NewWe published QA-Bench v0 - Measuring how AI models handle code verification

Privacy Policy

Canaries, Inc. · Effective July 28, 2026

This Privacy Policy describes how Canaries, Inc. ("Canary," "we," "us") collects, uses, and protects information when you use our websites (runcanary.ai and subdomains) and our AI red-teaming service. If you use the service under an agreement between Canary and your organization, that agreement (including any Data Processing Agreement) controls where it differs from this policy.

1. Information We Collect

Account information. When you or your organization sign up, we collect your name, work email address, and organization details. Authentication is handled by our identity provider; we do not store your passwords.

GitHub integration data. When your organization installs the Canary GitHub App, we receive repository metadata (repository names, pull request titles, descriptions, diffs, and commit metadata) for the repositories you choose to connect. We access repository contents only to perform the analysis and testing you have enabled.

Customer source code. To test your application, Canary clones connected repositories into isolated, single-use sandbox environments. Source code is processed transiently: sandboxes and the code inside them are destroyed when each run completes. We do not retain copies of your repositories outside the sandbox lifecycle.

Run results and evidence. We retain the outputs of the service: generated checks, findings, run logs, and evidence artifacts such as screenshots and screen recordings of the sandboxed application under test. These are stored encrypted.

Usage and log data. We collect standard operational logs (IP addresses, browser type, pages viewed, timestamps) to secure and operate the service.

Cookies. We use cookies necessary for authentication and session management. We do not sell information collected through cookies.

2. How We Use Information

We use the information above to provide and secure the service: to run the analysis and testing you request, deliver results to your pull requests and dashboard, authenticate users, prevent abuse, provide support, and meet our legal obligations. We also use aggregate, de-identified operational data to improve the service.

We do not use your data to train AI models. Canary does not use customer data — including source code, prompts, findings, or evidence — to train or fine-tune any machine-learning model, whether our own or a third party's.

3. How We Share Information

We do not sell personal information. We share information only with:

  • Subprocessors that help us provide the service, listed below. Each is bound by contractual confidentiality and data-protection obligations.
  • Service providers for supporting functions (e.g., email, customer communications).
  • Legal authorities where required by law, subpoena, or to protect our rights, users, or the public.
  • A successor entity in connection with a merger, acquisition, or sale of assets, subject to this policy.

Subprocessors

Our subprocessors fall into the following categories, all located in the United States: cloud infrastructure and hosting; isolated sandbox execution; identity and authentication; AI model inference (processed transiently per Section 2); and communications and support tooling. Customers may request our current named subprocessor list, which we provide under our Data Processing Agreement, by contacting founders@runcanary.ai.

4. Data Retention and Deletion

Customer source code exists only inside ephemeral sandboxes and is destroyed at the end of each run. Run results, findings, logs, and evidence artifacts are retained for the life of your organization's subscription. Upon verified request or contract termination, we delete customer data within 30 days, except where retention is required by law. Operational and audit logs are retained for up to 365 days.

5. Security

We maintain a security program aligned with SOC 2, including encryption of data in transit (TLS) and at rest (AES-256), least-privilege access controls with multi-factor authentication, continuous infrastructure monitoring, and audit logging. No system is perfectly secure; we encourage you to report suspected vulnerabilities or incidents to founders@runcanary.ai.

6. Your Rights and Choices

Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal information, or to object to or restrict certain processing. To exercise these rights, contact us at founders@runcanary.ai. If you use the service through your employer, we may direct your request to them, as they control the account.

California residents: we do not sell or share personal information as defined by the CCPA/CPRA, and we honor applicable rights requests. We do not discriminate against you for exercising privacy rights.

7. International Users

The service is operated from the United States and information is processed in the United States. If you access the service from outside the U.S., you understand your information will be transferred to and processed in the U.S.

8. Children

The service is not directed to individuals under 16, and we do not knowingly collect their information.

9. Changes to This Policy

We will post any changes on this page and update the effective date. For material changes affecting customer data handling, we will notify account owners by email.

10. Contact

Canaries, Inc. — 450 Townsend St, San Francisco, CA 94107. Privacy and security contact: founders@runcanary.ai.