Privacy Notice
What we collect, why, who touches it, and how to make us delete it. Plain language throughout.
Effective: 13 July 2026 · Material changes will be notified 30 days in advance by email and posted here with a revised effective date.
1. Who we are
SecurityAlert.ai is operated by CIA Development ("we," "us"). We are the data controller for the personal data described in this notice. Contact for privacy matters: legal@securityalert.ai.
2. What we collect
- Account data. Name and email address, provided when you sign up. Authentication is handled by Auth0; we never see or store your password.
- Billing data. Stripe customer ID, plan, and invoice history. Stripe tokenizes payment methods; we only ever see the last 4 digits of a card.
- Configuration data. The brand domains, monitors, certificates, and findings you set up in the product. This is your data; you can export and delete it.
- Usage analytics. Aggregate page-view analytics from a self-hosted, cookieless analytics instance (Umami). No advertising trackers, no third-party analytics services.
- Server logs. Standard web-server logs (IP address, user agent, request path) retained for security and abuse prevention.
3. What we do NOT collect
- Passwords (Auth0 handles authentication end to end).
- Full payment card details (Stripe tokenizes them).
- Advertising identifiers or cross-site tracking data. We run no ad pixels.
4. Why we process it
- To provide the Service (GDPR Art. 6(1)(b), performance of a contract): running your monitors, storing findings, sending the alerts you configure.
- Billing and accounting (Art. 6(1)(b) and (c)): processing payments and keeping records the law requires.
- Security and abuse prevention (Art. 6(1)(f), legitimate interest): server logs, rate limiting, audit trails.
- Product improvement (Art. 6(1)(f)): aggregate, cookieless usage analytics.
- Transactional email (Art. 6(1)(b)): alert notifications, billing receipts, and account messages via Postmark. We do not run third-party marketing campaigns against your data.
5. Cookies and local storage
- We set no first-party advertising or tracking cookies.
- Auth0 sets cookies during sign-in to keep your session alive; see Auth0's own privacy documentation for details.
- We use browser localStorage for a signed-in session cache and UI preferences (for example, table column choices). If you carry a domain from the public lookalike checker into signup, the normalized domain is also kept in your browser for up to 24 hours to prefill onboarding; it is not sent to analytics and is removed after successful setup or expiry.
- Our analytics (self-hosted Umami) is cookieless by design.
6. Who we share it with
We do not sell personal data. We share it only with the subprocessors needed to run the Service:
- Microsoft Azure: hosting and storage, Central US region.
- Auth0 (Okta): authentication and identity management.
- Stripe: payment processing.
- Postmark (ActiveCampaign): transactional email delivery.
Each processes data only on our instructions. We may also disclose data where the law requires it, and we will tell you when we legally can.
AI agent access you configure: if you connect an AI assistant or automation platform to your account (through an API key or the MCP endpoint), the findings and asset data it queries are delivered to that tool under your instruction, and its provider processes them under your agreement with them, not ours. Every such call is recorded in your audit log with the credential used, and revoking the credential severs access immediately.
7. How long we keep it
Retention periods per data category are published in full in our Data Retention Policy. The short version: you can delete your account at any time from Settings; deletion is immediate and cascades across all product data, while backups follow a rolling 30-day retention setting and expire during successful rotation. Billing records are retained as long as tax law requires.
8. Your rights
Under GDPR, CCPA, and similar laws you can:
- Access the personal data we hold about you.
- Correct inaccurate data (account details are editable in Settings).
- Delete your data (self-serve from Settings, or by request).
- Export your data in a portable format.
- Object to processing based on legitimate interest.
- Complain to your local supervisory authority.
To exercise any of these, use the self-serve controls in Settings or email legal@securityalert.ai. We respond within 30 days.
9. International transfers
Data is processed in the United States (Azure Central US). For customers requiring them, a Data Processing Addendum with Standard Contractual Clauses is available on request for Business and Enterprise plans: legal@securityalert.ai.
10. Security
Our security practices, compliance status, and vulnerability disclosure process are documented on the Trust page.
11. Children
The Service is a business tool and is not directed at children under 16. We do not knowingly collect their data.
12. Contact
Privacy questions and requests: legal@securityalert.ai. Security reports: see security.txt.