LCW Labs privacy notice
Server Alerts Privacy Policy
Server Alerts is a mobile and web companion for monitoring environments. This policy explains what information is collected, why it is used, how it is protected, and how users can request access or deletion.
Who operates Server Alerts
Server Alerts is operated by LCW Labs. For privacy questions, account requests, or deletion requests, contact developer@lcwlabs.app.
Information we collect
Server Alerts collects only the information needed to provide account access, monitoring visibility, notifications, security controls, and support.
Account information
- Email address used to sign in, receive invites, receive site-health emails, and manage access.
- Display name, first name, last name, or organisation name if provided in the portal.
- Role and membership information, including operator, viewer, and admin assignments.
- Multi-factor authentication status and related security metadata. Authentication secrets are stored server-side for verification and are not shown back to users after setup.
Device and notification information
- Firebase Cloud Messaging registration tokens used to deliver push notifications.
- Device platform and app instance identifiers used to register, update, and troubleshoot push delivery.
- Notification preferences for site health, warning, critical, and recovery alerts.
Monitoring site information
- Site names, site codes, licence status, connector enrolments, connector check-in timestamps, and site health state.
- Monitoring snapshots such as host and service names, current states, downtime indicators, notification settings, and alert details sent by the connector.
- Commands requested through the app or portal, such as downtime, acknowledgement, and notification control actions.
Audit and support information
- Audit events for security and operational traceability, including invites, role changes, health-alert setting changes, connector token rotations, licence actions, and monitoring actions.
- Pilot request information submitted through the website, including name, work email, organisation, monitoring system, and message.
Information we do not collect for product use
- Server Alerts does not collect advertising identifiers for advertising.
- Server Alerts does not sell user data.
- Server Alerts does not collect location, contacts, photos, microphone, camera, health, financial, or payment-card data through the mobile app.
- Server Alerts does not require inbound public access to a customer's monitoring server.
How information is used
- App functionality: to sign users in, show authorised monitoring sites, display status, send push notifications, and queue monitoring actions.
- Account management: to manage users, roles, seats, pilot access, licences, invitations, and admin access.
- Security and compliance: to protect accounts, verify connector access, rotate credentials, enforce role access, and maintain audit trails.
- Service communication: to send pilot decisions, trial information, team invitations, site-health email alerts, and support responses.
- Reliability and support: to diagnose connector check-ins, notification delivery, site health state, and account access issues.
How information is shared
LCW Labs does not sell personal information or share it for third-party advertising. Information may be processed by service providers that help run Server Alerts, including:
- Firebase: authentication and Firebase Cloud Messaging push notification delivery.
- Microsoft Azure: hosting, database, secret storage, logging, and managed application infrastructure.
- Microsoft Graph / Microsoft 365: transactional email delivery for pilot requests, invitations, trial messages, and site-health alerts.
These providers process information to provide Server Alerts functionality. LCW Labs may also disclose information if required by law, to protect the service, or to respond to a valid legal request.
Monitoring credentials and connector security
Server Alerts is designed so monitoring servers make outbound HTTPS calls to the broker. The broker and mobile apps do not directly connect to a customer's monitoring web interface.
When a user verifies access to a monitoring site, credentials are relayed to the local connector for local verification. Completed verification payloads are scrubbed server-side. Connector bearer tokens are stored hashed on the broker and can be rotated from the admin portal.
Production connector traffic to the Server Alerts broker uses HTTPS. Local HTTP is used only for localhost development and testing scenarios.
Security practices
- Data sent between the app, portal, broker, and production connector endpoints is encrypted in transit using HTTPS.
- Access to sites is controlled by user identity, site membership, role, and licence seat limits.
- Operators can invite users and manage site settings. Viewers have read-only access.
- Administrative actions and supported site actions are recorded in audit trails.
- Connector tokens can be rotated if a server is rebuilt or a secret may have been exposed.
Data retention
Account, site, licence, and audit records are retained while they are needed to provide the service, support users, maintain security, and meet operational or legal obligations. Monitoring snapshots and alert records may be retained to show current status, recent history, and audit context.
Pilot request records may be retained while evaluating and operating the pilot program. Rejected or obsolete requests may be deleted from the admin portal.
Access, correction, and deletion
Users may request access to, correction of, or deletion of their Server Alerts account information by using the Server Alerts account deletion request form or by contacting developer@lcwlabs.app.
Deletion may remove account profile data, device registrations, invitations, and site memberships. Some records may be retained where required for security, legal, accounting, abuse-prevention, or audit purposes.
Children
Server Alerts is intended for IT and monitoring administrators, operators, and authorised business users. It is not designed for children and is not directed at users under 18.
Changes to this policy
LCW Labs may update this policy as Server Alerts evolves. Material changes will be reflected on this page with an updated effective date.