🔒 Our Core Commitment
Canary Data monitors publicly accessible media and social content for district communications teams. We will never sell, rent, share, or monetize customer data, district configuration, or the analysis generated for a customer. Customer information exists solely to operate the platform, protect accounts, and deliver the subscribed service.
Privacy Policy
Effective Date: June 5, 2026 · Last Updated: July 25, 2026
1. Who We Are
Canary Data is a media intelligence platform that helps public school districts and other public sector organizations monitor publicly accessible news coverage, online conversations, and social media mentions related to their organization, schools, programs, and publicly identifiable leadership. The platform is designed to help communications teams understand public discussion, identify emerging issues, track sentiment, evaluate communications impact, and make informed messaging decisions. Contact us at privacy@canarydata.media.
2. Information We Collect
We collect only what is necessary to provide and secure the service:
- Account information: name, email address, organization, role, and other information provided during signup or account support.
- District configuration: district names, schools, geographic parameters, search terms, monitored public sources, and public social accounts or hashtags designated for monitoring.
- Publicly accessible content: news articles, public websites, public posts, metadata, and links retrieved from publicly available sources on a customer's behalf.
- Connected Meta account data: when an authorized district user connects Meta, we receive the Facebook Pages and connected Instagram professional accounts that person is permitted to access; granted permissions; owned posts and media; and the identifiers needed to keep those assets mapped to the correct district. We do not request permission to publish posts, manage comments or messages, access advertising accounts, or read native Insights in this release.
- Platform outputs: summaries, sentiment scores, risk levels, recommendations, tags, reports, exports, and other derivative analysis generated for the customer.
- Usage and security data: access logs, IP address, browser type, pages visited, authentication events, and similar technical data used for security, auditing, troubleshooting, and performance.
We do not intentionally collect student educational records, internal student information system data, private messages, or sensitive personal information. Canary Data is not designed to monitor private or closed Facebook groups, private social accounts, password-protected communities, or content that is not publicly accessible.
3. How We Use Information
We use information exclusively to:
- Operate, maintain, and deliver the Canary Data dashboard, reports, alerts, and support services.
- Authenticate users, secure accounts, enforce district-level access controls, and protect customer workspaces.
- Retrieve, filter, summarize, classify, and present publicly accessible media and social content selected by or relevant to the customer's configuration.
- Read owned posts and media from customer-authorized Facebook Pages and connected Instagram professional accounts and present that content in district-controlled reporting. Canary does not use this connection to publish, reply, manage messages or comments, access advertising accounts, alter campaigns, or spend advertising budget.
- Generate communications-focused analysis, including sentiment, reputation risk, recommendations, and report exports.
- Communicate about account setup, service operations, invoices, security, support, and product updates.
- Improve platform reliability, accuracy, and safety without selling customer data or using one customer's confidential configuration or outputs to market to another customer.
4. Public Data and Monitoring Boundaries
Canary Data is a public media and digital monitoring tool. Our intent is to surface information a district communications team could reasonably find in publicly accessible media or public social channels, not to surveil private communities. When a customer separately connects Meta, Canary also reads owned posts and media from the Facebook Pages and connected Instagram professional accounts that user explicitly selects.
- We do not intentionally access closed groups, private social media accounts, private parent or employee communities, or password-protected spaces.
- We monitor public social signals only when they are publicly accessible and relevant to a customer's configured district, schools, leaders, sources, or search terms.
- We do not provide tools for employee discipline, student discipline, law enforcement, or private individual surveillance.
- Recommendations are limited to communications functions such as messaging, engagement, channel strategy, reputation monitoring, and stakeholder awareness.
- Customers are responsible for choosing monitored terms and sources that are appropriate, lawful, and aligned with their organization's policies.
5. We Do Not Sell or Share Customer Data
This is non-negotiable. Canary Data does not and will never:
- Sell customer data, district configuration, public-source collections, reports, or analysis outputs to any third party.
- Share customer data with advertisers, data brokers, or marketing partners.
- Use customer data to target advertising.
- Use one customer's private configuration, exports, or derivative outputs as a product for another customer.
We may use trusted infrastructure and processing providers, such as hosting, database, monitoring, public-web collection, email, payment, and AI-processing vendors, only as needed to operate Canary Data. These providers are authorized to process information solely for service delivery, security, support, and platform operations.
6. Data Security and Protection of Analysis
We recognize that aggregated monitoring data and derivative analysis can become valuable and sensitive because it reflects an organization's issues, risks, priorities, and public narrative. We protect both source data and analysis outputs through administrative, technical, and organizational safeguards.
- Data is encrypted in transit using HTTPS/TLS and encrypted at rest by our infrastructure providers.
- Customer workspaces are separated by district or organization, with access limited to authorized users.
- Meta access tokens are encrypted separately on the server, are never returned to browser clients, and are deleted locally when a connection is disconnected or a valid Meta deletion request is received.
- Production access is limited to authorized Canary Data personnel and service providers who need access to operate, secure, or support the platform.
- Demo environments use fake/sample data and should not contain live customer records, student records, or private district work product.
- We use role-based access, logging, and operational controls designed to reduce unauthorized access and support investigation if an issue occurs.
- We review platform logic and data workflows to reduce inaccurate or off-geo results that could create misleading analysis for customers.
7. Security Incidents and Breach Notification
If we become aware of unauthorized access to customer information or a security incident that legally requires notification, we will investigate promptly, take appropriate steps to contain and remediate the issue, and notify affected customers in accordance with applicable law and contractual obligations. Notification timing and content may vary by state and circumstance, but our intent is to communicate without unreasonable delay while preserving the integrity of the investigation and any required remediation.
8. Data Retention and Deletion
We retain account information, district configuration, collected public content, reports, exports, and derivative analysis for the duration of the customer relationship unless a different retention period is agreed in writing. Meta credentials are retained only while the connection is active. A customer may disconnect Meta from Canary, remove Canary from Meta Business Integrations, or use Meta's data-deletion process; Canary then removes stored tokens and stops future collection. Upon cancellation or written request, we will delete or de-identify customer account and district data within a commercially reasonable period, unless retention is required for legal, security, billing, backup, or dispute-resolution purposes. Aggregated, non-identifiable technical logs may be retained for security and platform reliability.
9. Your Rights and Customer Control
Customers may request to:
- Review the account, district configuration, and report data associated with their organization.
- Correct inaccurate account or configuration information.
- Remove monitored terms, sources, users, or districts.
- Request deletion or export of customer data, subject to applicable law and contractual requirements.
- Opt out of non-essential communications.
To exercise these rights, email privacy@canarydata.media. We will respond within a reasonable timeframe.
10. FERPA, COPPA, and Student Data
Canary Data does not collect, process, or store student educational records or student information from internal school systems. The platform monitors publicly accessible media and social content about districts and public institutions. Canary Data is not intended to be used as a student record system, student profile, disciplinary tool, or child-directed service, and it is not designed to collect information from children under 13.
11. Changes to This Policy
If we make material changes to this policy, we will update the “Last Updated” date and notify subscribers by email or in-product notice when appropriate. Continued use of the service after an updated policy is posted or communicated constitutes acceptance of the updated policy.
Questions about this policy? Contact us at privacy@canarydata.media. We're a small team and will respond personally.