Privacy Policy

Last updated: July 2026

EOLCanary ("we", "us", "our") provides a service that tracks end-of-life dates and CVEs for software technologies and alerts users before their stack becomes outdated or vulnerable. This policy explains what data we collect, why, and how it's handled.

1. Data we collect

Account data. When you create an account, we collect your email address and, if you sign up with email/password, a securely hashed password. If you sign in with Google, we receive your name, email address and profile picture from Google. You may optionally add your first name, last name, organization and role in your profile.

Project data. The projects you create, the technologies and versions you add to them, your alert email address, and your alert threshold preferences.

Alert history. A record of which alert emails were sent, to whom, and when, so we don't send duplicate alerts.

Usage data. We use privacy-friendly analytics (Umami) and Google Analytics to understand aggregate traffic and usage patterns. We don't use this data to identify individual visitors.

2. How we use your data

  • To provide the core service: tracking your stack and sending you EOL / CVE alert emails.
  • To authenticate you and secure your account.
  • To send transactional emails (account confirmation, welcome email, password-related emails).
  • To understand how the product is used and improve it.

We do not sell your data, and we do not use it for advertising.

3. Third-party services

We rely on a small number of subprocessors to run EOLCanary:

  • Supabase — authentication and database hosting.
  • Resend — transactional and alert email delivery.
  • Netlify — application hosting.
  • Google — optional "Sign in with Google" authentication.
  • Umami / Google Analytics — aggregate, privacy-conscious usage analytics.

Each of these providers processes data only as needed to deliver their part of the service, under their own privacy and security terms.

4. Data retention

We keep your account and project data for as long as your account is active. If you delete a project, its data is removed. If you delete your account, your profile and project data are deleted; some records (such as alert history) may be retained briefly for operational and anti-abuse purposes before being purged.

5. Security

Access to your data is protected by row-level security policies at the database level, so you can only ever access your own projects and profile. Passwords are never stored in plain text.

6. Your rights

You can access, correct or delete your profile and project data at any time from your dashboard. If you're located in the EEA, UK or another jurisdiction with data protection laws, you also have the right to request a copy of your data or ask us to delete it entirely — contact us using the details below.

7. Cookies

We don't use tracking cookies or local storage for advertising. Our analytics providers may use minimal, privacy-respecting cookies or local identifiers to measure aggregate traffic.

8. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "last updated" date above.

9. Contact

Questions about this policy or your data? Reach out at contact@eolcanary.com.