1. Who we are
OwlSonar is a competitor-tracking service operated from Finland, within the European Union. The operator of OwlSonar is the data controller for personal data processed through owlsonar.com. For anything in this policy — questions, requests, complaints — contact us at lari@increaseai.ai.
2. What we process
- Account data — your name, email address and password. Passwords are stored only as salted hashes (scrypt), never in plain text.
- Workspace configuration — your workspace name, the competitors and public URLs you ask us to track, notification settings (Slack webhook URLs, alert email addresses, webhook endpoints) and the API keys you create.
- Snapshots of public web pages — structured snapshots and diffs of the public competitor pages you track. This is content its publishers made public; it may incidentally include personal data they chose to publish, such as names on a team page.
- Billing data — payments are handled by Stripe. Your card details never touch our servers; we store your subscription status and a Stripe customer reference.
- Technical logs — standard server logs (IP address, browser type, timestamps) for security and operations, and an audit log of the AI requests used to summarise detected changes. Those AI requests contain scraped public page content — never your password or payment details.
3. Why we process it
We process personal data on the legal bases the GDPR provides:
- Performing our contract with you — running your account, sweeping the pages you configured, delivering alerts, and billing your subscription.
- Legitimate interests — keeping the service secure, preventing abuse, and improving how detection works.
- Legal obligations — bookkeeping and tax records we are required to keep.
- Consent — anything optional we explicitly ask you about. You can withdraw consent at any time.
4. Cookies
One cookie: a session cookie that keeps you signed in. No advertising trackers, no third-party analytics cookies, no cross-site anything.
5. Subprocessors
We use a small set of service providers to run OwlSonar. Each processes data only on our instructions:
- Stripe — payment processing and subscription billing.
- Resend — transactional email (alerts, receipts, account messages).
- Railway — application hosting and databases, hosted within the EU/EEA where available.
- Firecrawl — fetching and rendering the public web pages you track.
- DataForSEO — search-engine result data used in discovery features.
- OpenRouter — AI models that summarise and severity-score detected changes.
6. Where your data lives
We host within the EU/EEA where available. Some subprocessors may process data outside the EU/EEA; where they do, transfers rely on the European Commission’s Standard Contractual Clauses or an adequacy decision such as the EU–US Data Privacy Framework.
7. How long we keep it
Change history and snapshots are retained according to your plan’s history limit — from 30 days to unlimited. Account data is kept while your account is active. After cancellation your data stays exportable via the API for 30 days, then it is deleted from our active systems; backup copies expire on their normal rotation shortly after. You can request deletion of your account and its data at any time.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you,
- have inaccurate data corrected,
- have your data erased (“right to be forgotten”),
- restrict or object to processing,
- receive your data in a portable format,
- lodge a complaint with a supervisory authority — in Finland, the Office of the Data Protection Ombudsman (tietosuoja.fi).
9. Security
Traffic is encrypted in transit (TLS). Passwords are hashed with scrypt. Workspaces are isolated per organisation, and API keys are scoped to your organisation and revocable at any time. We do not sell personal data — to anyone, for anything.
10. Changes to this policy
If we change this policy we will update this page and its effective date, and email you about material changes. Questions? lari@increaseai.ai.