Privacy Policy

Last updated: 2026-07-19 · effective immediately

OwlWatt (the "Service") is built around a simple promise: we collect only what we need to monitor your solar system, we never sell your data, and we never train AI models on it.

This policy explains how we collect, use, share, and protect personal information about you, and your rights under the European General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and comparable U.S. state laws.

1. Who we are

OwlWatt is operated by its founder as a sole proprietorship in Massachusetts, USA. For purposes of GDPR, we are the data "controller" for personal information we collect from you. For purposes of CCPA, we are a "business" and, where we act on our customers' behalf, a "service provider." OwlWatt does not currently have an EU or UK representative under GDPR Article 27; customers in the EU/UK with questions can contact us directly at the address in Section 15.

2. What we collect and from where

Categories of information

Sources

3. How we use it and why we are allowed to

We process personal information only for the purposes below, and only where we have a lawful basis to do so under GDPR Article 6. Under CCPA, these are the business purposes for which personal information is collected.

4. What we do not do with it

5. Do Not Sell or Share My Personal Information

We do not sell or share your personal information, for any purpose, to anyone. There is nothing for you to opt out of here, because the default is already off. We do not participate in any cross-context behavioral advertising programs. If that ever changes, we will update this section at least 30 days before any such activity begins and provide a working opt-out mechanism. We honor Global Privacy Control (GPC) signals from your browser as an expression of opt-out preference.

6. Who we share it with (Subprocessors)

We engage the following third-party service providers to operate the Service. We will post updates to this list at least 30 days before adding a new subprocessor so customers have time to object.

Provider Location Service Data categories Reference
Fly.io USA (Newark, NJ) Application hosting All customer data in transit through the app tier; no long-term storage Privacy / DPA
Neon USA (AWS us-east-1, N. Virginia) Postgres database Account, telemetry, devices, contracts, support tickets, consent log Privacy / DPA
Cloudflare Global edge (HQ USA) DNS, CDN, DDoS protection, WAF HTTP request metadata (IP, user-agent, timestamps); TLS-terminated page contents Privacy / DPA
Resend USA Transactional email delivery Email address, message body, delivery metadata Privacy / DPA
Anthropic USA (commercial API) AI-generated dashboard insights, and contract analysis when you opt in Anonymized telemetry summaries; contract text only when you opt in. Anthropic's commercial terms prohibit training on your data. Privacy / Terms
Stripe USA Payment processing (hosted checkout + subscription billing) Your payment details are entered directly on Stripe's hosted checkout page and never reach OwlWatt's servers. Stripe shares your email and billing address with us to run your subscription. Privacy / DPA
PostHog EU Product/marketing analytics — see Section 9 Page views sitewide; session replay on the signup/pricing/confirm/pair/founders flow only Privacy / DPA
Rewardful USA Referral/affiliate program tracking For annual-plan signups that arrive through a customer's referral link: a referral ID linking the new signup to the referring customer. If you enroll as an affiliate yourself, your email is sent to Rewardful to look up your referral stats in the dashboard. Privacy

7. International data transfers

Most subprocessors process personal data in the United States. PostHog (Section 6) processes analytics data in the EU. If you access the Service from the EU, UK, Switzerland, or another jurisdiction that restricts cross-border transfers, some of your data (account, telemetry, billing, support) will be transferred to and processed in the United States.

Transfers from the EU/UK/Switzerland to the United States are covered by Standard Contractual Clauses (SCCs) incorporated into each subprocessor's DPA linked above, and — where applicable and active — by the EU–U.S. Data Privacy Framework (DPF), UK Extension, and Swiss–U.S. Data Privacy Framework.

8. How long we keep it

To erase all your data entirely, use Account Deletion in Settings → Account → Cancel account.

9. Cookies and similar technologies

Cookies we set directly

Analytics

We run one analytics tool, PostHog, on our marketing site, help/learn content, and the signup, confirmation, and pairing pages. It's loaded from owlwatt.com/ph (a reverse proxy to PostHog's EU servers, not posthog.com directly) and records page views. On /signup, /pricing, /confirm, /pair, and /founders only, it also records session replay (a recording of on-page interactions) so we can see where people get stuck signing up. It's configured with autocapture off (no blanket click/form tracking), anonymous visitors are not assigned a persistent identity profile (person_profiles: identified_only), anonymous-visitor data is kept in memory only (no persistent PostHog cookie until you sign up or log in), and it honors your browser's Do Not Track setting and Global Privacy Control signal (Section 5) — if either is present, PostHog (including session replay) does not load at all.

The logged-in dashboard and the sign-in page run no third-party analytics. We previously loaded Plausible directly from plausible.io on those two pages; we removed it because it was not proxied through our own infrastructure like PostHog is, so it received authenticated customers' pageviews and IP addresses directly. A second unproxied analytics vendor on the pages where you're logged in didn't buy us anything a single, proxied tool doesn't already cover.

PostHog is not used for advertising or cross-context behavioral targeting, we don't run ad-retargeting pixels, and we don't sell or share analytics data with anyone (see Section 5). If you'd like to object to this processing, use the Objection right in Section 11 or contact us at the address in Section 15.

10. How we protect it

No system is perfectly secure. If we ever experience a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify affected customers without undue delay and, where required, notify the relevant supervisory authority within 72 hours.

11. Your rights

You have the following rights over your personal information. To exercise any of them, email [email protected] or use the self-service options in Settings → Account where indicated. We will respond within 30 days (GDPR) or 45 days (CCPA); free of charge in the vast majority of cases.

Rights available to everyone

Additional rights under GDPR / UK GDPR

Additional rights under CCPA / CPRA

We may need to verify your identity before fulfilling certain requests; we will match information you provide against your account record and may ask for additional verification for sensitive requests.

12. Complaints and supervisory authorities

If you believe we have mishandled your personal information, we would like the chance to fix it — please contact us first at [email protected]. You also have the right to lodge a complaint with a supervisory authority:

13. Children's privacy

The Service is intended for homeowners and is not directed to children under 16. We do not knowingly collect personal information from anyone under 16. If you believe a child under 16 has provided us personal information, please contact [email protected] and we will delete it.

14. Changes to this policy

We will update this policy from time to time as the Service evolves or as the law requires. When we make material changes — adding a new subprocessor, changing retention periods, adding new categories of data, or expanding our use of your data — we will notify you at least 30 days in advance by email and by posting a prominent notice on the Service. We also update the "Last updated" date at the top of this page on any change.

15. Contact

Questions, requests, or concerns about this policy or how we handle your personal information?

If you are an EU or UK data subject and would like to exercise rights that require us to engage additional formalities (for example, a subject access request through an authorized agent), please state that in your email and we will respond accordingly.