TremorWatch.AITremorWatch.AI

Privacy Policy

Last updated: 30 August 2026

1. Who we are

TremorWatch.AI is operated by RANA Technologies Limited (company no. 08433262), England & Wales, which is the data controller for the personal data described in Section 2.

2. What we collect and why

  • Account data — your name, email address, and Entra External ID identifier, to authenticate you and operate your workspace.
  • Workspace configuration — Monitor definitions, alert channel configuration (including webhook URLs/routing keys you provide), role assignments, and API keys you create.
  • Monitor check results — a hash of each polled endpoint's response schema, and (separately) a snapshot of the raw response body, stored in Azure Blob Storage and deleted automatically 90 days after creation.
  • Push notification subscriptions — the Web Push endpoint and keys for devices you register, only if you opt in.
  • Audit log — a record of sensitive actions taken in your workspace (who did what, when), retained for the life of the account for security and accountability purposes.
  • Billing data — handled by Stripe (see Section 4); we store your plan tier and usage counters, not your payment card details.

3. About the raw response snapshots

If the API or MCP server you configure a Monitor against returns data about identifiable individuals — your own customers, for example — that data may be captured in the raw response snapshot described above. In that scenario, RANA Technologies acts as a data processor on your behalf as data controller for that second-order personal data, under UK GDPR. You are responsible for having a lawful basis to have that data processed this way, and for configuring Monitors accordingly. A Data Processing Agreement is available on request for customers who require one.

4. Third parties we use

  • Microsoft Azure — hosting, database, storage, and infrastructure (UK South region for primary data).
  • Microsoft Entra External ID — authentication.
  • Anthropic (Claude) — AI classification of detected schema changes. The change diff (not raw response bodies) is sent for classification.
  • Stripe — payment processing and subscription billing.
  • Azure Communication Services — transactional email (verification links, alert emails).

5. Data retention

Raw response snapshots are deleted automatically 90 days after creation via a storage lifecycle policy. Workspace configuration and audit log entries are retained for the life of your account and deleted on request after account closure, subject to any legal retention obligation. Backups are retained per our internal disaster recovery policy, available on request.

6. Cookies and similar technologies

TremorWatch.AI does not use analytics or advertising cookies. Sign-in uses browser session storage (not a cookie) to hold your authentication session, and this is strictly necessary for the Service to function — no cookie consent banner is shown because no non-essential cookies are set. If that changes, this page and a consent banner will be updated together.

7. Your rights (UK GDPR)

Subject to applicable law, you can request access to, correction of, or deletion of your personal data, and can object to or restrict certain processing. Contact us using the details in Section 8. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk).

8. Contact

Questions about this policy or a data request: ranatechnologies.uk