Identity and monitoring data
This surface can involve account profile data, protected email addresses, alert routing details, and trigger telemetry needed to monitor attacker contact.
Last updated: July 14, 2026. Data handling, retention windows, user controls, and storage transparency across the full CanaryVaults platform.
Each module handles a different shape of security data, so the privacy page mirrors that split clearly.
This surface can involve account profile data, protected email addresses, alert routing details, and trigger telemetry needed to monitor attacker contact.
This surface can involve original document text, injected document text, planted facts, and suspicious AI outputs. On-chain anchoring is not enabled on this deployment, so no blockchain transaction reference is written for a detected leak.
This surface can involve user prompts submitted for inspection, optional system prompts, detection outcomes, confidence scores, and blocked-message history tied to the account.
This surface can involve honeypot configuration, public trap hits, captured request headers, IP addresses, and submitted messages. On-chain anchoring is not enabled on this deployment, so no blockchain reference is written for a trap hit.
This surface can involve agent identifiers, action detail, outcomes, metadata supplied by the user, content hashes, and the cryptographic seal used to detect later modification. On-chain anchoring is not enabled on this deployment, so no blockchain transaction reference is written.
This is the practical summary of where the platform draws boundaries around retention, processors, and public proof.
These are the retention windows the platform actually enforces in code, not aspirational values.
Trap-hit telemetry captured from attackers (IP addresses, request headers, submitted messages) is security data about the attacking party and may be retained beyond the windows above for abuse prevention and community defense.
Export and deletion are self-service. This section describes exactly what each control does.
Data controller: the CanaryVaults service, operated via canaryvaults.com. Formal legal-entity details (registered name and address) will be published here once finalized; privacy requests sent to hello@canaryvaults.com reach the controller directly in the meantime.
A complete list of every third-party service the platform uses — including the AI inference provider that processes prompts and documents you submit for inspection — is maintained on the subprocessors page.
Update account settings, review security context, or open support from the linked trust surfaces below.