Effective Date: May 5, 2026
This Privacy Policy explains how Network Canaries LLC. ("we", "us"), operating the Network Canaries service at https://networkcare.io, collects, uses, and shares personal data when you use the Service. It applies to all visitors, waitlist subscribers, and customers.
We collect and process the following categories of data:
We use the data above to:
We do not sell your personal data. We do not use your data to train machine-learning models. We do not run advertising on the Service. We do not perform automated decision-making — including profiling — that produces legal or similarly significant effects concerning you.
Where the GDPR or UK GDPR applies, we rely on the following legal bases: performance of a contract (operating the Service you signed up for), legitimate interests (security, fraud prevention, product improvement), consent (where required for optional communications), and legal obligation (tax, accounting, lawful requests).
We use the following third-party service providers ("subprocessors") to operate the Service. Each is bound by a data-processing agreement and processes data only on our instructions.
| Subprocessor | Purpose | Data location |
|---|---|---|
| Stripe | Payments and subscription billing | United States, EEA |
| Resend | Transactional email delivery | United States |
| Google (OAuth) | "Sign in with Google" authentication | United States |
| DigitalOcean | Application hosting and managed databases | United States |
| Sentry | Error monitoring and aggregated diagnostics | United States |
| Cloudflare | Bot mitigation (Turnstile) on signup; static asset CDN (cdnjs) | Global edge; United States |
| jsDelivr (Fastly) | JavaScript / CSS asset delivery (CDN) | Global edge |
| Automattic (Gravatar) | Default avatar lookup keyed on a hash of your email | United States |
We will update this list when we add or change subprocessors. Material additions will be announced by email to active customers.
We set the following cookies. All are strictly necessary to operate the Service and are exempt from consent under the GDPR ePrivacy Directive Article 5(3).
We do not currently use any advertising, analytics, or cross-site tracking cookies.
Our infrastructure and several of our subprocessors are located in the United States. Where we transfer personal data of EEA, UK, or Swiss users to the United States, we rely on the European Commission's Standard Contractual Clauses (SCCs) or equivalent safeguards offered by each subprocessor.
We retain personal data only as long as needed for the purposes listed above. Specific retention windows:
Depending on your jurisdiction (EEA, UK, California, and others), you may have the right to:
To exercise any of these rights, email [email protected]. We respond within 30 days.
We are not required to appoint a Data Protection Officer under GDPR Article 37 and have not done so. Privacy questions should be directed to [email protected].
We protect data with industry-standard controls: TLS for data in transit, encryption at rest for our managed databases, per-tenant authorization checks, rate limiting and audit logging on sensitive endpoints, hashed API keys, and truncated-hash logging of IP addresses. No system is impenetrable; report suspected vulnerabilities to [email protected] — see our security.txt for disclosure terms.
The Service is not intended for individuals under 18, and we do not knowingly collect data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
Customers acting as data controllers under the GDPR may request a Data Processing Addendum incorporating the EU Standard Contractual Clauses by emailing [email protected].
We may update this Privacy Policy from time to time. We will post the updated version with a revised Effective Date and, for material changes, notify account holders by email.
The data controller is Network Canaries LLC.. Privacy questions and rights requests: [email protected].