Privacy notice · version 1.1
Collect the evidence needed—and nothing more.
Updated 7 September 2026. This notice explains how StackFirefly processes account and minimized WordPress reliability data during the beta.
What StackFirefly processes
Account and workspace details support authentication, authorization, service delivery, security, and communication. Monitoring data is limited to status, timing, selected headers, counts, ages, capabilities, sanitized fingerprints, operational changes, checks, incidents, and diagnosis records.
Monitoring telemetry does not intentionally include passwords, API secrets, cookies, authentication headers, arbitrary form or POST contents, order or customer records, complete response bodies, or session replay.
Why data is used
Data is used to run deterministic checks, correlate incidents, deliver alerts, provide bounded diagnosis guidance, secure accounts, support authorized requests, and verify recovery. Sanitized evidence sent for AI diagnosis cannot give a model access to a customer system or make the model authoritative for health or recovery.
Legal bases
Processing needed to create an account, pair a site, run monitoring, show incidents, deliver alerts, and provide requested support is based on performing the beta service agreement or taking requested pre-contract steps. Security, abuse prevention, service integrity, and limited operational measurement rely on the operator's legitimate interests, balanced against user rights. Legal obligations apply where records must be preserved or disclosed by law. Consent is used only where a separate optional activity legally requires it and can be withdrawn without affecting earlier lawful processing.
Service providers and international transfers
Amazon Web Services supports application hosting, databases, cache, storage, transactional email, and bounded AI processing, primarily in the Europe (Frankfurt) region where the selected service supports it. Google or Microsoft processes sign-in data only when a user chooses the corresponding OAuth option.
When performance testing is enabled, Google PageSpeed Insights receives the registered public homepage URL and loads its public resources to measure mobile performance. StackFirefly retains selected measurements and limited resource paths, not screenshots or complete page reports. No account credentials or private page access are supplied for these tests.
Providers process data under their applicable contractual and data protection terms. StackFirefly does not intentionally transfer monitoring evidence outside the EEA without reviewing and documenting an applicable transfer mechanism. The current provider list will be updated before a material new provider begins processing customer data.
Security and access
StackFirefly uses scoped workspace authorization, per-Agent signed credentials, replay protection, encryption in transit, bounded access, audit history, session controls, and authenticator-app two-factor authentication. No system is risk-free; suspected unauthorized access should be reported promptly to security@stackfirefly.com.
Retention and deletion
The current design bounds raw telemetry to 30 days, check history to 13 months, detailed incident and audit history to 24 months, and compact reliability history to five years. Workspace deletion disables service immediately and targets operational purge within 30 days, subject to documented security, dispute, and legal retention needs.
Your choices and contact
Depending on applicable law, individuals may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent where consent is the legal basis. Workspace owners can start export or deletion review from authenticated privacy controls, or contact support@stackfirefly.com. Identity may be verified before a request is fulfilled.
Individuals may also lodge a complaint with Romania's National Supervisory Authority for Personal Data Processing at dataprotection.ro. StackFirefly does not use automated decisions that produce legal or similarly significant effects.
Cookies and local storage
Essential cookies and local storage support authentication, security, CSRF protection, and saved preferences. These remain active when optional analytics is rejected. Optional first-party analytics is currently disabled. When enabled, it requires a separate opt-in through Cookie settings.
Optional analytics measures a consenting browser session’s public landing page, allowlisted campaign source and medium, campaign label, and whether that session leads to registration, verification, and site connection. Registration may link that record to your account. It does not collect browsing histories, full URLs, referrers, IP addresses, or user-agent strings in analytics records, and uses no advertising pixels or session replay. Ordinary security and hosting logs are separate from these analytics records.
Cookie settings is available throughout the site and app. Accept and reject are equally available, and rejecting does not affect the service. Your choice is stored for 180 days in this browser. Optional visit records are deleted after 90 days; withdrawing removes the current session’s visit where it can still be identified. You can request deletion of other linked records through support. Consent is the basis for this optional measurement.
