Skip to content

Privacy Policy

Effective: 2026-09-02

Who we are

Network Care LLC, a New Jersey limited liability company (“Network Care,” “we,” “us,” or “our”), operates Security Canaries. We are responsible for the personal information described in this policy.

Scope

This policy applies to the Security Canaries website, accounts, monitoring service, support, and related communications. It does not govern third-party sites or services that publish their own privacy notices. Read it together with our Terms of Service. The English-language version controls if a translation conflicts with it.

Information we collect

Account information. Name, email address, password hash, authentication providers, account settings, team membership and roles, and records of the Terms versions you accept.

Monitored-domain information. Domain names you submit, ownership-verification records, public DNS and web responses observed by our checks, derived findings, alerts, baselines, history, and your acknowledgments or notes.

Billing and communications. Subscription and transaction references supplied by our payment provider, plus messages and support or privacy requests you send us. We do not receive full card numbers from our payment provider.

Technical information. IP address, request and security logs, timestamps, device and browser information, session identifiers, service usage, diagnostic events, and any profile image you upload.

How we collect information

We collect information directly from you, from members of your teams, automatically when you use the Service, from the public endpoints of domains you authorize us to monitor, and from providers you choose to connect, such as Google sign-in or a payment provider.

How we use information

We use information to provide and bill for the Service; verify domain authorization; run checks and deliver alerts; administer accounts and teams; respond to requests; prevent abuse; protect customers and the Service; diagnose failures; comply with law; enforce our terms; and improve the Service. We may create aggregate, anonymized statistics that do not identify a customer, organization, or individual domain. We do not sell personal information, and we do not publish or sell per-domain results.

Legal bases

Where applicable law requires a legal basis, we process information to perform our contract with you; for legitimate interests such as operating, securing, and improving the Service; to comply with legal obligations; and with consent where consent is required. You may withdraw consent for future processing, but withdrawal does not make earlier processing unlawful.

Cookies and local storage

We use essential cookies for authentication, session security, cross-site-request-forgery protection, and preferences. Your browser’s local storage may remember display choices such as light or dark theme. Google Analytics is disabled for launch. We will not enable it without a separate consent and legal design appropriate to the locations in which the Service operates.

Service providers

We use DigitalOcean for infrastructure and PostgreSQL and Redis for application data and queues. Resend delivers outbound email. When configured or enabled for your account, providers may include Stripe and dj-stripe for billing, Cloudflare Turnstile for bot protection, Sentry for error reporting, Google for sign-in, and S3-compatible storage for profile media. Google Analytics may be supported when configured, but it is disabled for launch. Providers process information for us under their own contractual and security obligations and may process data in countries where they operate.

International processing

We and our providers may process information in the United States and other countries. Where required, we use contractual or other recognized safeguards for transfers across borders. Privacy protections may differ from those in your home jurisdiction.

Retention

We keep account and service information while needed to provide the Service and for legitimate business, security, dispute, and legal purposes. Monitoring history and audit records are retained according to product limits and operational retention schedules. Closed operational records and backups expire on rotating schedules; deletion from backups occurs as those backups age out. We may retain de-identified information that can no longer reasonably identify you.

Security

We use administrative, technical, and organizational safeguards designed for the nature of the information we process, including access controls, encryption in transit, credential hashing, service monitoring, and backups. No system is completely secure, so we cannot guarantee absolute security.

Your choices and rights

You can update account details and team access in the Service and may delete your account when its team ownership safeguards allow. Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to appeal or complain to a regulator. To make a request, email privacy@example.invalid. We may need to verify your identity and may retain a minimal record of the request and response.

Deletion limitations

Deleting your account removes account-owned data and memberships, but does not delete a shared team or its monitored domains when another administrator remains. Some audit and security records retain the event while removing the user reference. We may retain information required for legal claims, fraud prevention, payment records, or other legal obligations, and residual copies remain in backups until their ordinary rotation. A sole team administrator must promote another administrator or delete the team before deleting the account.

Children

The Service is for business and professional use and is not directed to anyone under 18. We do not knowingly collect personal information from children. Contact us if you believe a child provided information to the Service.

Changes

We may update this policy as our practices or legal obligations change. We will post the new effective date and provide additional notice when a material change requires it.

Contact

Send privacy questions or requests to privacy@example.invalid. The operator is Network Care LLC, New Jersey, United States.