Skip to content
watchdogβOpen dashboard

Field guide

How Watchdog handles your data.

The account information and agent telemetry Watchdog collects, its service providers, retention and deletion requests.

Code and examples reviewed

Effective September 5, 2026. Watchdog Limited operates Watchdog and is the contact for this policy: contact@withwatchdog.com.

What we collect and why

To provide accounts, we store your name, email address, optional profile image, password hash or Google sign-in identity, and session records including IP address and browser information. Passwords are hashed. OAuth tokens and queued account emails are encrypted by the application.

To monitor jobs, we store the names and identifiers you choose, framework and environment, schedules, limits, run/event IDs and timestamps, lifecycle status, progress messages and explicit metadata. Optional signals include tool names, status, duration and argument fingerprints; model names, token counts and reported costs; and named outcomes. We store incidents, evidence, alert destinations, integration credentials and delivery attempts needed to operate your checks.

To manage subscriptions, we store Stripe customer/subscription references, status, billing periods and aggregate telemetry usage. Stripe hosts payment entry and stores payment-method details; Watchdog does not receive your full card number.

Send monitoring signals, not customer content

Do not send secrets, access tokens, passwords, raw prompts, raw model outputs, tool arguments/results, customer documents or sensitive personal information. This applies to names, progress messages, labels and metadata as well as payload fields.

The SDK fingerprints tool arguments locally and removes some sensitive field names. The server also filters known sensitive names. These filters are not a content scanner or a guarantee of anonymization: text under other names is still transmitted. You decide what your instrumentation reports.

Providers and disclosure

Cloudflare hosts the application and database. Resend sends account verification and password-reset mail. Google is used if you choose Google sign-in. Stripe receives account and billing details needed for checkout and subscription management. Your configured Slack, PagerDuty, email and webhook destinations receive incident information when enabled. Support messages go to the operator’s support inbox and email providers.

These providers process information needed to deliver their services; their own policies also apply. This release does not provide a contractual data-residency choice or claim a compliance certification. We may disclose information when required by law or necessary to address abuse or protect the service.

Cookies and service diagnostics

Sign-in uses essential session and OAuth cookies. Account pages and APIs use private, no-store caching rules. Public acquisition logs record a page path and broad referral category, without a visitor identifier or raw referral/query string in the application log. This release does not include an advertising tracker. Hosting providers and security diagnostics may process request metadata, so this does not mean that IP addresses are never processed.

Retention

Developer keeps settled run history for 7 days; Pro keeps it for 30 days, measured from the latest received event. Active runs, unresolved incidents and outstanding deliveries can stay longer so operational work is not lost. Cleanup runs in batches and can lag. Compact expired-run identifiers and aggregate usage counts remain to prevent history recreation and quota resets.

Account, job, integration settings, billing and support records are separate from run-history cleanup. They are retained to operate the account and handle support, billing, security or legal obligations. There is no automatic account-deletion timer. Backups and records held by providers may follow separate retention processes; deleting an account does not promise immediate erasure of every backup or legally required billing record.

Access, correction and deletion requests

Contact contact@withwatchdog.com from your registered email to request access, correction or deletion. We verify ownership, review the request and explain any records that must remain. Do not include your password or keys. Account deletion is a support process; subscription cancellation is available separately in Account & billing.

Policy changes

We publish changes here with an updated effective date. If we make a material change to how information is used, we will provide appropriate notice and obtain consent where required.