⌁ Checkpulse

Privacy Policy

Draft for review. Last updated October 4, 2026. This policy has not yet been reviewed by a lawyer and may change before Checkpulse opens to the public.

This policy explains what personal data Checkpulse ("we", "us") collects when you use Checkpulse, why, and the choices you have. Contact us at [contact email not yet configured].

What we collect

Account information. Your name, email address, a salted hash of your password, your two-factor secret if you enable it, and when you signed up and last signed in.

Content you provide. Project and check names, descriptions, runbooks, tags, alert channel destinations (such as email addresses and webhook URLs) and their credentials, incident notes, and the names of API keys.

Data your jobs send. Ping times, signals, exit statuses, run IDs, durations, request methods, and up to 4 KB of output per ping. We do not need personal data in ping output; avoid sending it.

Usage and security data. Counts of pings, alerts, emails, and API requests per account per day; an audit log of changes in each project; and, to limit abuse, sign-in attempt counters keyed by a one-way hash of your email address and of your IP address. Our hosting provider records request logs, including IP addresses, for operating and securing the service.

Cookies and local storage. A session cookie that keeps you signed in, a short-lived cookie that protects forms against cross-site requests, and a light or dark theme preference stored in your browser. We do not use advertising or third-party analytics cookies.

How we use it

  • To provide the service: run checks, record pings, deliver alerts and account emails (confirmation, password reset, invitations), and show your history.
  • To secure the service: authenticate you, enforce limits, prevent abuse, and investigate problems.
  • To operate and improve the service using aggregate statistics.
  • To contact you about your account or important changes.

We do not sell personal data or use it for advertising.

Who can see it

  • Members of your projects see that project's data according to their role.
  • Alert destinations you configure receive alerts, which can include check details and, for email and webhooks, the last ping output.
  • Administrators use an admin console that shows account details (name, email, status, sign-in times) and usage counts. It is technically prevented from showing projects, checks, pings, or alert destinations. People with direct access to the production database could access all data; we limit this to operating the service, investigating abuse or security issues, and complying with the law.
  • Service providers process data on our behalf: our hosting provider (Railway) and our email delivery provider [to be confirmed]. They may process data outside your country.
  • Authorities, when required by law.

How long we keep it

DataRetention
Ping historyThe most recent events per check, up to your account's history limit.
Delivered alerts and account emails30 days.
Incidents, audit logs, usage countsAbout 400 days.
Deleted checks7 days, so they can be restored.
Account dataUntil you delete your account.

Backups may keep data for a short additional period.

Your choices and rights

  • Access and export: download your data as JSON from your account page.
  • Correction: change your name and password in your account; edit your projects at any time.
  • Deletion: delete your account from your account page. Projects you created are deleted unless another owner can take them over.
  • Depending on where you live, you may have further rights, such as objecting to processing or complaining to a data protection authority. Contact us to exercise them.

Security

We hash passwords, store API keys and session tokens only as hashes, support two-factor sign-in, restrict webhook destinations, encrypt connections with HTTPS, and limit administrator access as described above. No system is perfectly secure; tell us at [contact email not yet configured] if you find a vulnerability.

Children

Checkpulse is not intended for children under 16, and we do not knowingly collect their data.

Changes

We will post updates here and notify account holders of material changes.