Privacy policy
Last updated October 7, 2026
Gryphon is a service for monitoring websites and servers. It is made up of a web dashboard, apps for iPhone and Android, and an optional agent you can install on your own servers. Gryphon is a product of GoCode.ca ("GoCode", "we", "us", "our"). This policy explains what information Gryphon collects, why, who it is shared with, and the choices you have.
This policy covers the Gryphon service that GoCode operates. Gryphon can also be installed and run by other organizations on their own servers. If you use an installation run by someone else, that organization decides how your information is handled, and this policy does not apply to it.
Who we are
Gryphon is owned and operated by GoCode.ca, in Canada. For privacy questions or requests, contact us at support@gocode.ca.
Information we collect
Your account
- Your name and email address, which you use to sign in and which identify you to the other people on your account.
- Your password, which we store only as a one-way hash (bcrypt). We cannot read it.
- Your time zone, so that times are shown in your local time.
- Your account and role: the account you belong to, its name, whether you are an owner or a member of it, and, for a member, whether the owner lets you change what is monitored.
- Two-factor sign-in, if you turn it on: the secret your authenticator app shares with us, which we encrypt, one-way hashes of your recovery codes, and, for each browser you choose to trust, a label made from the browser's name and when you trusted it.
- Your alert preferences: whether you want alerts by push and by email, whether you are on call and until when, and the alarm sound you chose.
What you ask Gryphon to monitor
- Hosts and services: the names, domain names, web addresses and IP addresses of the servers and sites you add, any labels you give them (such as a location or operating system), and how often each one should be checked.
- Credentials for database checks: if you set up a Postgres, MariaDB, MySQL or Redis check, the host, port, username, password and database name it needs. We encrypt these before storing them.
- Check results: whether each check passed, response times, status messages (such as "502 Bad Gateway" or a certificate's expiry date), and the events recorded when a service has a problem or recovers.
- Readings from the Gryphon agent: if you install the agent on a server, it connects to Gryphon from that server — we never connect to your servers to reach it — and reports the server's disk space, memory use, CPU use and system load, its own version, the server's host name, operating system and processor type, when it connected and when it was last connected, and the results of the checks it runs for you: databases, Docker containers and Swarm services, web, ping and port checks inside your network, the age of files in folders you allow, and the exit status and first line of output of scripts you put in its script folder. In a Kubernetes cluster it also reports the cluster's version, its own namespace and the node it runs on, and, for what you ask it to watch, how many workloads, pods and nodes are ready, with the names of those that are not and why (a pod that keeps crashing, a node under memory pressure) and when a CronJob last succeeded. It reads only what its access in the cluster allows, which does not include Secrets or logs.
- Agent tokens and heartbeat addresses: the token each agent connects with, which we store only as a one-way hash, and for a heartbeat check the private web address your job calls, with the time and result of each call.
- Maintenance windows, acknowledgements and status pages: the windows you schedule; who acknowledged an outage and when, which everyone on the account sees; and the status pages you publish, which anyone with the address can read unless you give one a password; a page's own domain, if you give it one; and its password, which we store only as a one-way hash. A visitor who gives a page's password is sent a cookie that lets them back in for thirty days, and that cookie is all we keep about them.
- Integrations: if you add a Slack, Discord, Microsoft Teams or webhook integration, the address you give it, which we encrypt before storing, and for a webhook the secret its requests are signed with; which alerts and hosts it is for; and when it last delivered and the last error it met.
The iPhone and Android apps
- Push notification token: if you are signed in and allow notifications, the token that Apple (on iPhone) or Google's Firebase Cloud Messaging (on Android) issues for the app on your phone, with the app version and the version of iOS or Android, so alerts reach the right device. Notifications are the only permission the Android app asks for. The iPhone app also asks to use Face ID if you turn on its app lock; Face ID is handled by your phone, and nothing about it is sent to us.
- Subscription status: when you subscribe through the App Store or Google Play, we store the subscription's status, plan, free-trial end date, renewal date, the price the store reports for the next renewal, and the store's own identifier for the purchase (Apple's transaction identifier or Google's purchase token), so we can confirm your subscription with the store. The store handles payment, and we never see or store your payment details.
- An identifier for your account: when you buy a subscription, the app can give the store a random identifier for your Gryphon account, so that the store's record of the purchase can be matched to the right account. It contains nothing that names you.
