Privacy Policy

Effective Date: September 3, 2026

This Privacy Policy explains how Network Canaries LLC. ("we", "us"), operating the Network Canaries service at https://networkcanaries.com, collects, uses, and shares personal data when you use the Service. It applies to all visitors and customers.

1. Data We Collect

We collect and process the following categories of data:

  • Account data: name, email address, password hash, and (if you sign in with Google) the OAuth identifier and basic profile fields returned by Google. Profile avatars display an initial from your workspace name, name, or email address without contacting an external avatar service.
  • Billing data: for paid plans, billing address and payment-method metadata. Card numbers are handled exclusively by Stripe; we never see or store them.
  • Configuration data: the targets you choose to monitor (IP, domain, URL), check types, intervals, alert rules, and labels. This may include data that is sensitive in context (for example, a URL that reveals an internal service name).
  • Operational logs: request timestamps, HTTP status codes, error traces, and the SHA-256-truncated hash of source IP addresses. We do not log raw IP addresses in application logs.
  • Cookies: we set the cookies listed in §5 below. None are used for advertising, and we run no tracking cookies. If we ever add an analytics or tracking cookie, we will update this Policy and notify account holders before doing so.
  • Signup attribution: when you create an account, we record the campaign tags (utm_source and similar) present in the link you arrived through, the website that referred you — the site name only, never the full address — and the plan you clicked. This tells us which channels bring us customers. It is read from that single request: we store nothing on your device beforehand and do not track your browsing across visits. If you arrive without any of this, we record nothing.
  • Website analytics: on our public marketing pages and our sign-up and log-in pages only, we use Cloudflare Web Analytics to count page views and see which countries and referring sites our visitors come from. It is cookieless: it stores nothing on your device, assigns you no persistent identifier, and cannot follow you across other websites. Country is derived from your IP address at the moment of the request and is not retained against you. We do not run analytics inside the authenticated application, and we never place analytics on our customers' public status pages.

2. How We Use Data

We use the data above to:

  • Operate and maintain the Service, including running the checks you configure.
  • Authenticate you and secure your account.
  • Bill you and process payments through Stripe.
  • Send transactional email — verification, password reset, alert notifications, and billing receipts.
  • Detect, investigate, and respond to abuse or security incidents.
  • Comply with our legal obligations.

We do not sell your personal data. We do not use your data to train machine-learning models. We do not run advertising on the Service. We do not perform automated decision-making — including profiling — that produces legal or similarly significant effects concerning you.

3. Legal Bases (EEA / UK Users)

Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (operating the Service you signed up for), legitimate interests (security, fraud prevention, product improvement), consent (where required for optional communications), and legal obligation (tax, accounting, lawful requests).

4. Subprocessors

We use the following third-party service providers ("subprocessors") to operate the Service. Each is bound by a data-processing agreement and processes data only on our instructions.

Subprocessor Purpose Data location
StripePayments and subscription billingUnited States, EEA
ResendTransactional email deliveryUnited States
Google (OAuth)"Sign in with Google" authenticationUnited States
DigitalOceanApplication hosting and managed databasesUnited States
SentryError monitoring and aggregated diagnosticsUnited States
CloudflareBot mitigation (Turnstile) on signup; static asset CDN (cdnjs); cookieless website analytics on public pagesGlobal edge; United States
jsDelivr (Fastly)JavaScript / CSS asset delivery (CDN)Global edge

We will update this list when we add or change subprocessors. Material additions will be announced by email to active customers.

5. Cookies

We set the following cookies. All are strictly necessary to operate the Service and are exempt from consent under the GDPR ePrivacy Directive Article 5(3).

  • sessionid — session cookie required for login to work; cleared on logout.
  • csrftoken — CSRF protection cookie required for form submissions.
  • nc_language — stores the language you selected from the locale switcher.
  • theme — stores your light/dark theme preference.
  • messages — short-lived cookie carrying one-off status notifications (for example "Saved") across a redirect; cleared as soon as the message is displayed.

We use no advertising, analytics, or cross-site tracking cookies. The website analytics described in §1 are cookieless — they set nothing on your device, which is why this list is unchanged by them and why we show no cookie consent banner.

6. International Transfers

Our infrastructure and several of our subprocessors are located in the United States. Where we transfer personal data of EEA, UK, or Swiss users to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent safeguards offered by each subprocessor.

7. Data Retention

We retain personal data only as long as needed for the purposes listed above. Specific retention windows:

  • Account data: retained while your account is active. After we verify and fulfil a deletion request, account data is deleted from the application database except where limited records must be retained for security, tax, accounting, or other legal obligations.
  • Check results: retained per plan — Free 7 days, Pro 90 days, Business 180 days — then automatically purged.
  • Audit logs: agent audit logs (the per-request record of monitoring-agent API activity) are retained for 30 days; account and activity audit logs (changes to monitors, alert rules, memberships and operator actions, stored with a hashed IP address and user agent) are retained for 365 days.
  • Billing records: retained for the period required by tax and accounting law (typically 7 years).

8. Your Rights

Depending on your jurisdiction (EEA, UK, California, and others), you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your data.
  • Object to or restrict certain processing.
  • Receive a copy of your data in a portable format.
  • Withdraw consent (where processing is based on consent).
  • Lodge a complaint with your local data-protection authority.

To exercise any of these rights, email [email protected]. We respond within 30 days.

9. Data Protection Officer

We are not required to appoint a Data Protection Officer under GDPR Article 37 and have not done so. Privacy questions should be directed to [email protected].

10. Security

We protect data with industry-standard controls: TLS for data in transit, encryption at rest for our managed databases, per-tenant authorization checks, rate limiting and audit logging on sensitive endpoints, hashed API keys, and truncated-hash logging of IP addresses. No system is impenetrable; report suspected vulnerabilities to [email protected] — see our security.txt for disclosure terms.

11. Children

The Service is not intended for individuals under 18, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Data Processing Addendum (DPA)

Customers acting as data controllers under the GDPR may request a Data Processing Addendum incorporating the EU Standard Contractual Clauses by emailing [email protected].

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated version with a revised Effective Date and, for material changes, notify account holders by email.

14. Controller and Contact

The data controller is Network Canaries LLC.. Privacy questions and rights requests: [email protected].