Alarum

shield_person Privacy policy

Last updated: August 13, 2026

1. Who we are

Alarum is published by BIG et Nouf, a French SARL registered at 17 Boulevard de Strasbourg, 62000 Arras, France (RCS Arras 978 428 506, VAT FR55 978 428 506). For any privacy-related question, contact us at contact@bigetnouf.fr.

2. Data we collect

We collect only what the service needs to operate:

  • Account data: email address, display name, avatar URL, and the OAuth subject identifier returned by your sign-in provider (GitHub or Codeberg).
  • Workspace content: workspaces, projects, ingestion tokens, notification rules, forwarders and quiet-hour preferences you create in the app.
  • Webhook payloads: the raw events you send to Alarum for routing and inbox display.
  • Push subscriptions: when you enable browser notifications, the endpoint and cryptographic keys provided by your browser's push service.
  • Technical logs: timestamp, IP and HTTP status of each ingestion call, kept for rate-limiting and abuse detection.
  • Billing identifiers: a Paddle customer reference once you subscribe to a paid plan. We never see or store card data.

3. Why we process it

  • Operate the service: store events, route notifications, render the dashboard.
  • Authenticate you and prevent unauthorized access to your workspaces.
  • Bill your subscription (paid plans only) via Paddle.
  • Detect and block abuse (rate-limit, anti-SSRF, ingestion log).
  • Communicate service-critical messages (security alerts, invoices, account changes).

We never sell your data and never use webhook payloads for advertising or profiling.

4. How long we keep it

  • Raw webhook payloads: deleted automatically after your plan's detail-history horizon (3 days on Discover, 30 days on Freelance, 90 days on Agency).
  • Aggregated rollups (counts per day/level, top tags and sources): kept for your plan's trend-history horizon (1 month, 6 months or 1 year), then purged.
  • Account data: kept while your account is active and deleted when you close it. A short audit window (logs of authentication and billing events) may be retained up to 12 months for security and legal compliance.
  • Billing records: invoices and the underlying transaction trail are retained for the period required by French accounting law (10 years).

5. Sub-processors

Operating the service relies on a small number of vetted third parties:

  • OVH (France): hosting and storage. Data resides in OVH's datacenters in France.
  • GitHub / Codeberg: OAuth sign-in.
  • Paddle.com Market Ltd (UK): Merchant of Record handling subscription billing, tax collection and customer payment data on our behalf.
  • Mozilla / Google / Apple push services: when you enable browser notifications, your browser's push endpoint is contacted to deliver alerts.

We sign Data Processing Agreements with these sub-processors where applicable.

6. International transfers

Service data is stored within the European Union (OVH, France). Some sub-processors (Paddle, GitHub, push services) may process limited account or billing data outside the EU under standard contractual clauses or adequacy decisions.

7. Your rights

Under the GDPR you can access, rectify, port, restrict or erase your personal data, and object to its processing. You can act on most of these rights directly from your account (Settings → Account), or contact us at contact@bigetnouf.fr. You may also lodge a complaint with the CNIL (French data protection authority).

8. Security

We use HTTPS for every connection, hash credentials with strong algorithms, sign session tokens, run anti-SSRF guards on outbound webhooks, and keep databases on encrypted volumes provided by our host. No system is perfectly secure: if you spot a vulnerability please email contact@bigetnouf.fr.

9. Cookies

Alarum uses a single first-party session cookie to keep you signed in. We do not use advertising, analytics or third-party tracking cookies.

10. Audience measurement

Alarum measures its audience with Matomo, hosted on our own servers: without cookies, with an anonymised IP address, and a retention limited to 180 days. No webhook content, no token and no account data is ever transmitted. This is why you are not asked to accept anything.

What we record is a page view, along with your interface language, your theme, and whether you opened Alarum as an installed app or in a browser tab. Identifiers in the address bar are replaced by :id before anything is sent, and two areas are excluded from measurement entirely: invitation links, which carry an access secret, and the administration pages.

On top of that, the following events count an action. Each one carries a type, never a value you typed. Open your browser's network tab and check for yourself:

EventWhenWhat is transmitted
alarum / signup / githubYou create an accountThe sign-in provider, never your name or email
alarum / login / githubYou sign back inThe sign-in provider, never who you are
alarum / workspace / createYou create a workspaceNothing else, never its name
alarum / project / createYou create or delete a projectWhich of the two, never the project name
alarum / token / createYou create or revoke an ingestion tokenWhich of the two, never the token
alarum / forwarder / discordYou create a forwarderThe kind of destination, never its URL
alarum / member / inviteYou invite someone to a workspaceNothing else, never their email or the invitation code
alarum / snippet / curlYou copy an integration exampleThe language you picked, never the snippet nor the token
alarum / push / enableYou turn on browser notificationsNothing else, never your push endpoint
alarum / checkout / proA payment overlay opensThe plan, never an amount or a customer reference
alarum / subscribed / proA subscription is confirmedThe plan, never an amount or a customer reference

Receiving your webhooks is not measured this way at all: it happens server-side and never reaches Matomo. And we deliberately do not attach your account to these measurements, so they count usage, not people.

11. Changes

We may update this policy as the service evolves. Material changes will be announced in the in-app changelog and, when required, by email.