Privacy policy

How Statix handles personal data in Tars, our internal monitoring and on-call tool, on the web at tars.statix.io and in the Tars app for Android.

Last updated 24 September 2026

1. At a glance

Only people with a Statix single sign-on account can use Tars: our staff and contractors, and one read-only account for Google Play's app review. There is no public sign-up, no advertising, no analytics and no tracking. Tars processes the personal data it needs to sign you in, to alert you about incidents on your phone, and to record who handled an incident.

2. Who is responsible

Statix Online UG (haftungsbeschränkt)
Suhrenkamp 22B
22335 Hamburg, Germany
Phone: +49 40 468970790
Email: support@statix.io

3. What Tars processes and why

Your account

You sign in through the Statix single sign-on (Authentik), which we operate ourselves. Tars then receives and stores your name, email address, profile picture, account ID and group memberships. The groups decide whether you may use Tars and whether you may change things or only read them.

Sign-in sessions

Each session on the web or in the app stores a random token, when it started and was last used, and the IP address and browser or device name it signed in from. A session ends when you sign out, or 14 days after it was last used. While the app is signed in it renews its session once a day, so that alerts keep reaching you on days you don't open it.

Your phone

To receive push notifications, the Android app registers with Firebase Cloud Messaging (see section 4) and sends Tars the phone's Firebase installation ID, its model name, for example "Google Pixel 9", and the app version. This registration belongs to the app's session and is deleted with it.

What you do in Tars

Acknowledging or resolving an incident, comments, silences and changes to settings are stored with your name and the time, so the team can see who handled what.

Server logs

Our hosting provider and Tars write technical logs of requests: time, address, status and, at the hosting provider, the IP address. We use them to run Tars and keep it secure. They are deleted automatically after the hosting provider's retention period.

On the phone itself

The app stores the following in its private storage on the phone: the session token, encrypted with a key that stays in the Android Keystore; the IDs of recent notifications, so a duplicate doesn't ring twice; and your alert settings. Android's backup is turned off for the app, so none of this leaves the phone, and uninstalling the app removes it.

The app does not access your location, contacts, photos, files, camera or microphone. It contains no advertising, analytics or crash reporting libraries.

4. Push notifications through Google Firebase

Alerts reach the Android app through Firebase Cloud Messaging, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A push contains the incident's title, severity, monitor name and a short status text, and after an acknowledgement the name of the person who acknowledged. Google delivers it to your phone and may process it on servers outside the EU, including in the USA. Google LLC is certified under the EU-US Data Privacy Framework. Google processes this data on our behalf under the Firebase data processing terms. More in Firebase's privacy information.

5. Hosting

Tars runs on Railway, a service of Railway Corporation, San Francisco, USA. The servers and the database, including its backups, are in Railway's EU region in the Netherlands. We have a data processing agreement with Railway, so it processes this data only on our instructions and in line with the GDPR. More in Railway's privacy policy.

6. Other recipients

Incident notifications can also go to a chat room on the Matrix server that Statix operates itself. Google Play distributes the app; Google processes the data needed for that under its own privacy policy. We don't sell personal data or share it for advertising.

7. Legal basis

We process this data under Art. 6 (1) (b) GDPR where using Tars and being on call is part of your employment or service contract with Statix, and otherwise under Art. 6 (1) (f) GDPR. Our legitimate interests are to run our services reliably, to fix outages quickly, to keep Tars secure and to record who handled an incident.

8. How long we keep data

  • Your account stays while you have access to Tars. We delete it on request or when you leave Statix.
  • Sessions end at sign-out or 14 days after their last use. The phone's push registration is deleted with its session.
  • Check results and the log of sent notifications are deleted after 90 days.
  • Incidents, comments and the audit log stay as long as we need the incident history to run our services. When an account is deleted, acknowledgements and audit entries lose the link to it; comments keep the name they were written under.
  • Database backups are replaced on Railway's backup schedule.

9. Your rights

You have the right to access the personal data we hold about you, to have it corrected or deleted, to restrict its processing, to receive it in a machine-readable format, and to object to processing based on Art. 6 (1) (f) GDPR on grounds relating to your particular situation. Write to support@statix.io.

You can also complain to a data protection authority. Ours is the Hamburg Commissioner for Data Protection and Freedom of Information (HmbBfDI).

10. Deleting your account and data

Tars accounts come from the Statix single sign-on and can't be created or deleted in the app. To have your Tars account and the data linked to it deleted, email support@statix.io from the address on the account. We delete it within 30 days and confirm by email.

Signing out in the app ends its session on the server at once, and with it the phone's push registration. Uninstalling the app deletes everything it stored on the phone.

11. Security

All connections to Tars are encrypted with TLS. Only accounts in the Statix single sign-on can sign in, and read-only accounts can't change anything.

12. Changes

We update this policy when Tars changes what it processes. The date at the top shows the latest version.

Statix Online UG (haftungsbeschränkt). Imprint