Privacy Notice
What we collect, why, who touches it, and how to make us delete it. Plain language throughout.
Effective: 13 July 2026 · Material changes will be notified 30 days in advance by email and posted here with a revised effective date.
1. Who we are
SecurityAlert.ai is operated by CIA Development ("we," "us"). We are the data controller for the personal data described in this notice. Contact for privacy matters: legal@securityalert.ai.
2. What we collect
- Account data. Name and email address, provided when you sign up. Authentication is handled by Auth0; we never see or store your password.
- Billing data. Stripe customer ID, plan, and invoice history. Stripe tokenizes payment methods; we only ever see the last 4 digits of a card.
- Configuration data. The brand domains, monitors, certificates, and findings you set up in the product. This is your data; you can export and delete it.
- Usage analytics. Aggregate page-view analytics from a self-hosted, cookieless analytics instance (Umami). No advertising trackers, no third-party analytics services.
- Server logs. Standard web-server logs (IP address, user agent, request path) retained for security and abuse prevention.
3. What we do NOT collect
- Passwords (Auth0 handles authentication end to end).
- Full payment card details (Stripe tokenizes them).
- Advertising identifiers or cross-site tracking data. We run no ad pixels.
4. Why we process it
- To provide the Service (GDPR Art. 6(1)(b), performance of a contract): running your monitors, storing findings, sending the alerts you configure.
- Billing and accounting (Art. 6(1)(b) and (c)): processing payments and keeping records the law requires.
- Security and abuse prevention (Art. 6(1)(f), legitimate interest): server logs, rate limiting, audit trails.
- Product improvement (Art. 6(1)(f)): aggregate, cookieless usage analytics.
- Transactional email (Art. 6(1)(b)): alert notifications, billing receipts, and account messages via Postmark. We do not run third-party marketing campaigns against your data.
5. Cookies and local storage
- We set no first-party advertising or tracking cookies.
- Auth0 sets cookies during sign-in to keep your session alive; see Auth0's own privacy documentation for details.
- We use browser localStorage for a signed-in session cache and UI preferences (for example, table column choices). This data stays in your browser.
- Our analytics (self-hosted Umami) is cookieless by design.
6. Who we share it with
We do not sell personal data. We share it only with the subprocessors needed to run the Service:
- Microsoft Azure: hosting and storage, US East region.
- Auth0 (Okta): authentication and identity management.
- Stripe: payment processing.
- Postmark (ActiveCampaign): transactional email delivery.
Each processes data only on our instructions. We may also disclose data where the law requires it, and we will tell you when we legally can.
7. How long we keep it
Retention periods per data category are published in full in our Data Retention Policy. The short version: you can delete your account at any time from Settings; deletion is immediate and cascades across all product data, and rotated backups age out within days. Billing records are retained as long as tax law requires.
8. Your rights
Under GDPR, CCPA, and similar laws you can:
- Access the personal data we hold about you.
- Correct inaccurate data (account details are editable in Settings).
- Delete your data (self-serve from Settings, or by request).
- Export your data in a portable format.
- Object to processing based on legitimate interest.
- Complain to your local supervisory authority.
To exercise any of these, use the self-serve controls in Settings or email legal@securityalert.ai. We respond within 30 days.
9. International transfers
Data is processed in the United States (Azure US East). For customers requiring them, a Data Processing Addendum with Standard Contractual Clauses is available on request for Business and Enterprise plans: legal@securityalert.ai.
10. Security
Our security practices, compliance status, and vulnerability disclosure process are documented on the Trust page.
11. Children
The Service is a business tool and is not directed at children under 16. We do not knowingly collect their data.
12. Contact
Privacy questions and requests: legal@securityalert.ai. Security reports: see security.txt.