Skip to main content
CanaryVaultsCanaryVaults home
ProductsPricingBlogDocs
Start Free
Trust Center

Privacy and data handling

Last updated: July 14, 2026. Data handling, retention windows, user controls, and storage transparency across the full CanaryVaults platform.

What data each product surface may handle

Each module handles a different shape of security data, so the privacy page mirrors that split clearly.

CanaryVaults

Identity and monitoring data

This surface can involve account profile data, protected email addresses, alert routing details, and trigger telemetry needed to monitor attacker contact.

CanaryRAG

Document and leak-detection data

This surface can involve original document text, injected document text, planted facts, and suspicious AI outputs. On-chain anchoring is not enabled on this deployment, so no blockchain transaction reference is written for a detected leak.

CanaryShield

Prompt inspection and block history

This surface can involve user prompts submitted for inspection, optional system prompts, detection outcomes, confidence scores, and blocked-message history tied to the account.

CanaryHoneypot

Trap endpoint and attacker telemetry

This surface can involve honeypot configuration, public trap hits, captured request headers, IP addresses, and submitted messages. On-chain anchoring is not enabled on this deployment, so no blockchain reference is written for a trap hit.

CanaryAudit

Agent action logs and verification data

This surface can involve agent identifiers, action detail, outcomes, metadata supplied by the user, content hashes, and the cryptographic seal used to detect later modification. On-chain anchoring is not enabled on this deployment, so no blockchain transaction reference is written.

Privacy promises

What the product is trying to minimize

  • Collect only the data needed to operate monitoring, alerting, billing, and user-facing controls.
  • Keep product-surface descriptions clear so users understand whether they are submitting inbox data, documents, prompts, trap telemetry, or audit records.
  • Support export and deletion workflows through account controls where available.
  • Use linked trust pages so security, privacy, and support expectations are easier to review together.
User controls

How users keep control of their data

  • Review and update account profile and notification settings.
  • Export supported account data and audit records through the settings or product workflows where available.
  • Delete the account through supported privacy controls.
  • Raise privacy or handling concerns through the support and security paths.

Storage transparency

This is the practical summary of where the platform draws boundaries around retention, processors, and public proof.

  • Transport data is encrypted in transit.
  • Platform data is stored with controlled access and operational logging.
  • Payment data is handled by processors; full card details are not stored in CanaryVaults.
  • Audit records are sealed with an HMAC key held in the application environment and never stored in the database, so a record altered at the database level fails verification.
  • On-chain proof anchoring is not enabled on this deployment. No content hash, transaction, or other data is written to any public blockchain. If that changes, anything published on-chain would be public and permanent, and this page will name the network first.

How long data is kept

These are the retention windows the platform actually enforces in code, not aspirational values.

  • Threat events: Kept for the account retention window (default 365 days). A monthly cleanup job deletes events older than that window on the 1st of each month at 02:00 UTC.
  • Community shield alerts: Shared malicious-IP alerts expire 7 days after they are created.
  • Data export links: Emailed export download links are single-use and expire after 24 hours.
  • Backend operational logs: Rotated with a 30-day retention.
  • Session cookies: Authentication cookies live at most 7 days and are HttpOnly. See the cookie policy for details.
  • Account, canaries, monitored emails, billing records: Kept until you delete your account.
  • Public blockchain references: None exist. On-chain anchoring is not enabled on this deployment, so nothing has been published to a public blockchain and there is no on-chain data to retain or delete. If anchoring is enabled in future, on-chain content hashes are public and permanent by design and cannot be deleted.

Trap-hit telemetry captured from attackers (IP addresses, request headers, submitted messages) is security data about the attacking party and may be retained beyond the windows above for abuse prevention and community defense.

Your data rights (GDPR, UK GDPR, CCPA)

Export and deletion are self-service. This section describes exactly what each control does.

  • Export: download a JSON export of your data from account settings at any time. It includes your account profile, canaries, threat events, and subscription and billing event history.
  • Deletion: delete your account from settings. Deletion is immediate and irreversible, cancels any active PayPal subscription, removes your database records and authentication account, and sends a confirmation email.
  • Both actions are self-service and complete without a support ticket. If you send a request by email instead, we respond within 30 days, consistent with GDPR and UK GDPR response requirements.
  • Email requests go to hello@canaryvaults.com, which reaches the data controller directly. Security vulnerabilities go to security@canaryvaults.com instead — that mailbox is for disclosure and carries its own response targets.

Data controller: the CanaryVaults service, operated via canaryvaults.com. Formal legal-entity details (registered name and address) will be published here once finalized; privacy requests sent to hello@canaryvaults.com reach the controller directly in the meantime.

Third-party services

A complete list of every third-party service the platform uses — including the AI inference provider that processes prompts and documents you submit for inspection — is maintained on the subprocessors page.

View the subprocessor list

Control actions

Update account settings, review security context, or open support from the linked trust surfaces below.

Open settingsOpen CanaryShieldOpen CanaryAuditOpen security centerReview support paths
CanaryVaults

Deception-based AI security. Decoys, trap facts, honeypots, prompt defense, and tamper-evident audit trails — one workspace.

Plant your first canary

PRODUCT

ProductsCanaryAgentDashboardPricingReferralGet started

RESOURCES

DocumentationQuickstartShieldEvidence formatAPIBlog

COMPANY

AboutSecurityReport a vulnerabilityContact

TRUST

Trust centerVerify evidenceStatusChangelogIncidentsDPA

COMPARE

vs Thinkst Canaryvs CanaryTokensFor SaaS teams

LEGAL

TermsPrivacyCookiesSubprocessorsSupport
deception-based AI security© CanaryVaults · canaryvaults.comsha-256 sealed · tamper-evident

CANARYVAULTS