Privacy Policy

How we collect, use, and protect your information at Canary.

Last updated: January 6, 2025

Information We Collect

Account Information

When you create an account, we collect your email address, name, and profile picture through Google OAuth. This information is used to identify you and provide access to your secure document vault.

Document Data

We store the documents you upload, including file names, content, and metadata such as upload dates. Documents are encrypted and stored securely in user-specific folders.

Recipient Information

We collect and store contact information for recipients you designate to receive your documents, including names and email addresses. This information is used solely for document delivery purposes.

Usage Data

We collect information about how you use our service, including login times, document access patterns, and notification interactions to improve our service and ensure security.

How We Use Your Information

Service Provision

Your information is used to provide our core services: secure document storage, automatic delivery to recipients, and notification scheduling based on your check-in preferences.

Communication

We use your email address to send you check-in notifications, service updates, security alerts, and to facilitate document delivery to your designated recipients.

Security and Fraud Prevention

We monitor usage patterns to detect and prevent unauthorized access, fraudulent activity, and to maintain the security of your documents and personal information.

Service Improvement

We analyze usage data to improve our features, user experience, and to develop new capabilities that better serve your digital legacy management needs.

Data Security and Protection

Encryption

All documents are encrypted both in transit and at rest using industry-standard encryption protocols. Your documents are stored in secure, user-specific folders that cannot be accessed by unauthorized parties.

Access Controls

Access to your data is strictly limited to authorized personnel who require it for service provision. All access is logged and monitored for security purposes.

Infrastructure Security

Our infrastructure employs multiple layers of security including firewalls, intrusion detection systems, and regular security audits to protect your data from unauthorized access.

Authentication

We use secure OAuth authentication through Google to ensure only you can access your account. We do not store your Google password or other sensitive authentication credentials.

Information Sharing and Disclosure

Recipient Delivery

We share your documents only with the recipients you explicitly designate, and only under the conditions you specify (such as failing to check in within your designated timeframe).

Legal Requirements

We may disclose your information if required by law, legal process, or to protect the rights, property, or safety of Canary, our users, or others, but only to the extent legally required.

Service Providers

We work with trusted third-party service providers for infrastructure, email delivery, and other essential services. These providers are contractually bound to protect your data and use it only for service provision.

No Commercial Use

We do not sell, rent, or trade your personal information or documents to third parties for marketing or commercial purposes. Your digital legacy remains private and secure.

Data Retention

Account Data

We retain your account information and documents for as long as your account remains active or as needed to provide our services. This ensures your digital legacy remains accessible when needed.

Delivered Documents

After documents are delivered to recipients according to your instructions, we may retain delivery logs for accountability and service improvement purposes, but the documents themselves remain in your vault.

Legal Requirements

In some cases, we may need to retain certain information for longer periods to comply with legal obligations, resolve disputes, or enforce our agreements.

Your Rights and Control

Access and Portability

You can access, download, and export your documents and data at any time through your Canary dashboard. You have full control over your digital legacy.

Correction and Updates

You can update your account information, recipient details, and notification preferences at any time through your account settings.

Deletion

You can delete your account and all associated data at any time. Upon deletion, your documents and personal information will be permanently removed from our systems within 30 days.

Data Protection Rights

If you are in the EU, you have additional rights under GDPR including the right to object to processing, request data portability, and lodge complaints with supervisory authorities.

Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at privacy@canary-app.com. We are committed to addressing your concerns and protecting your privacy.