WATCHDOG™Return to WatchDog
WatchDog legal

Privacy Policy

Version 2026-08-15-platform · Effective August 15, 2026

This Policy explains how Moment Signal Labs, LLC handles information when you use WatchDog’s website, mobile applications, condition monitoring, Agent Watches, evidence-backed alerts, and account services.

1. Scope

This Privacy Policy (the “Policy”) applies to WatchDog™, including its public website and demonstration, authenticated web and mobile applications, WatchSpecs, Agent Watches, Opportunity Matches, notifications, support, and related services (collectively, the “Service”). WatchDog is operated by Moment Signal Labs, LLC (“Moment Signal Labs,” “we,” “us,” or “our”).

This Policy does not govern third-party services that you access independently, even when the Service links to them. Their privacy policies apply to their handling of information.

2. Information we collect

  • Account information. Email address, display name, authentication identifiers, account status, timezone, legal-acceptance records, account-access information, and successful sign-in history.
  • WatchDog definitions. Names, natural-language descriptions, selected categories and scopes, structured WatchSpecs, thresholds, delivery preferences, templates, and optional expectations.
  • Monitoring and evidence records. Source runs, normalized observations, condition results, Opportunity Matches, evidence, confidence and reliability attributes, alert history, and interaction status such as opened, acknowledged, or dismissed. For an Agent Watch, this may include the exact URL you choose, extracted product facts, a limited text excerpt, a content hash, retrieval time, and an AI verdict when you enable a semantic condition.
  • Notification information. Device and push-subscription identifiers, platform, permission state, delivery results, and notification preferences. SMS content alerts are not active in WatchDog 1.2.
  • Device and usage information. Browser and device type, operating system, app version, timestamps, pages or screens used, request metadata, errors, diagnostics, and security events. Successful sign-in records may include an opaque client-generated session identifier, platform, app version, user agent, sign-in time, and last activity time. We do not store raw bearer tokens. We do not store a raw IP address in the sign-in log; when a dedicated audit secret is configured, the server may store a one-way keyed hash of the connection address for security correlation.
  • Developer connection information. Connection name and type, granted scopes, key prefix, one-way credential hash, expiration and revocation status, and last-use time. Raw API credentials are shown once and are not stored in recoverable form.
  • Webhook information. Destination URL and host, subscribed event types, delivery status and attempts, response status, a bounded response excerpt, signing-secret version and hint, and security or failure information. Raw signing secrets are shown once and are not stored in recoverable form.
  • Platform request and activity audit. Meaningful account actions and API or MCP request metadata such as operation, path, status, duration, connection identity, app or client version, user agent, request identifier, trace context, and an optional one-way keyed IP correlation value. We do not store raw bearer credentials in these logs.
  • Support and deletion requests. Messages, files, request status, identity-verification information when needed, and records of how a request was resolved.
  • Public or licensed source data. Sports events, game state, SEC filings, company events, public product pages selected by a user, and source metadata used to evaluate conditions. This source data may identify public-company officers or other people named in public filings. Agent Watches retrieve only approved public-network HTTPS pages and do not intentionally access private, authenticated, local-network, or paywalled resources.

A public demonstration may use local browser storage and simulated or historical data. Do not enter sensitive personal information into a demonstration or WatchDog description.

3. How we use information

We use information to:

  • create and administer accounts, authenticate users, record successful sign-ins, protect accounts, and enforce access entitlements;
  • create and manage scoped API or MCP connections, authenticate external clients, enforce rate limits and idempotency, and audit platform requests;
  • compile user descriptions into structured WatchSpecs and present the interpretation for review;
  • retrieve and normalize supported source data, including exact approved public product pages, evaluate deterministic and permitted semantic conditions, preserve evidence, and create Opportunity Matches;
  • deliver in-app and push notifications, manage preferences, dispatch signed webhooks to destinations you configure, retry eligible failures, and troubleshoot delivery;
  • operate, secure, test, monitor, analyze, and improve the Service;
  • prevent abuse, investigate incidents, enforce agreements, and comply with legal obligations;
  • respond to support, privacy, and account-deletion requests;
  • create aggregated or deidentified analytics that do not reasonably identify an individual.

4. Artificial-intelligence processing

WatchDog can use an artificial-intelligence service provided by OpenAI to interpret a natural-language condition, identify missing details, propose a structured WatchSpec, or evaluate a saved semantic condition against retrieved public evidence. Before an authenticated user invokes interpretation or activates a semantic Agent Watch, the interface asks for permission to send the applicable content to OpenAI for that purpose.

For condition interpretation, the information sent may include the text you enter, the selected Category or sport, recent messages in the condition-building conversation, and technical instructions needed to return a structured result. For semantic Agent Watch evaluation, it may include the saved semantic condition, deterministic condition results, the public source URL and host, extracted product facts, retrieval time, and a limited public-page excerpt. Do not include sensitive personal information, account credentials, private financial information, health information, or secrets in a condition description.

Templates and already structured conditions may be available without AI processing. Deterministic WatchDog engines—not the language model—calculate supported numerical conditions such as scores, time windows, filing dates, values, prices, availability rules, and thresholds. A semantic verdict supports a match only when the configured confidence threshold is met; uncertain or unavailable AI results do not satisfy the semantic condition. OpenAI’s handling of information is also governed by its applicable service terms and privacy commitments to Moment Signal Labs.

