Privacy Policy
Last updated
This policy explains what personal data Website Monitor collects, why, who it is shared with and what control you have. It describes how the application actually works, including the places where it stores your information.
Who we are
Website Monitor is operated by DevCraftKit. For the purposes of data protection law, DevCraftKit is the controller of the personal data described here.
Content you monitor or publish belongs to you. For the monitoring data and status page content of your organization, we act on your instructions.
What we collect
Account information
Your name, email address and time zone, and a hash of your password (we never store the password itself). If you delete your account we remove this information as described below.
Sign-in sessions
When you sign in we create a session. We store a hash of the session token, when it was created and when it expires, the IP address it was created from and your browser's user agent. You can see your active sessions and sign out of any of them in Settings.
Monitor and status page configuration
The monitors you create (name, URL, check settings, tags, descriptions), your organization's name, and any status pages you configure, including titles, descriptions, logo and website addresses, and the text you write. Status pages you make public can be read by anyone with the link.
Monitoring data
For each check: the time, whether it passed, the HTTP status code, response time and size, any error code or message, and the SSL certificate's issuer, validity dates and days remaining. We record the size of a response, not its content. We also store incidents, their updates and the audit trail of actions taken in your organization (such as creating a monitor), with the acting user.
Notification information
Email addresses and webhook URLs you add as notification channels, webhook signing secrets (stored encrypted), and a record of each notification: what it was about, whether it was delivered and any coarse failure reason. If you add someone else's email address, make sure you are entitled to.
API keys
We store a hash of each API key and its first few characters so you can recognise it. The full key is shown once, when you create it.
Free uptime checker
If you use the public checker, the address you enter is requested once and the result is returned to you. It is not saved to a database. Your IP address is used to limit how often the tool can be used.
Technical and log data
Like most web services, our servers and hosting infrastructure process technical request data such as IP address, user agent, requested address and errors in order to deliver the site, keep it secure and diagnose problems. IP addresses are also held temporarily in memory to rate-limit sign-in, sign-up and tool requests.
What we do not collect
This website does not use analytics, advertising or tracking tools, and does not profile visitors. If that changes, this policy and the Cookie Policy will be updated first.
How we use it
- To provide the service: run your checks, detect incidents, send notifications and publish status pages.
- To secure accounts and the service, including preventing abuse and misuse of the monitoring system.
- To send service emails such as alerts, password resets and test messages. We do not send marketing email.
- To respond to support, privacy and security requests.
- To meet legal obligations and to establish or defend legal claims.
Our legal bases are performing our contract with you, our legitimate interests in running and securing the service, and compliance with the law.
How long we keep it
- Account, organization, monitors, incidents, status pages and notification settings: until you delete them or your account.
- Raw check results: 90 days by default, after which they are removed by a scheduled job.
- Sign-in sessions: until they expire (14 days after sign-in by default) or you sign out or revoke them.
- Password-reset links: single use and short-lived.
- Technical logs: for a limited period needed for security and diagnostics.
Copies in infrastructure backups, if any, are removed when those backups rotate. We may keep limited information longer where the law requires it or to resolve a dispute.
How we protect it
Passwords, session tokens and API keys are stored as hashes, webhook secrets are encrypted, the session cookie is HttpOnly, access to your organization's data is checked on the server for every request, and outbound monitoring requests are restricted to public addresses. Read more on the Security page. No system is perfectly secure; if we learn of a breach affecting you, we will notify you as the law requires.
International transfers
We and our providers may process data in countries other than the one you live in. Where the law requires a safeguard for a transfer out of the EEA, the UK or Switzerland, we use one that it recognises. Ask us at the address below for details of the mechanism that applies to you.
Your rights
Depending on where you live (for example under the GDPR, the UK GDPR or California law) you may have the right to access your data, correct it, delete it, restrict or object to its processing, receive a portable copy, and withdraw consent where we rely on it. You can edit your profile, organization and notification settings yourself in Settings. For anything else, contact us. We may need to verify your identity first, and we will answer within the time the law allows.
You also have the right to complain to your local data protection authority.
Deleting your account
You can delete your account in Settings by confirming your password. Organizations that only you belong to are deleted with it, including their monitors, check history, incidents, status pages (which stop working immediately), notification channels and API keys. If an organization has other members, it is kept and only your membership and personal data are removed. Your sessions end and the sign-in cookie is cleared.
Children
Website Monitor is for businesses and developers and is not directed to children under 16. We do not knowingly collect their data; contact us if you believe a child has created an account.
Changes to this policy
When we change this policy we update the date at the top. If a change materially affects how we use your data, we will give notice in the service or by email before it takes effect.
Contact
For privacy questions and requests, contact (this deployment has not configured a contact address yet). For other help, see Support and contact.