If you subscribe on our website instead, Stripe handles the payment (see Service providers). We keep the identifiers Stripe gives your customer record and subscription with your account, so that its notices about renewals and cancellations reach the right account, and what Stripe tells us about the subscription: its plan, its status and its dates.
On iPhone, the app keeps your sign-in details in the Keychain. On Android, it encrypts them with a key held in the phone's Android Keystore, and the app's data is excluded from Google's cloud backups. The Android app uses Google's Firebase only to receive notifications; it does not include Firebase's analytics or any other analytics or advertising tools.
App usage counts
The apps include a demo that lets you try Gryphon on made-up servers before you subscribe. The demo runs entirely on your phone. To learn whether it is useful, the app sends us a short report the first time each of these things happens on an installation of the app:
- the app is opened with nobody signed in;
- the demo is opened, its practice outage is started, the outage is acknowledged, and the outage is seen through to the end;
- a host or a check is added inside the demo;
- a Subscribe button is tapped, in the demo or on the purchase screen;
- a subscription is bought, and which plan it is for;
- you sign in to an account you already had, so that we can leave existing customers out of the figures.
Each report contains the name of the step, the date and time it happened, the app version, whether it is the iPhone or the Android app, and a random identifier that the app creates for itself the first time it is opened. Nothing else is sent. In particular, nothing you type or add in the demo is sent, only the fact that you added something.
We keep these reports separate from accounts on purpose. The random identifier is not your Apple ID or Google account, an advertising identifier, or any identifier belonging to your device. The app never sends it together with your sign-in details, your name, your email address or your subscription, and we store nothing beside it that names you or your account. We use the IP address a report arrives from only to limit how often reports can be sent, and we do not store it with the report. The identifier is kept in the app's own storage on your phone and is removed when you delete the app. If you restore an iPhone from a backup, or move the app to a new phone, the identifier may come with it.
We use these counts only to see how many people open the demo, how far they get, and whether people who open it go on to subscribe. We do not use them for advertising, we do not combine them with information from anyone else, and we do not share them.
IP addresses
When the app or your browser connects to Gryphon, we receive its IP address. We use it to limit repeated attempts to sign in, create accounts and similar requests, and it can appear in our server logs when one of those limits is reached.
When the agent connects, we receive the IP address of the server it runs on. It appears in our server logs, with the host the agent connected for, and we use it to limit repeated attempts with tokens we did not issue. We do not store it with the host or show it in Gryphon.
The website
- Cookies: a session cookie keeps you signed in (for up to 24 hours), and a security cookie protects forms against cross-site request forgery. If you tick "Remember me", a further cookie keeps you signed in for up to a year, or 30 days if you use two-factor sign-in. If you choose to trust a browser when signing in with two-factor, a cookie lets that browser skip the code for 30 days. We do not use advertising or analytics cookies.
We do not collect your location, contacts, photos, advertising identifiers, browsing history, health data or biometrics, and we do not use third-party analytics or tracking tools. The only information we gather about how Gryphon is used is the app usage counts described above.
How we use information
- To run the checks you set up. Our servers connect to the hosts and web addresses you add, and our web checks identify themselves as Gryphon when they do.
- To show you the state of your services on the dashboard and in the app.
- To alert the people on your account, by push notification and email as each of them has chosen, when a service has a problem and when it recovers.
- To sign you in, keep your account secure, and keep each account's information separate from every other account's.
- To confirm your subscription and free trial with Apple, Google or Stripe.
- To diagnose and fix problems with the service.
- To see whether the app's demo helps people decide whether to subscribe, using the app usage counts.
We do not sell your personal information, we do not use it for advertising, and we do not share it except as described below.
Service providers
We use a small number of service providers to run Gryphon. Each receives only what it needs to do its job:
- Apple delivers push notifications to iPhones. Your device token and each notification's content (the host name, the check's name, and its status message, such as "502 Bad Gateway") pass through Apple's push service. Apple also processes App Store purchases and tells us your subscription status.
- Google delivers push notifications to Android phones through Firebase Cloud Messaging. Your device token and each notification's content (the same as for iPhones) pass through it. To issue the token, Firebase creates an identifier for that installation of the app and receives basic information about the app and the phone, such as the app's name and version. Google also processes Google Play purchases: we ask Google about each purchase to confirm it, and Google tells us when a subscription renews, is cancelled or is refunded.
