Last updated: September 10, 2026
1. Who we are and what this statement covers
SignalSitter is a service of Flow XO LLC, 4711 Muirfield Ct, Santa Rosa, CA, United States (“SignalSitter”, “we”, “us”). This statement explains how we handle personal data when you visit signalsitter.com, create or use a SignalSitter account, send monitoring data to the service, configure a delivery destination, pay for a plan, or contact us. For account, billing, website, security, and support data, Flow XO LLC decides why and how the data is used and acts as controller or business. For monitoring data that a customer submits about its own systems or people, the customer decides the purpose and means of processing and Flow XO LLC acts as its processor or service provider. If you are represented in monitoring data by a SignalSitter customer, direct your request to that customer first; we assist the customer with requests we are required to support.
2. Data we collect
We collect the following categories: Account and membership data: name, email address, avatar, organization, membership, role, authentication session, and provider-issued identifiers. Clerk is authoritative for names, email addresses, avatars, and sessions. SignalSitter’s control plane stores pseudonymous Clerk identifiers and roles, not members’ names or email addresses. Monitoring and service data: monitor names and keys, configuration, observation payloads and numeric measurements, incidents, incident timelines, delivery attempts, anomaly feedback, usage, and timestamps. Destination and credential data: callback URLs, encrypted or derived signing material, credential labels, public prefixes, and derived credential verifiers. Secret values are shown once where the product says they are and are not readable back from the service. Billing data: organization and plan identifiers, subscription state, and Stripe customer and subscription identifiers. Stripe, not SignalSitter, stores payment methods, invoices, and refund details. Security and operational data: request and correlation identifiers, public actor and organization identifiers, operation names, problem codes, bounded diagnostic reasons, audit records, refusal counts, and ephemeral IP rate-limit keys. We do not put authorization credentials, callback secrets, configuration headers, observation payloads, measurement values, or raw MCP inputs in structured application logs. Correspondence: the content and addressing information in messages sent to support@signalsitter.com or privacy@signalsitter.com. Public-site and device data: IP address, user agent, request and security telemetry processed by Cloudflare and Framer when they deliver the public site, and essential browser storage used for authentication, security, and appearance preferences in the application.
3. Why we use data
We use data to provide, secure, troubleshoot, and improve SignalSitter; create and authenticate accounts; enforce organization scope and plan limits; accept and retain observations; detect and record incidents; deliver customer-directed callbacks; administer subscriptions; answer support and privacy requests; prevent abuse; keep an audit trail; comply with law; and protect our customers, the public, and the service. Depending on the data and where you live, our legal basis is performance of our contract with you, our legitimate interests in operating and securing the service, compliance with law, consent where the law requires it, or the customer’s instructions where we act as processor. We do not sell personal data or use it for cross-context behavioral advertising. We do not send customer monitoring data to an analytics provider, a session recording provider, or an AI model provider.
4. Cookies and telemetry
The authenticated application uses cookies and browser storage that are necessary to authenticate users, maintain sessions, prevent abuse, and remember appearance preferences. Cloudflare and Framer process ordinary request and security telemetry to deliver the public site and application. SignalSitter does not currently use optional advertising cookies, third-party product analytics, or session recording. If that changes, we will update this statement and obtain consent where required before using non-essential cookies.
5. Retention, export, and deletion
The current Free plan retains raw observations and the related incidents, incident events, delivery attempts, and anomaly feedback for 7 days. The current Builder, Smart, and Scale plans retain those raw records for 30 days, five-minute numeric aggregates for 90 days, and hourly numeric aggregates for 365 days. Plan changes do not rewrite already-issued plan versions, and the plan shown in the product is authoritative for your organization. Configuration, destinations, credentials, and organization projections remain until they are deleted, revoked, disabled, or the organization is purged. The general control-plane audit index is retained for one year. API credential audit history currently has no age-based deletion schedule and can remain indefinitely. Operational receipts and abuse refusal samples are retained for 30 days. Cloudflare platform logs and Microsoft 365 correspondence follow the applicable provider and tenant settings; SignalSitter does not promise a fixed deletion date for those records. You can export the organization’s available data before requesting organization deletion. An organization deletion ends access, revokes credentials, disables destinations, and cancels a paid subscription immediately. Unless you choose immediate deletion, the request can be reversed for 7 days and the production stores are then purged. Immediate deletion begins that purge without the reversal window. Export is not available after the deletion request. Payload-free tombstones that prevent identifier reuse, bounded usage aggregates, and audit records may remain for security, accounting, and legal purposes. Deleting one monitor is immediate and irreversible.
