Privacy Policy
Effective: June 13, 2026
1. What We Collect
When you sign up for and use NightWatch AI, we collect the following:
- Account information — your email address, name (if provided), and account credentials.
- Competitor URLs — the website addresses you choose to monitor.
- Scraped page content — HTML snapshots of monitored pages, stored to detect changes between runs.
- Detected changes — records of what content changed between snapshots.
- AI-generated briefings — text generated from detected changes and delivered to your email.
- Billing information — handled by Stripe; we do not store payment card numbers, CVV codes, or bank account details.
- Usage data — log events (page views, button clicks, API calls) used to improve the service and for analytics. This is aggregated and de-identified where possible.
2. How We Use Your Data
We use your data exclusively to:
- Run daily automated scrapes of your competitor URLs.
- Detect content changes between scrapes and store those change records.
- Generate and deliver AI briefings by email when changes are detected.
- Send service-related emails: briefings, account notices, billing receipts, and security notifications.
- Respond to your support requests.
- Maintain and secure your account.
- Aggregate usage data for product improvement (this data is not linked to individual users without their consent).
We do not sell your personal information. We do not use your data to train AI models.
3. Data Sharing & Third-Party Services
We share data with the following third-party service providers, each acting as a data processor under your instructions:
- Postmark (Authenticated Inc.) — transactional email delivery. Your email address is processed by Postmark solely to deliver NightWatch AI briefings and transactional messages. Postmark does not retain your data beyond what is needed to complete delivery and does not use it for its own purposes.
- OpenAI (OpenAI, L.L.C.) — we send detected changes and page snapshots to OpenAI's API to generate briefing text. OpenAI processes this data under its own privacy policy. We do not use OpenAI to profile or identify individual users.
- Stripe, Inc. — payment processing. Stripe collects and processes payment data directly under its own privacy policy; we never see your card number or CVV.
- Neon (Neon Database Inc.) — our primary database provider. User data and service data are stored on Neon-managed PostgreSQL infrastructure.
We do not transfer your data to any country outside the United States except where Postmark or OpenAI require processing in their US-based or EU-based data centers.
4. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal basis for processing your personal data is:
- Contract performance (Art. 6(1)(b)) — processing your account data and competitor URLs is necessary to perform the service contract between you and NightWatch AI.
- Legitimate interests (Art. 6(1)(f)) — we use aggregated, non-identifiable analytics data to improve our service, which constitutes a legitimate interest that is not overridden by your privacy rights.
- Consent (Art. 6(1)(a)) — for marketing emails, where required by applicable law, we obtain your explicit consent before sending non-service-related communications.
Where we rely on legitimate interests, you have the right to object to such processing at any time by contacting support@nightwatch-ai.com.
5. Your GDPR Rights (EEA/UK)
If you are in the EEA, United Kingdom, or Switzerland, you have the following rights under the GDPR or UK GDPR:
- Access (Art. 15) — request a copy of the personal data we hold about you.
- Rectification (Art. 16) — request correction of inaccurate personal data.
- Erasure (Art. 17) — request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
- Restriction (Art. 18) — request that we restrict processing in certain circumstances.
- Data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format.
- Objection (Art. 21) — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw that consent at any time.
To exercise any of these rights, email support@nightwatch-ai.com with your request. We will respond within 30 days.
If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority (e.g., the Information Commissioner's Office in the UK, or your national data protection authority in the EEA).
6. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), grants you the following rights regarding your personal information:
- Right to know — request disclosure of: the categories and specific pieces of personal information we collect, the categories of sources, business purposes, and third parties with whom we share it, and whether we sell or share your data (we do not sell your personal information).
- Right to delete — request deletion of your personal information, subject to certain exceptions.
- Right to correct — request correction of inaccurate personal information.
- Right to opt-out of sale/sharing — we do not sell or share personal information for cross-context behavioral advertising.
- Right to limit use of sensitive personal information — we do not collect sensitive personal information as defined under CPRA.
- Non-discrimination — we will not discriminate against you for exercising your privacy rights.
To submit a request, email support@nightwatch-ai.com with "California Privacy Request" in the subject line. We will respond within 45 days. You may also designate an authorized agent to exercise these rights on your behalf by providing written authorization and proof of agency status.
7. Data Retention
We retain your data for the following periods:
- Competitor URLs and scraped snapshots: 90 days after you remove the competitor or cancel your subscription.
- Detected changes and briefing history: 12 months from the date of generation.
- Account data (email, billing): 5 years after account closure for legal and tax compliance.
- Analytics events: 13 months.
After these periods, data is permanently deleted or anonymized.
8. Cookies & Analytics
We use first-party session and analytics cookies to distinguish unique visitors and track landing-page conversion funnels. Specifically:
- A session cookie to maintain login state (expires when you close your browser).
- An analytics cookie to track unique visitors and conversion events (stored in our own database, not a third-party analytics platform).
We do not use third-party tracking cookies, advertising cookies, or cross-site tracking. No data is shared with advertising platforms.
9. Data Security
We protect your data through:
- HTTPS encryption for all data in transit.
- Environment-variable secrets management — database credentials and API keys are not committed to the repository.
- Access controls limiting internal access to production systems.
- Regular review of third-party service access permissions.
No method of internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security, but we take commercially reasonable measures to protect your data.
10. International Data Transfers
Your data is primarily stored and processed in the United States. Where data is transferred to Postmark or OpenAI for service delivery, such transfers may involve data processing in the US or EU. We rely on standard contractual clauses or equivalent legal mechanisms where required by applicable law to ensure adequate protection for such transfers.
11. Children's Privacy
NightWatch AI is not intended for users under 18. We do not knowingly collect personal data from minors. If we become aware that data has been collected from a minor without verified parental consent, we will delete it promptly.
12. Do Not Track
Our service does not currently respond to Do Not Track browser signals. We use only first-party analytics cookies, which are not affected by Do Not Track in the way that third-party advertising trackers are.
13. Changes to This Policy
We may update this privacy policy from time to time. The effective date at the top of the page reflects the most recent update. For material changes that expand our data collection or sharing practices, we will notify you by email at least 14 days before the change takes effect. Continued use of the service after a policy change constitutes acceptance of the new terms.
14. Contact & Data Officer
Questions about this policy or requests to exercise your privacy rights? Email support@nightwatch-ai.com. We will respond within 30 days (45 days for California requests).