Last updated August 21, 2026
Privacy Notice
This notice explains how SCAI LLC handles personal information through Dr. Canary websites, accounts, the portal, support, Inspections, and Reports.
Scope and roles
SCAI LLC (“SCAI,” “we,” or “us”) is the controller of personal information used for our own business purposes, including website operation, accounts, billing, support, communications, security, and service telemetry.
When SCAI processes Customer Personal Data on a Customer’s behalf to provide the Service, Customer determines the purpose of that processing and an applicable Data Processing Addendum governs it. This Notice does not replace that agreement or make SCAI the controller of every processing activity.
Information we collect
Depending on how a person uses the Service, we collect:
- Account and organization data: name, email address, profile image, organization membership, role, invitations, and sign-in records.
- Order and billing data: billing contact, purchase, Plan, status, and payment events. Payment-card details go directly to our payment provider; SCAI does not receive full card numbers.
- Portal and support data: Reports, findings, comments, assignments, sharing selections and recipient contact information, share-link events, support requests, and messages sent to us.
- Device and service data: IP address, browser and device details, session and security identifiers, request logs, error telemetry, and Service interactions.
- Inspection and public-source data: URLs, screenshots, page recordings, technical traces, and other evidence from publicly reachable digital properties.
At a Customer’s direction, we use a supplied recipient address to send or prepare a Report or share link, record issuance and access activity, and show the address and viewing status to that Customer.
Sources and purposes
We receive information directly from users and Customers; automatically from devices and the Service; from payment, identity, hosting, and support providers; and from publicly reachable sources inspected by the Service.
We use it to:
When information is Customer Personal Data, we use it only as Customer directs and the applicable Data Processing Addendum permits.
- provide accounts, Orders, Inspections, Reports, sharing, and support;
- authenticate users, process transactions, and keep business records;
- secure, operate, and debug the Service, and analyze and improve it using permitted service telemetry and aggregated or deidentified information;
- communicate about requested services, account activity, and material updates;
- investigate disputes, enforce agreements, and comply with law.
Public inspection evidence
The Service inspects publicly reachable pages using an ordinary browser and keeps screenshots and technical evidence needed to support or dispute a finding. It does not need private access to inspect public material. The Crawler Policy describes the crawler’s operating boundaries.
If a public page displays personal information, that information can incidentally appear in a capture. We do not collect it to identify or profile the person. To request review or removal from our retained copies, email tom@drcanary.com with the page or Report involved.
AI-assisted processing
We may use AI-assisted processing to classify public page behavior, organize evidence, and draft or review findings. Model inputs are limited by design to public scan content and instructions needed for that task—not account, portal, support, or payment data.
AI output may be incomplete or wrong. It is treated as one input to the Service’s evidence and review process, not as a compliance certification or a decision about a person’s legal rights.
How information is disclosed
We disclose information only as reasonably needed:
- to service providers that host, secure, support, process payment for, or otherwise operate the Service, as listed in Service Providers and Subprocessors;
- to a Customer, its Authorized Users, and recipients they designate through a Report or share link;
- to investigate a Report dispute or protect the Service and others;
- when required by law or a valid legal process; or
- as part of a merger, financing, acquisition, reorganization, or sale of relevant assets, subject to appropriate confidentiality protections.
We do not sell personal information, use it for targeted advertising, or share it for cross-site behavioral advertising. The Service does not contain third-party ad pixels or session-recording tools.
Retention
Retention depends on the information and why it is needed:
- Model responses and inspection evidence are kept only as long as reasonably needed to run, support, and verify Inspections and Reports. Evidence supporting open findings or published Reports may be kept longer while it remains relevant to checking or disputing the finding.
- Account and portal data is kept while needed to provide the account and for a reasonable deletion, recovery, security, or dispute period afterward.
- Order and payment records are kept as required for accounting, tax, fraud prevention, and legal obligations. Security logs and support records are kept only as long as reasonably needed for those purposes.
We may retain limited information when required by law, needed to resolve a dispute, or necessary to honor an opt-out or deletion request. We delete or deidentify information when it is no longer reasonably needed for these purposes.
Security
We use administrative, technical, and organizational safeguards appropriate to the information and the Service, including access controls, encryption in transit, restricted production access, and security logging. Service providers receive only the access needed for their role.
No security measure is perfect. We cannot guarantee that information will never be accessed, lost, or altered. Customers should use appropriate access controls, limit Authorized Users, and report suspected incidents promptly.
Rights and choices
A person may ask to access, correct, or delete personal information SCAI controls, or to object to or restrict particular processing. Where applicable, a person may also request a portable copy or appeal our response. We may verify identity and authority before acting, and some information may be retained where law or a valid business need requires it.
To change non-essential communications or make a privacy request, email tom@drcanary.com. Service and legal notices may still be sent when necessary. A Customer controls requests concerning Customer Personal Data; we will direct those requests to the relevant Customer where appropriate.
Children and international processing
The Service is a business product and is not directed to children under 16. We do not knowingly collect their personal information. Contact us if you believe a child has provided it.
SCAI is based in the United States. We and our service providers may process information in the United States and other countries where we operate. Privacy and data-protection rules may differ across those locations; we apply protections required by applicable law and our contracts.
Changes and contact
We may revise this Notice as the Service or law changes and will post the revised version here. We may also notify account holders of material changes.
Questions, privacy requests, and complaints may be sent to tom@drcanary.com.