6. Where data is processed
The SignalSitter control plane and paid-plan numeric aggregate store are restricted to the European Union. A monitor created with the EU jurisdiction runs and stores its observations, incidents, and configuration in the European Union. A monitor created with the unrestricted jurisdiction may run and store that data outside the European Union; unrestricted is not a promise of storage in the United States or any other country. Jurisdiction is fixed when a monitor is created. Cloudflare’s routing queue carries pseudonymous routing identifiers but no observation payload, destination URL, or secret, and Cloudflare does not offer a regional placement control for that queue or for Workers Logs. Clerk stores account identity and session data in the United States. Human correspondence is stored in the existing Flow XO LLC Microsoft 365 tenant location. Stripe and the other providers below may process data in the countries where they and their subprocessors operate. Where personal data is transferred internationally, we rely as applicable on an adequacy decision, including the EU-US Data Privacy Framework for certified US recipients, the European Commission’s Standard Contractual Clauses, the UK Addendum or data bridge, or another lawful transfer mechanism. Choosing an EU monitor does not make identity, support correspondence, routing metadata, or platform logs EU-resident.
7. Service providers and subprocessors
These are the external providers that currently process personal or customer data for SignalSitter: Provider | What it handles | Location and transfer posture Cloudflare, Inc. | Public and application traffic; Workers; EU-restricted D1 control plane and R2 aggregates; jurisdiction-selected Monitor Durable Objects; routing queue; rate limiting; platform logs | Global network. D1 and R2 are restricted to the EU; each Monitor Durable Object follows the selected jurisdiction; queue and log placement are not selectable. Cloudflare’s DPA includes international-transfer safeguards. Clerk, Inc. | Account identity, organization membership, authentication, and sessions | United States. Clerk relies on the EU-US Data Privacy Framework and contractual safeguards described in its DPA. Stripe, Inc. and its applicable affiliates | Checkout, payment methods, subscription administration, invoices, and billing-provider records | Stripe processes data internationally under its DPA and transfer mechanisms. Microsoft Corporation and its applicable affiliates | Human support and privacy correspondence in Microsoft 365 | The existing Flow XO LLC tenant location and Microsoft’s service locations, subject to Microsoft’s DPA and transfer commitments. Framer B.V. | Hosting and delivery of the public website and its ordinary request telemetry | Framer and its subprocessors may process data internationally under Framer’s DPA and Standard Contractual Clauses. GitHub, Inc. | Deployment and a restricted operator workflow carrying organization identifiers and bounded support diagnostics | GitHub’s service locations, subject to its data-protection terms and transfer mechanisms. The workflow does not expose observation payloads, measurement names or values, callback destinations, or secrets. Resend is not a current SignalSitter account-notice or incident-delivery processor. Customer-configured HTTPS callback destinations are recipients chosen by the customer, not our subprocessors. A customer may instead choose a WhooshBang destination operated by Flow XO LLC; that sends the incident data the customer directs to that separate service and any messaging providers the customer configures there.
8. Sharing and disclosure
We disclose data to the providers above to operate the service; to a destination you configure; within your organization according to membership and role; when required by law or a valid legal process; to protect rights, safety, and the service; or as part of a merger, financing, acquisition, or sale of assets with appropriate protections. We do not disclose monitoring data to support staff through the support-diagnostics interface: it exposes state, timing, counts, and public identifiers only.
9. Security
We use administrative, technical, and organizational safeguards designed for the nature of the data, including HTTPS, tenant-scoped authorization, isolated monitor authorities, derived credential verifiers, encrypted or derived secret material, one-time secret display, callback destination validation and DNS rechecking, structured log allowlists, least-privilege operator access, and audit records. No service is perfectly secure, and these controls are not a guarantee that an incident cannot occur.
10. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal data; object to or restrict processing; withdraw consent; and complain to a data-protection authority. You may also have the right to appeal our response. We may need to verify your identity and may retain information where law permits or requires it. Account holders can use product controls where available or email privacy@signalsitter.com. If a SignalSitter customer submitted data about you, contact that customer first because it controls the data; the customer can route an authorized request to us. Authorized agents may make requests where the law allows it, subject to verification.
11. Children
SignalSitter is a business service and is not directed to children. You must be at least 18 years old to create an account. We do not knowingly collect personal data directly from children through account registration.
12. Changes and contact
We may update this statement when the service or law changes. We will publish the revised statement at https://signalsitter.com/privacy with a new last updated date and provide additional notice where required. Questions and privacy requests: privacy@signalsitter.com General support: support@signalsitter.com Flow XO LLC, 4711 Muirfield Ct, Santa Rosa, CA, United States