Privacy Policy
This page explains what personal data Thirdwatch collects, why we collect it, who we share it with, and the rights you have over it. Applicable privacy rights depend on your location. Contact us to request access, correction or deletion of your data.
Last updated:
1. Who we are
“Thirdwatch” (“we”, “us”) operates the website at thirdwatch.dev, the Thirdwatch MCP server, and the family of public scraper actors listed at apify.com/thirdwatch. We are the data controller for personal data collected through these surfaces, except where the Apify platform itself is the controller (e.g., your Apify account credentials).
2. What we collect
- Account data: email address, sign-in metadata, and session information when you sign in through Clerk. Thirdwatch also stores MCP API-key hashes, OAuth grants and hashed access/refresh tokens.
- Billing data: billing email, country, and payment and payment/product identifiers when you purchase credits. Dodo Payments handles checkout and card details; Thirdwatch does not store full card numbers.
- Usage data: API requests, tool calls, MCP usage events, credit consumption, anonymous device IDs, and aggregate page-view analytics. Stored in our Postgres database on Railway and in PostHog when that optional integration is configured.
- Optional website analytics: after you accept, Microsoft Clarity collects interaction metrics, heatmaps and masked session replay on public marketing pages to help us improve the website. Text is masked; account, dashboard and OAuth pages are excluded. Arbitrary URL query values and fragments prevent recording; known public blog categories and setup anchors are allowed. We send no account identifier, email or tool input to Clarity, and request no advertising storage. Microsoft processes this data under its Privacy Statement.
- Tool inputs and outputs: when you run a Thirdwatch actor or call an MCP tool, the inputs you provide and the data returned pass through our infrastructure. Usage records include a redacted query summary, called sources, result counts, credits and delivery costs. When Apify executes a request, its platform also stores run inputs and datasets. Outputs may contain third-party PII scraped from public sources at your direction.
- Diagnostic data: error stack traces, latency, and non-personal context for reliability monitoring (Sentry). Emails, IP addresses, request bodies, and webhook payloads are stripped before send.
We do not collect: government IDs, biometric data, health data, precise geolocation, browsing history outside our surfaces, or special-category data under GDPR Art. 9.
3. Why we collect it (lawful basis)
- Contract performance — to provide the service you signed up for (account, billing, tool execution).
- Legitimate interest — to keep the service secure, measure aggregate usage, and detect fraud or abuse.
- Consent — for non-essential cookies and marketing analytics (see our Cookie Policy).
- Legal obligation — when required to retain or disclose records (e.g., tax invoicing, lawful requests).
4. Who we share it with
We share personal data only with the sub-processors listed at /legal/subprocessors, under the terms and data-processing arrangements applicable to those services. We do not sell personal data. We do not install advertising network pixels; Microsoft Clarity processes optional website analytics under Microsoft's published privacy terms.
Outputs of scraper actors and MCP tools are returned to you. We do not use those outputs to train models or to enrich any third-party dataset.
5. International transfers
Our infrastructure spans the United States and the European Union (see sub-processor regions). The providers may process data outside your country. Their published privacy and data-processing terms describe their transfer arrangements.
6. Retention
- Account & billing records: retained while your account is active. Payment and credit-ledger records may remain after account closure when needed for accounting, fraud prevention, disputes or a legal obligation.
- Tool inputs/outputs: Apify-executed requests are retained under the provider's configured run/dataset retention. Direct-provider results are returned in the response; Thirdwatch retains usage summaries, not a separate full result dataset.
- Usage logs & diagnostics: usage records remain while your account is active unless deleted following a verified request. Monitoring providers use their configured retention settings.
- Analytics events: retained according to the configured analytics project. You can decline optional browser analytics and request deletion of account-linked analytics.
7. Your rights
Under GDPR, DPDP, and CCPA you have the right to access, correct, delete, port, or restrict the processing of your personal data, and to object to processing based on legitimate interest. EU/UK residents additionally have the right to lodge a complaint with their supervisory authority. California residents have the right to opt out of any sale of personal data — we do not sell personal data.
To exercise any of these rights, email support@thirdwatch.dev. We respond within 30 days.
8. Security
We use HTTPS for public service endpoints. Clerk handles website sign-in; Thirdwatch handles MCP authorization and hashed tokens. Access to infrastructure and customer records is restricted to service operation. Contact support to rotate an exposed credential or revoke a connection.
9. Children
Thirdwatch is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, email support@thirdwatch.dev and we will delete it.
10. Changes to this policy
We will revise this policy as the service evolves. Material changes will be announced on the site and, where required, by email. The “Last updated” date at the top of this page reflects the most recent revision.
11. Contact
For privacy questions, data subject requests, or to report a concern, email support@thirdwatch.dev.