Privacy Policy
Last updated: June 2026
1. Overview
Welcome to Invariant.dev. We respect your privacy and are committed to protecting your personal data. This privacy policy describes how we collect, process, secure, and use your personal details and event payloads when you use our monitoring services, visit our website, or interact with our console.
2. Data We Collect
We collect information necessary to deliver our real-time business rule & event monitoring services. This includes:
- Account Credentials: Email address and encrypted credentials when you register.
- Integration Configuration: Slack webhook URLs or HTTP callback endpoints you provide to receive alerts.
- Ingested Event Payloads: JSON metadata, event names, and timestamp structures streamed via our REST API. We use this data solely to evaluate the invariants and rules you configure.
- Billing Information: Purchase metadata, customer keys, and subscription details. Note that payment transactions are reseller-managed and processed securely by Paddle.
3. How We Use Your Data
Invariant.dev processes your information to fulfill our contractual commitments:
- Evaluating real-time business rule constraints and monitoring SLA timing windows.
- Dispatching alerts (e.g. to Slack or custom webhooks) immediately when rules are breached.
- Managing subscription access tiers (Free vs. Pro plan limits).
- Optimizing application latency and checking system health.
We do not sell, trade, or share your data or event payloads with third-party advertisers or data brokers under any circumstances.
4. Retention & Security
Your privacy is integrated into our infrastructure:
- Retention Limits: Free plan events are retained for 3 days; Pro plan events are kept for 30 days before being automatically purged from our databases.
- Encryption: All payload transmissions are encrypted in transit using Transport Layer Security (TLS 1.3) and encrypted at rest in our databases.
- Access Control: Event data and rule metadata are restricted using row-level security (RLS) policies within Supabase, ensuring that only authenticated workspace members can read them.
5. Contact Us
If you have any questions about this Privacy Policy, or wish to request data export or deletion under standard privacy frameworks (such as GDPR or CCPA), please email us at: