SignalWatch

Privacy Policy

What we store and why

Last updated 18 September 2026. Short version: we keep what the product needs to work, nothing for advertising, and you can delete all of it.

What we collect

What we do not do

Processors we rely on

Retention

Snapshots are deleted after 45 days (we keep the single most recent one per monitor so diffs keep working). Monitors and their history are deleted immediately when you delete them. Accounts and everything attached are deleted when you ask us to close the account. Backups roll off within 14 days.

Your rights

You can export or delete your data, or ask what we hold, by emailing [email protected] from your account address. We answer within a few days. If you are in the UK or EU you also have the right to complain to your data protection authority.

Security

All traffic is HTTPS. Sessions use HttpOnly, Secure cookies. API keys are random 256-bit tokens you can rotate. Outbound webhooks are HMAC-signed so your receiver can verify they came from us. The monitoring worker refuses to fetch private or internal addresses.

Changes

If this policy changes materially we will email account holders. The date at the top always reflects the current version.