Privacy Policy
Last updated: May 1, 2026
This Privacy Policy explains what personal information Printique Studios Limited Company, a company registered in Ghana, doing business as "Signalog" ("we", "us", or "our"), collects through the Signalog platform at signalog.dev (the "Service"), how we use and share it, and the rights you have over it. Read it together with our Terms of Service.
For most personal data we process, we act as the data controller. When we process Customer Data on your behalf as part of operating the Service for a paying customer (e.g., monitor configurations, status page content), we act as a data processor and a Data Processing Agreement is available on request.
1. What we collect
From you, directly
- Account information: name, email address, password (stored as a bcrypt hash — we never see the plaintext), team membership, role.
- Profile and paging preferences: phone number (only if you opt into SMS or voice paging), notification settings.
- Billing details: name, billing address, and tax ID where applicable. Payment card details are entered directly with our Payment Processor and we don't store card numbers ourselves.
- Communications: messages you send to support, feedback, and bug reports.
Generated through use of the Service
- Customer Data: monitor configurations, URLs and endpoints, status page content, incident records, postmortems, changelog entries, integration credentials (encrypted at rest).
- Monitoring telemetry: the results of probes you've configured — response times, status codes, regions that ran the check, errors observed.
- AI feature inputs: when you use AI assistance (postmortem drafts, translations, runbook suggestions, etc.), the prompt context relevant to that action — see subprocessors below.
- Usage data: log entries, API call records, IP addresses, browser type, page paths, performance metrics. We use these for security, debugging, and capacity planning.
2. How we use it
We use the information we collect to:
- Operate, maintain, secure, and improve the Service.
- Provide customer support and respond to questions or complaints.
- Process subscription payments and credit purchases, send invoices and receipts.
- Send transactional emails: incident pages, monitor status changes, account notifications, billing receipts, security alerts. You cannot opt out of transactional emails while your account is active.
- Send product updates and onboarding emails. You can opt out of these from your profile settings or via the unsubscribe link in any such email.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations and respond to lawful requests from authorities.
Lawful bases (GDPR / UK GDPR). Where the GDPR applies, we process personal data on the bases of: (a) contractual necessity (to provide the Service you've subscribed to); (b) legitimate interests (security, fraud prevention, product improvement); (c) consent (where required, e.g., for non-essential cookies or marketing emails); and (d) legal obligation (tax, accounting, lawful requests).
3. Subprocessors
We rely on a small set of trusted vendors to operate the Service. We've reviewed each one's security and privacy posture; each is contractually obligated to handle data in line with applicable laws.
| Subprocessor | Purpose | Region |
|---|---|---|
| Google Cloud Platform | Compute, database, storage, CDN | EU and US regions |
| Paddle | Payment processing, tax compliance, billing receipts (Merchant of Record) | UK / US |
| Resend | Transactional email delivery | US |
| Twilio | SMS and voice paging (only when you opt in) | US (with global delivery) |
| Google (Gemini API) | AI assistance — postmortem drafts, translations, runbook suggestions, etc. | US |
| Anthropic (Claude API) | AI assistance, fallback / specialised models | US |
| Cloudflare | DDoS protection, custom domain certificate issuance | Global edge |
| GitHub | OAuth sign-in (only if you choose to sign in with GitHub) | US |
| Slack | Slack workspace integration (only if you connect Slack) | US |
| Discord | Discord webhook delivery (only if you configure a Discord channel) | US |
| PagerDuty / Opsgenie | Optional alert delivery (only if you configure them) | US |
AI subprocessors do not train their models on your inputs, per their commercial API terms. We send only the context necessary for the requested action; we don't store AI prompt content beyond what's required for the immediate response.
We will update this list before adding a new subprocessor and provide at least 30 days' notice to active customers for any change that affects how Customer Data is processed.
4. International transfers
We are based in Ghana and our subprocessors are located primarily in the United States and the European Union. Personal data may be transferred to and processed in countries outside your region. Where data leaves the European Economic Area or the United Kingdom, we rely on appropriate safeguards (Standard Contractual Clauses or equivalent) to protect it. A copy is available on request.
5. Data retention
- Account data: retained while your account is active.
- Customer Data and monitoring telemetry: retained according to your plan — 30 days on Free, 90 days on Starter, 365 days on Pro, 730 days on Business. We may retain aggregated, anonymised statistics indefinitely.
- Billing records: retained for 7 years to comply with Ghanaian tax and accounting obligations, regardless of account closure.
- Logs and security telemetry: 90 days, longer where required for an active investigation.
- Backup copies: deleted within 30 days of removal from active systems.
On account closure, we delete personal data that isn't subject to a legal-hold or accounting obligation within 90 days. You can request earlier deletion via support.
6. Your rights
Depending on where you live, you may have some or all of the following rights over your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete your data, subject to legal exceptions.
- Portability — receive a machine-readable export of data you provided.
- Restriction — ask us to limit processing in certain circumstances.
- Objection — object to processing based on legitimate interests, including for direct marketing.
- Withdraw consent — where processing is based on consent, withdraw at any time without affecting prior lawful processing.
- Lodge a complaint — with your local data protection authority. Ghanaian residents may complain to the Data Protection Commission of Ghana.
To exercise any right, email us at privacy@signalog.dev. We'll verify your identity (so we don't disclose data to the wrong person) and respond within 30 days. If we need more time for a complex request, we'll let you know.
California (CCPA): if you're a California resident, you have rights to know what personal information we collect, sell, or share; to delete it; to correct it; and to opt out of the "sale" or "sharing" of personal information. We don't sell personal information for money, and don't share it for cross-context behavioural advertising.
7. Security
We use industry-standard safeguards: TLS 1.2+ in transit, AES-256 encryption at rest in our cloud database, role-based access controls, audited employee access, secret rotation, and infrastructure hardening. Passwords are stored as bcrypt hashes. Sensitive integration credentials (Slack tokens, Twilio keys) are encrypted at the application layer.
No system is 100% secure. If we discover a breach affecting your personal data, we'll notify you and the relevant authorities without undue delay, as required by applicable law.
8. Cookies and similar technologies
- Essential cookies: required for authentication and session management. Disabling them prevents the Service from working.
- Preference cookies: remember your settings (theme, current team).
- Status page authentication cookies: when a status page is password-protected, we set a scoped cookie after successful password entry so you don't have to re-enter on every page view.
- Analytics: aggregated, privacy-respecting analytics about how the Service is used. We don't use third-party advertising trackers.
You can control cookies through your browser settings. Disabling essential cookies will sign you out and prevent further use of authenticated features.
9. Children
The Service is not directed to children under 18. We do not knowingly collect personal data from children under 18. If you believe a child has provided us with personal data, contact us at privacy@signalog.dev and we'll delete it.
10. Changes
We'll update this Privacy Policy from time to time. Material changes will be announced by email to active users at least 30 days before they take effect; the "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the Service after the effective date is your acceptance of the updated policy.
11. Contact
For privacy questions, requests, or complaints:
Privacy: privacy@signalog.dev
General support: support@signalog.dev