Privacy policy

What SquidGrid collects, why, how long we keep it, and what we deliberately never collect.

Last updated 23 August 2026

Who we are

SquidGrid is a network monitoring service operated from Texas, United States. For any question about this policy or about data we hold, write to [email protected]. We answer privacy requests from that address and nowhere else, so it does not get lost behind sales mail.

What we collect

Account information

Your email address, the name of your organisation, and which people belong to it. Sign-in is handled by a third-party authentication provider; we never see or store your password. We keep a record of sessions so you can be signed out of a device you no longer control.

Measurement data

This is the service. For each destination you choose, we record round-trip time, packet loss, and the sequence of router addresses your packets crossed to get there. We also record which of your probes made each measurement, the version it is running, and the city you told it that it lives in.

Website information

Standard server logs: IP address, the page requested, and the time. We do not run advertising or third-party analytics, and we do not set tracking cookies. The only cookie we set is your sign-in session.

What we deliberately do not collect

We do not read your traffic, and we cannot.

The probe measures its own packets and the ICMP responses they provoke. It has no capability to capture, inspect or store your network traffic — this is a property of how it is built, not a policy we promise to follow. The image is public at squidgrid/probe and you are welcome to verify it.

Why we hold it

To provide the service you asked for — measuring the destinations you chose and showing you the results — and to keep the service running and secure. Where the GDPR applies, our basis is performance of a contract for account and measurement data, and legitimate interests for security logging.

How long we keep it

DataRetained
Latency and loss samples30 days at full resolution
Hourly summaries400 days
Incident evidence180 days
Path and hop records180 days
Account and organisation recordsUntil you close the account

Path and hop records are kept for 180 days, so a route today can be compared against the same route months back. If you want yours deleted sooner, ask and we will delete them.

Who else touches it

We use a small number of third-party providers to run the service — for authentication, hosting, network ingress, and email. They process data on our behalf and for no other purpose. A current list of our named sub-processors is available to customers on request, and we notify customers before adding a new one so they can object.

We do not sell personal information, and we do not share it for advertising. We have never received a government request for customer data; if that changes we will tell affected customers unless we are legally prohibited from doing so.

Your rights

Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. If the GDPR or the CCPA applies to you, you additionally have the rights those laws grant, including the right to object to processing and the right not to be discriminated against for exercising them. Write to [email protected] and we will respond within 30 days.

Where data is held

Our service and database run in Europe; our probes run in several countries. Measurement data therefore crosses borders by design — that is what measuring international paths means.

Changes

If we change this policy in a way that materially affects you, we will tell account holders by email before it takes effect rather than quietly changing the date at the top.