purpose Data location
StripePayments and subscription billingUnited States, EEA
ResendTransactional email deliveryUnited States
Google (OAuth)"Sign in with Google" authenticationUnited States
DigitalOceanApplication hosting and managed databasesUnited States
SentryError monitoring and aggregated diagnosticsUnited States
CloudflareBot mitigation (Turnstile) on signup; static asset CDN (cdnjs)Global edge; United States
jsDelivr (Fastly)JavaScript / CSS asset delivery (CDN)Global edge
Automattic (Gravatar)Default avatar lookup keyed on a hash of your emailUnited States

We will update this list when we add or change subprocessors. Material additions will be announced by email to active customers.

5. Cookies

We set the following cookies. All are strictly necessary to operate the Service and are exempt from consent under the GDPR ePrivacy Directive Article 5(3).

  • sessionid — session cookie required for login to work; cleared on logout.
  • csrftoken — CSRF protection cookie required for form submissions.
  • django_language — stores the language you selected from the locale switcher.
  • theme — stores your light/dark theme preference.

We do not currently use any advertising, analytics, or cross-site tracking cookies.

6. International Transfers

Our infrastructure and several of our subprocessors are located in the United States. Where we transfer personal data of EEA, UK, or Swiss users to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent safeguards offered by each subprocessor.

7. Data Retention

We retain personal data only as long as needed for the purposes listed above. Specific retention windows:

  • Account data: retained while your account is active, and for up to 90 days after deletion to allow recovery and to satisfy our legal obligations.
  • Waitlist data: retained until you accept your invitation or request deletion. We do not actively purge waitlist entries; email [email protected] to be removed.
  • Check results: retained per plan — Free 7 days, Pro 90 days, Business 365 days — then automatically purged.
  • Audit logs: agent and authentication audit logs are retained for 30 days.
  • Billing records: retained for the period required by tax and accounting law (typically 7 years).

8. Your Rights

Depending on your jurisdiction (EEA, UK, California, and others), you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data.
  • Object to or restrict certain processing.
  • Receive a copy of your data in a portable format.
  • Withdraw consent (where processing is based on consent).
  • Lodge a complaint with your local data-protection authority.

To exercise any of these rights, email [email protected]. We respond within 30 days.

9. Data Protection Officer

We are not required to appoint a Data Protection Officer under GDPR Article 37 and have not done so. Privacy questions should be directed to [email protected].

10. Security

We protect data with industry-standard controls: TLS for data in transit, encryption at rest for our managed databases, per-tenant authorization checks, rate limiting and audit logging on sensitive endpoints, hashed API keys, and truncated-hash logging of IP addresses. No system is impenetrable; report suspected vulnerabilities to [email protected] — see our security.txt for disclosure terms.

11. Children

The Service is not intended for individuals under 18, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Data Processing Addendum (DPA)

Customers acting as data controllers under the GDPR may request a Data Processing Addendum incorporating the EU Standard Contractual Clauses by emailing [email protected].

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version with a revised Effective Date and, for material changes, notify account holders by email.

14. Controller and Contact

The data controller is Network Canaries LLC.. Privacy questions and rights requests: [email protected].