5. Developer connections, MCP, and webhooks

When you create a developer connection, an external application or agent that presents its credential can act on your behalf only within the scopes assigned to that key. WatchDog stores a one-way hash and prefix rather than a recoverable copy of the raw credential. The interface displays the raw credential once. You can rotate or revoke keys and connections.

When you configure a webhook, WatchDog sends the selected event payload and delivery metadata to the public HTTPS destination you provide. That recipient is a separate party acting at your direction. The recipient may collect network metadata and process the event under its own terms and privacy practices. WatchDog signs each delivery using a secret shown once; the Service stores the inputs needed to derive and rotate the signing secret, not the raw secret itself.

Administrators may view a unified User Activity history containing meaningful product, access, API, MCP, webhook, notification, legal, and account actions. It is designed as an operational audit trail, not a raw clickstream. Exact logout time is not claimed; session end may be inferred from last observed activity.

6. How we disclose information

We may disclose information to:

  • Hosting, database, identity, and security providers that operate the Service, including Netlify and related infrastructure providers.
  • Notification providers used for app and web push delivery, including OneSignal and underlying mobile-platform services such as Apple Push Notification service. SMS content alerts are disabled unless and until a compliant sender program is approved and separately activated.
  • Artificial-intelligence providers such as OpenAI when you give the feature-level permission described above.
  • Sports, public-filing, retailers, websites, and other data providers when requests are needed to retrieve supported observations. Agent Watch requests identify the public URL and necessarily reach the site hosting that page. Requests may include ordinary network and technical metadata but are not intended to include private WatchDog account content.
  • Webhook recipients you choose when you direct WatchDog to deliver selected signed events to a public HTTPS endpoint. Those recipients process the payload under their own terms and privacy practices.
  • Professional advisers and vendors that support legal, accounting, security, customer support, analytics, or operations under appropriate obligations.
  • Authorities or other parties when reasonably necessary to comply with law, protect rights or safety, investigate fraud or abuse, or respond to valid legal process.
  • A successor organization in connection with a merger, financing, reorganization, sale, or transfer of all or part of the business, subject to applicable law.
  • Other parties at your direction or with your consent.

We do not sell personal information for money. We do not permit third-party advertisers to access private WatchDog account content.

7. Local storage, cookies, and mobile technology

The Service may use browser storage, authentication tokens, cookies, mobile secure storage, and similar technology to keep you signed in, preserve a demonstration session, remember settings, protect requests, and support notifications. Blocking these technologies may prevent parts of the Service from working.

Mobile operating systems and app stores may independently collect information under their own policies. You can control push permission through device settings.

8. Retention

We retain information for as long as reasonably necessary to provide the Service, preserve evidence and alert history requested by users, maintain successful sign-in, platform request, webhook delivery, and security audit records, comply with legal obligations, resolve disputes, and enforce agreements. Agent Watch evidence is intentionally limited to normalized facts, metadata, a bounded excerpt, and hashes rather than a permanent copy of an arbitrary full page. Retention periods differ by data type and purpose.

Legal-acceptance records and limited security or transaction records may be retained after an account closes because they document the agreement or activity in effect during your use. We may retain deidentified or aggregated information where permitted by law.

9. Security

We use administrative, technical, and organizational safeguards designed to protect information. These may include access controls, encrypted network transmission, credential isolation, logging, and vendor security controls. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. You are responsible for protecting your credentials and devices.

10. Your choices and account deletion

You may manage WatchDogs, notification preferences, developer connections, API keys, MCP access, and webhook endpoints within the Service. You can rotate or revoke credentials and webhook secrets, pause or revoke connections, and remove webhook destinations. Browser and device settings control push permissions. AI interpretation is not invoked from the condition-building interface unless you select its permission control. A semantic Agent Watch likewise requires an affirmative AI-consent control; you may create a deterministic exact-page Watch without a semantic condition.

You may request account deletion through the account controls available in the Service. We may verify your identity, place the request in review, disclose an estimated completion timeline, and confirm completion. Deletion removes or anonymizes account data that is not required for a legitimate retention purpose. Certain legal, security, fraud-prevention, audit, and dispute records may be retained where permitted or required by law.

11. State and other privacy rights

Depending on where you live and applicable law, you may have rights to request access, correction, deletion, portability, or information about disclosures, and to appeal certain decisions. These rights may be subject to exceptions. We will not discriminate against you for exercising a legally protected privacy right.

12. Age restriction

The authenticated Service is intended only for adults age 21 or older. It is not directed to children, and we do not knowingly create authenticated accounts for anyone under 21. Contact us through the available support channel if you believe an ineligible person provided information.

13. International processing

The Service is operated from the United States. If you access it from another country, information may be processed in the United States or other locations where our service providers operate, subject to applicable law.

14. Changes to this Policy

We may update this Policy to reflect changes in the Service, providers, or law. We will identify the current version and effective date. Material changes may be presented for renewed acknowledgment before you continue using the authenticated Service.

15. Contact

WatchDog is operated by Moment Signal Labs, LLC, Knoxville, Tennessee, United States. Privacy questions or requests may be submitted through the support or contact method available within the Service.

© 2026 Moment Signal Labs, LLC. All rights reserved.
TermsPrivacy