- Stripe processes payments for subscriptions bought on our website. Your card details go directly to Stripe, and we never see or store them. Stripe also receives the account owner's name and email address, and the billing address entered at checkout, which it uses to work out the sales tax due; a business may also give a tax number. Stripe tells us the status of your subscription.
- Mailgun sends our email: alerts, sign-in codes, confirmation and password-reset links, and notices about your account. It receives the recipient's email address and the message.
- Linode hosts our servers and database in Canada, and the servers our check locations run on in other countries.
The app usage counts are stored on our own servers, which Linode hosts, and are not sent to any other service provider.
Integrations you add. When you add an integration, each alert it is for is sent to the address you gave: a Slack, Discord or Microsoft Teams channel, or a system of your own. The alert names the host, the check, its status and its message, links back to Gryphon, and on an acknowledgement says who acknowledged it. These services are not our providers: you choose them, and what they do with an alert is governed by your agreement with them. Removing the integration stops anything more being sent; it does not remove what was already posted.
We may also disclose information where the law requires it.
Data retention
- Check results and events are kept for 90 days, then deleted automatically. Agent readings are kept for 7 days, and an hourly summary of them (how many there were, and their lowest, highest and average) for 90 days. So are the alerts in each person's in-app inbox, and acknowledgements, which go 90 days after the outage they were for has ended.
- App usage counts are kept for 13 months from the day we receive them, then deleted automatically.
- Your account details, hosts, services and settings are kept for as long as your account exists.
- When you delete your account, its information is deleted from our servers immediately.
- Backups are kept for 30 days. Information you delete can remain in a backup until that backup expires, and is then gone for good.
Deleting your account
You can delete your account at any time from the iPhone or Android app, or on the web. If you are an account owner, this deletes the whole account: its people, hosts, services, check history and settings. If you are a member, it deletes your own user record. The information is deleted from our servers immediately and cannot be recovered, except that your name stays on any outage you acknowledged, as the rest of the account saw it, until that history is deleted after 90 days. Copies in our backups expire within 30 days.
Deleting your account does not cancel an App Store or Google Play subscription. The stores manage those, so cancel it in your iPhone's Settings or in the Google Play Store app. A subscription bought on our website through Stripe is cancelled automatically when you delete your account, straight away, and the time left in the current period is not refunded. Stripe keeps its own record of the payments (the name, email address and billing address, and the invoices) for as long as tax and accounting law requires; nothing of it stays in Gryphon. You can also ask us to delete your account by emailing support@gocode.ca.
The app usage counts are not part of your account and are not deleted with it, because we keep nothing that says which of them came from you. They are deleted automatically after 13 months. Deleting the app removes the random identifier from your phone.
Your rights
You may ask to access, export, correct or delete your personal information at any time by emailing support@gocode.ca. Depending on where you live, you may have further rights under laws such as PIPEDA (Canada), the GDPR (EU and UK) or the CCPA (California). We respond to verified requests within 30 days.
The app usage counts are the one exception. Because we do not link them to you or to your account, we have no way to find the ones that came from your phone in order to show, correct or delete them. They are deleted automatically after 13 months.
Children
Gryphon is a tool for businesses and is intended for adults. You must be at least 18, or the age of majority where you live if that is higher, to use it, as our Terms of Service require. We do not knowingly collect information from anyone younger; if we learn that we have, we will delete it.
Security
Connections to Gryphon are encrypted with HTTPS. Passwords are stored as bcrypt hashes, the apps' sign-in tokens are stored on our servers only as hashes, and the credentials for database checks are encrypted. Each account's information is kept separate from every other account's, and repeated sign-in attempts are limited. No system is perfectly secure, but we take reasonable steps to protect your information.
Where your information is stored
Our servers are hosted by Linode in Canada, and that is where your information is stored. If you use Gryphon from outside Canada, your information is transferred to and processed there.
The one exception is our check locations. On the Pro and Teams plans, some checks also run from servers in other countries, which Linode also hosts. Our locations page lists them. To run one of those checks, our server sends the location only what the check needs: the host's name, the address being checked, and the check's settings, which for a database check include its password. This is sent over an encrypted connection. The location runs the check, sends back the result and keeps nothing. It has no database, and it does not store or log the information it was sent.
Apple, Google, Stripe and Mailgun may process information in other countries, including the United States.
Changes to this policy
We may update this policy from time to time. We will tell you about material changes through the app or by email to the address on your account. The "Last updated" date at the top shows when it last changed.
Contact
GoCode.ca
Questions or requests: support@gocode.ca