Privacy Policy
What we store and why
Last updated 18 September 2026. Short version: we keep what the product needs to work, nothing for advertising, and you can delete all of it.
What we collect
- Account: your email address and a bcrypt hash of your password. We never see or store the plain password.
- Monitors: the URLs, CSS selectors, ignore patterns, intervals, and webhook URLs you configure.
- Snapshots: for each notable event (first fetch, change, down, recovery) the extracted visible text of the public page, compressed, plus a text diff and the HTTP status. This is what powers the “what changed” view. Unchanged polls are not stored.
- Billing: your Creem customer id and subscription status. Card details never touch our servers — Creem is the merchant of record.
- Product events: coarse breadcrumbs such as “signed up”, “created first monitor”, “started checkout”, with a timestamp, so we can see where the sign-up flow breaks.
- Server logs: our reverse proxy logs request paths, status codes and IP addresses for security and debugging. Logs rotate automatically.
What we do not do
- No third-party analytics or advertising scripts. The site loads fonts from Google Fonts and nothing else from third parties.
- We do not sell, rent or share your data with anyone except the processors below.
- We do not fetch pages that require a login, and we do not store cookies from the sites you monitor.
Processors we rely on
- Creem (payments, tax, invoices) — receives your email and what you bought.
- Resend (transactional and alert email) — receives your email address and the content of alerts we send you.
- Cloudflare (DNS, TLS, DDoS protection) — sees request metadata in transit.
- Our own server, hosted in a data centre in Salt Lake City, United States.
Retention
Snapshots are deleted after 45 days (we keep the single most recent one per monitor so diffs keep working). Monitors and their history are deleted immediately when you delete them. Accounts and everything attached are deleted when you ask us to close the account. Backups roll off within 14 days.
Your rights
You can export or delete your data, or ask what we hold, by emailing [email protected] from your account address. We answer within a few days. If you are in the UK or EU you also have the right to complain to your data protection authority.
Security
All traffic is HTTPS. Sessions use HttpOnly, Secure cookies. API keys are random 256-bit tokens you can rotate. Outbound webhooks are HMAC-signed so your receiver can verify they came from us. The monitoring worker refuses to fetch private or internal addresses.
Changes
If this policy changes materially we will email account holders. The date at the top always reflects the current version.