Skip to content

What we collect, and what we do not

We collect an email address so we can send you a sign-in code and the alerts you asked for, and almost nothing else. There is no tracking pixel in our email, no advertising network, and we never see your card details.

Last updated

What we store

Every piece of personal data we hold, why, and for how long.
WhatWhyHow long
Your email addressTo send sign-in codes and the alerts you asked for. It is your account identifier.Until you ask us to delete the account.
A hash of your session tokenTo recognise your browser as signed in. We store the hash, never the token.30 days, then deleted.
A hash of your IP addressTo spot a session on a device you do not recognise. Hashed, never stored raw.With the session, so 30 days.
Your browser's user-agent stringSo the account page can say "Chrome on macOS" about a session you might not recognise.With the session.
The product codes you watchTo know what to check and what to write to you about.Until you remove them.
A hash of each sign-in codeTo check the code you type. Peppered, so a leak of the table alone does not reveal codes.10 minutes live; the row is deleted after 7 days.
Delivery outcomes from our email providerSo a hard bounce stops us emailing a dead address, which protects delivery for everyone else.Kept as a record while the account exists.
Which alerts we have sent youSo a re-run of the nightly sender cannot email you the same thing twice.Kept as a record while the account exists.

What we deliberately do not store

  • Card details. Paddle is our Merchant of Record: they take the payment and we never see, hold or transmit a card number.
  • A password. There is nothing to breach, because there is nothing to steal.
  • Your raw IP address. Only a salted hash, because the only question we ever ask of an address is "the same as before?", which a hash answers.
  • Anything linking a search to a person. We log what codes are searched for, because it tells us which pages to build — that log has no user id column, by design, and never will.
  • A tracking pixel. Our emails contain no images at all, so nothing reports back when you open one. We know whether the provider delivered it and nothing more.

Cookies

Two, both strictly necessary, neither used for analytics or advertising. Under the ePrivacy Directive strictly necessary cookies do not require consent, which is why this site has no cookie banner: there is nothing to consent to.

Every cookie this site and the app set.
NamePurposeLifetime
ds_sessionKeeps you signed in. HttpOnly, so no script can read it.30 days
ds_csrfProves a form was submitted from our own page, not another site's.24 hours

Who else processes your data

As few parties as we can manage. Each one is here because the product cannot work without it.

  • Paddle — payments, as Merchant of Record. They receive your email and billing details directly; we receive a subscription status and a customer identifier.
  • Resend — email delivery. They receive the recipient address and the message.
  • Our hosting provider — runs the servers and the database, inside the EU.

Your rights

Email hello@devicesignal.com and we will act on any of these. We will not ask you to fill in a form or prove a legal basis for asking.

Under the UK GDPR and EU GDPR you have the right to access what we hold about you, to have it corrected, to have it deleted, to receive it in a portable form, and to object to processing. Deleting your account removes your email address, your sessions, your watch list and your send history. Anonymised search counts have no identifier and cannot be traced back to you, so they remain.

We do not sell personal data, and we do not share it for advertising. There is no automated decision-making that affects you.

Where the data lives

Our servers and database are in the EU. Paddle and Resend are US companies and transfer data under their own standard contractual clauses; using them means your email address is processed in the US as well as the EU.

Changes, and how you will know

The date at the top of this page changes when the text does. If a change materially affects what we do with your data, we will email you rather than quietly updating a page and hoping you re-read it.