Privacy notice
Detections stores the least it can and still be an account you own. This page describes what is actually recorded, how long it is kept, who else processes it, and what deleting an account does and does not remove. It describes the system as it runs today rather than what it intends to do.
- Last updated
- 25 August 2026
- Applies to
- The Detections service at detections.app
1. What this notice covers
This notice applies to the Detections service at detections.app: the public catalogue, the workspace that comes with an account, and the mail the service sends you. Throughout, “the service” means that and nothing wider.
It does not apply to the public repositories the catalogue draws from. Those are run by other projects, under their own terms, and reading a rule here is not the same act as visiting the project it came from. It does not apply to any other site you reach by following a link out of this one.
The three sections that follow describe what is collected, split by where it comes from: what you give the service, what the service records because you used it, and what reaches it from public sources without anyone having signed up.
2. Information you provide
Your account. The name you chose, the email address you signed up with, whether that address has been confirmed, an optional picture, and the dates the record was created and last changed. Your display name is shown wherever your work appears; your address is not.
Your credentials. Detections runs its own identity provider rather than delegating to an external one, so your password and any tokens from a social sign-in are held in this system rather than with a third party. Passwords are not stored in plaintext: what is stored is a hash used to verify a sign-in. If you add a second factor, the information needed to verify it and the recovery material that goes with it are stored protected, together with a count of failed attempts so the factor can be locked after repeated failures.
Your workspace. Detection content you write is private to your workspace until you share or contribute it. Every save creates a version, so the history of a rule is kept rather than overwritten — including drafts and versions you never published, which remain part of the workspace's history for as long as the workspace does.
What you contribute. When you contribute a rule to the public catalogue, the licence you chose, the attribution you asked for and your confirmation that you were entitled to contribute it are recorded with it. What that means for ownership is on content and licensing.
3. Information collected as you use it
Sessions. A session records when it was opened, when it was last renewed, when it expires, and whether it ever presented a second factor. You can see every session your account has open and end any of them from your profile, and changing your password ends all the others at once. Detections does not derive a device fingerprint or a location history from account sessions, which is why the sessions screen shows you times and assurance rather than a city and a browser.
Security and abuse-prevention records. Signing in, signing out, requesting a confirmation or recovery mail, changing a password and answering a second-factor challenge are each recorded as an event, as are actions that change something inside the product. An event carries what happened, the account it concerns, the outcome, and when. These records are designed not to contain passwords, authentication tokens, API keys or credentials for external services.
Two kinds of record are kept and they differ in one respect worth stating. Authentication records carry no network address at all, and the field is left empty deliberately: the address the service observes identifies the network path a request travelled rather than the person who made it, and recording it as though it identified somebody would be worse than recording nothing. Records of actions taken inside the product can carry the address the request arrived from. Where an address is used to count repeated sign-in attempts, it is hashed before it leaves the process that received it.
Where you came from. If you reach the sign-up page through a shared link, the campaign parameters on that address — the platform, the channel and the campaign name — are read from it so we could tell which links bring people here. No account created today carries any: the step that would record them does not currently run, so nothing is kept. Should that change, it changes on this page first.
Either way, nothing else about the visit is kept: no address, no referrer, no browser or device details. There is no cookie behind this and nothing follows you between visits.
4. Information that arrives from public sources
This is the one category that concerns people who never created an account. Detection content in the catalogue comes from public repositories, and most of it carries the name its author signed it with. That name is published beside the rule where the licence covering the material calls for attribution. A rule whose document carries no signature is shown without an author rather than credited to whoever hosts the repository — Detections does not guess one, and does not merge two people because their names match.
Where a document signs with an address rather than a name alone, that address is stored with the record. It is never published: the projection the public pages read carries the display name and the organisation and does not carry the address.
If a name here is yours, write to contacto@detections.app and how it appears can be corrected, or the page that gathers your work withdrawn — that page is kept out of search engines for this reason. What can and cannot be changed about an attribution, and why the answer depends on the licence rather than on a rule of ours, is on content and licensing.
5. How this information is used
- Operating your account and the workspace that comes with it.
