Privacy Policy
Effective date: July 18, 2026 — Version 1.0
PulseWatch ("we", "us") is a cron job and uptime monitoring service. This policy explains what data we collect, why we collect it, and what we do with it — in plain English, because you have better things to read.
Data we collect
Account data. When you sign up we store your email address. If you sign in with Google or GitHub (through Supabase Auth), we also receive the basic profile those providers share, such as your name and avatar. We never see your passwords for those providers.
Monitoring configuration. The monitors you create: names, the URLs you ask us to check, schedules, grace windows, and status-page settings. Don't put secrets or personal data in monitor names — they appear in alerts and, if you enable it, on your public status page.
Operational data. For heartbeat monitors we record ping timestamps, the source IP address and user agent of each ping. For uptime monitors we record check results: timestamps, HTTP status codes, response latency, and error messages. We keep daily uptime aggregates to draw history bars.
Alert channels. The email addresses you add for alerts, Telegram chat IDs when you connect the Telegram bot, and webhook URLs you configure. Alert deliveries are logged (recipient, subject, outcome) so you and we can debug missed alerts.
Payments. Payments are processed by Lemon Squeezy as merchant of record. We never see or store your card number. We store your subscription status, plan, and Lemon Squeezy customer and subscription identifiers.
Emails. Emails we send you (alerts, test emails) go through our email providers and we log that they were sent and whether delivery was accepted.
What we do NOT collect
No advertising trackers, no analytics scripts, no session recording. The only cookies we set are the authentication cookies required to keep you signed in. We do not sell personal data — to anyone, for anything.
How we use data
- To run the service: schedule checks, receive pings, detect downtime, and deliver alerts.
- To bill paid plans through Lemon Squeezy.
- To secure the service: rate limiting and abuse prevention use source IPs.
- To help you debug: ping and check history is shown in your dashboard.
Who processes data for us
We use a small set of subprocessors to run PulseWatch:
- Supabase — database and authentication
- Railway — API server and monitoring worker
- Vercel — web application hosting
- Lemon Squeezy — payments (merchant of record)
- Resend and Google (Gmail API) — outbound email delivery
- Telegram — alert delivery, only if you connect a Telegram chat
Each processes only the data needed for its role.
Retention and deletion
Deleting your account (Settings → Delete account) permanently removes your profile, monitors, channels, history, and subscription record from our database. Operational logs (pings, check results, alert logs) exist to power your dashboards and are pruned as they age out of their retention windows. Backups held by our database provider expire on their standard schedule.
Your rights
You can access and correct your data in the dashboard, export what you see, and delete your account yourself at any time. For anything else — access requests, corrections, complaints — email pulsewatch.dev@gmail.com and we will respond within 30 days. Depending on where you live (e.g. the EU/EEA or UK), you may have additional statutory rights; we honor them.
Children
PulseWatch is not directed at children under 16, and we do not knowingly collect their data.
Changes
If we change this policy in a way that matters, we will note the new effective date here and notify you by email or an in-app notice before the change takes effect.
Contact
Questions about privacy: pulsewatch.dev@gmail.com