Civetta ("we", "us") provides family-aware DNS security. This policy explains what we collect, why, and how you control it.
Information we collect
Account information
Email address, account identifier, and authentication state — collected when you sign up. Authentication is handled by Clerk; we never see your password.
Device information
Platform, model, and a device label you choose. We store an optional push token so we can deliver notifications you've opted into.
DNS event data
When a Civetta-protected device blocks a malicious or suspicious domain, we record: the device, a one-way hash of the domain, the threat category and score, and the time of the block. We do not store full browsing history, successful queries, or the raw domain string.
Billing
Stripe handles payments. We receive subscription metadata (plan, status, period dates) but never your card number, CVV, or full payment instrument.
Family-share data
When a protected user invites a family member to receive alerts, the family member sees only:
- A severity tier (Critical, High, Medium, Info)
- A general threat category
- A short, non-identifying recommendation
The family member never sees the raw domain, the threat score, or the device label. Both parties must consent before any data is shared, and either party can revoke at any time.
Family-sharing consent is renewable, not perpetual. It must be confirmed every 90 days. If a renewal is missed, sharing pauses automatically — no alerts flow, and the family member no longer sees the protected user's history — until both parties reconfirm. Neither account is deleted; only the share is paused.
Revocation runs in two phases. Immediately, in the same database transaction that records your revocation, the share is marked revoked and any in-flight request using it is denied before the response is sent. Asynchronously, within 24 hours, cached shared alerts on the family member's web dashboard, push-notification history, and downstream view stores are scrubbed; both parties receive a confirmation email when the cleanup completes; and an audit-log entry records the completion. Until that second phase finishes, a copy of the abstracted alert may briefly remain in a cache, which is why we send the confirmation email rather than treat the synchronous revoke as the end of the process.
How we use the data
- To detect and block threats in real time on your devices
- To send you the alerts and digests you've subscribed to
- To bill you for the plan you chose
- To meet our security and audit obligations
We do not sell your data. We do not use your DNS event data to build advertising profiles.
Sharing
We share data with:
- Stripe — for billing
- Clerk — for authentication
- Amazon Web Services — for hosting and storage
- Apple Push Notification service / SES — for delivering notifications you opted into
We share only the minimum each provider needs. We never share your data with advertisers, data brokers, or analytics platforms that build cross-site profiles.
Your rights
- Access — request a copy of your data
- Correction — fix anything inaccurate
- Deletion — delete your account and all associated data, anytime, from the Account page
- Portability — export your data in a machine-readable format
Email privacy@civetta.io for any of the above. We respond within 30 days.
Data retention
We keep DNS event data for 90 days, after which it's aggregated to anonymous threat-intelligence statistics. Audit logs are retained for one year. When you delete your account, your personal data is removed from our active systems immediately and from backups within 30 days.
Security
Civetta uses multi-tenant data isolation enforced by the database itself (PostgreSQL row-level security). Audit log entries are append-only. Production secrets live in AWS Secrets Manager. We're happy to share details about our architecture; ask security@civetta.io.
Threat intelligence attribution
Civetta's DNS-layer protection combines multiple public threat-intelligence feeds. We gratefully acknowledge:
- URLhaus & ThreatFox (abuse.ch) — malware distribution + IOCs
- FireHOL Level 1 — IP / CIDR blocklist
- Phishing.Database — active phishing domains
- PhishTank (Cisco Talos) — community-verified phishing URLs
- OISD — aggregated blocklist (CC BY 4.0)
- Tranco — research top-sites list (popularity floor)
Changes to this policy
If we change anything material we'll email you and update the date at the top of this page before the changes take effect.
Contact
Questions: privacy@civetta.io.