- Verifying a sign-in, and a second factor if you added one.
- Sending the transactional mail that confirms an address or recovers a password.
- Keeping the service secure, rate-limiting abuse of it, and investigating a security incident if one happens.
- Publishing the catalogue with the provenance and attribution each rule arrived with.
- Understanding which shared links bring people here.
6. What it is not used for
Detections does not use account information for behavioural advertising, does not sell it, and does not track you across other sites. There is no analytics cookie, no tracking pixel and no third-party script — the pages this site serves declare a policy that permits scripts only from this origin, so a third-party tag would not execute even if one were added by mistake.
Two things are worth separating rather than collapsing into a single promise. Detections does not operate behavioural analytics and does not build a browsing profile for visitors who never create an account. Its infrastructure providers do process the network and request metadata necessary to deliver and secure the service, in the ordinary way that serving a website requires.
No credentials for your own detection tooling ever reach this system. Detections reads rules from public repositories and works on the text you give it; it does not connect to your SIEM and has nowhere to put a credential for one.
8. Where it is processed
Every one of those providers is established in the United States, so the information necessary to operate the service is processed there rather than where you are. Detections does not currently offer a choice of processing region, and does not claim one.
9. How long it is kept
How long each kind of record is kept, rather than a single number that would be wrong for most of them:
- Account profile
- While the account exists, then as described below.
- Sessions
- Until they expire or you revoke them.
- Second-factor material
- Until the factor is removed or the account is deleted.
- Security and audit evidence
- Three years as currently configured. It is an operational setting an administrator can move between one and ten years, and shortening it destroys evidence on the next housekeeping pass.
- Campaign attribution
- At most two years, and deleted with the account before that if you delete it sooner.
- Workspace content
- For as long as the workspace exists.
- Published contributions
- Under the licence they were published beneath, which is a question about the content rather than about your account.
10. Deleting your account
You can schedule deletion from your profile. It does not happen immediately: there is a grace period during which nothing has been destroyed and you can cancel. When it executes, your sessions, your second factor and its backup codes, and your stored credentials are deleted outright.
The account record itself is not removed. Its address is replaced with one that cannot receive mail and its display name is emptied, which is de-identification rather than anonymisation — the record keeps its identifier, because the append-only security evidence above refers to it and removing the row would leave those records pointing at nothing. Calling that anonymisation would claim an irreversibility it does not have. Detection content you already contributed to the public catalogue stays published under the licence it was contributed under.
11. Keeping it secure
The controls this service is built with — the trust boundaries between its planes, the isolation between workspaces, and the audit evidence that mutating operations leave behind — are described on security, along with how to report a vulnerability. Those are architectural properties rather than a certification, and no set of them makes a service impossible to breach; the honest statement is what is in place, which is why it is written down where it can be checked.
12. Your rights and choices
Most of what you might want, you can do yourself: reviewing and ending sessions, changing your password, adding or removing a second factor, and scheduling deletion are all in your profile. For the rest — asking what is held about you, asking for it in a portable form, asking for a correction — write to us and a person will answer. There is no self-service export today, and this page does not pretend otherwise.
Two limits are worth stating plainly rather than discovering later. Security evidence is append-only, so a record that a sign-in happened is not removed on request; it is what makes the trail worth keeping, and it is de-identified with the account rather than erased. And an attribution that the licence covering the material requires is not removed on request either — what can change is how the name appears and whether the page collecting your work exists.
13. Reaching us
For a question about what is held, a correction, or a request this page does not cover, write to contacto@detections.app. A problem with content, attribution or a licence in the catalogue goes to the same address, and content and licensing says what to include so it can be acted on.
This notice describes engineering behaviour rather than making legal claims, and it does not claim compliance with any particular framework or certification. Where that matters to you, treat what is written here as an accurate description of the system and the absence of the rest as exactly that — an absence, not an implication.
14. Changes to this notice
This notice changes when the system does. The version on this page is always the current one and carries the date it last changed, shown at the top.
If a change means Detections starts collecting something it did not collect before, that is a change to this page and not a footnote elsewhere.