Privacy
Company Identity
- Legal name: Pixeware LTD
- Address: 37 Beech Lane, SK6 4AF, Romiley, UK
- Country: UK
- Registration ID: 08161767
- VAT ID: GB141143753
Watchgoose processes account, monitoring, and billing data needed to operate the service, including account credentials, project metadata, check configuration, alert delivery history, and billing contact details.
Last updated: 2026-09-03
What We Collect
Account data includes your email address, authentication/session metadata, security settings, timezone, optional signup attribution responses, notification preferences, project membership, and support correspondence. Monitoring data includes check names, descriptions, tags, schedules, ping URLs, ping timestamps, status changes, logs, and alert delivery records. If you configure integrations, we store the integration settings needed to send alerts.
GitHub may be used as a sign-in provider; Watchgoose retains only the verified primary email address returned by GitHub. We do not retain the GitHub access token, account ID, username, or profile data.
We do not need payment card numbers to operate Watchgoose. Paddle handles checkout, taxes, invoices, receipts, and payment details as merchant of record. We store billing identifiers, plan state, entitlement snapshots, invoice metadata, and webhook/audit records needed to keep your subscription in sync.
On selected anonymous public pages of watchgoose.com, we use Umami Cloud to understand aggregate page visits, referral sources, campaign attribution, and page performance. We do not load analytics on authenticated, account, tokenized-link, error, or legal pages, or on staging and preview hosts. Umami may receive the page URL (including its query string), page title, referrer, display size, language, browser, operating system, device type, approximate location, and Core Web Vitals. We do not configure identity tracking or session replay, and we do not send account identifiers, email addresses, form contents, or monitoring data. The tracker honors your browser's Do Not Track setting and does not set analytics cookies. Do not put personal or sensitive information in links to public pages.
Connected AI Clients
When you approve a Model Context Protocol (MCP) connection, you choose one project and either read-only or read-and-write access. The connected AI client can receive only the fields returned by the tools allowed for that access. Source IP addresses, user agents, run IDs, body URLs, ping body contents, check UUIDs and ping URLs, and integration channel UUIDs are never sent to the connected AI client.
The connection flow processes a single-use authorization handoff and a delegated project credential. The handoff expires after five minutes and can be used only once. The hosted MCP service processes the delegated credential transiently in memory when making project API requests and stores it only as encrypted OAuth grant state. It does not return the delegated credential, API keys, or OAuth tokens as tool output.
OAuth client, authorization, session, grant, and delegated credential state is stored in service-owned SQLite on the single production host in one region. OAuth payloads and the delegated credential are encrypted at rest, and stored identifiers are keyed so a database copy does not reveal live identifiers. This state follows our normal production backup rotation rather than globally replicated OAuth storage.
The MCP application adds no telemetry. Our production proxy keeps normal security and operational access logs, including source IP address, user agent, full request URI including its query string, method, status, and timestamp. Authorization, cookie, and X-Api-Key headers are removed from these logs, and the OAuth callback is not logged. Access-log fields are never returned to the connected AI client as tool output.
We retain the MCP connection record while the associated account and project data remains active, including the client name, selected project, approved access, creation and last-use times, and revocation status. For each MCP API operation, we record the operation, route, method, outcome, HTTP status, timestamp, and associated connection. These audit events are retained for 90 days. You can revoke a connection under Account settings > MCP Connections; revocation blocks future project API access and the client must complete authorization again to reconnect.
How We Use Data
We use data to provide monitoring, alerting, account administration, approved connected-client access, billing administration, abuse prevention, security logging, support, and service improvement. We may use aggregated or de-identified operational information to understand reliability, capacity, and product usage, but not to identify a customer publicly without permission.
Legal Bases
For users in the UK, EEA, or other GDPR-style jurisdictions, our legal bases are: contract, where processing is needed to provide Watchgoose; legitimate interests, where we secure, maintain, improve, and protect the service; legal obligation, where billing, tax, accounting, or lawful request records must be kept; and consent, where applicable for optional communications or settings you choose.
Processors and Third Parties
We use service providers for hosting, networking, email delivery, human support email, authentication through GitHub, billing through Paddle, error/operational diagnostics, privacy-preserving aggregate web analytics through Umami Cloud, backups, and security operations. These providers may process data only as needed to provide their services to us. A current subprocessor list or more detailed procurement information can be requested at support@watchgoose.com.
Retention
We keep account and project data while your account is active. Monitoring logs are retained according to your plan limits and service configuration. Billing, invoice, tax, entitlement, and security/audit records may be kept longer where required for accounting, fraud prevention, dispute handling, or legal compliance. Backups are overwritten on a normal rotation and are used for disaster recovery, not as an active archive.
Watchgoose sends operational email for sign-in links, monitoring alerts, email reports, and account lifecycle notices. Paddle sends billing invoices and billing receipts.
Your Choices and Requests
You can change notification settings and remove projects or checks from the product. Privacy requests, including access, correction, export, deletion, objection, or restriction requests, can be sent to support@watchgoose.com.
The service is not directed to children under 16. Do not use Watchgoose for special-category personal data, payment card data, health records, or other regulated sensitive data unless we have agreed to that use in writing.