Trust and privacy
What we store, where it lives, how long it stays, and what this site deliberately cannot do. Written to be checked rather than trusted.
No tracking, because there is nothing to track with
This site ships zero JavaScript. The security policy on every page says script-src 'none', which means no analytics, no tag manager, no session recorder, no A/B testing script and no third-party pixel can run here even if someone tried to add one. There is no cookie banner because there are no tracking cookies to consent to.
The only cookies are the ones that make signing in work: a session cookie, a short-lived cookie that ties a login code to the browser that asked for it, and your selected organisation. All are __Host- prefixed, Secure, HttpOnly and SameSite-restricted.
What we store about you
- Your email address. That is the whole account. There are no passwords to leak, because there are no passwords — signing in is a link or a six-digit code sent to that address.
- Sessions. Stored as a SHA-256 hash of a random token, never the token itself, together with the user agent and IP of the browser that signed in — so you can see and revoke your own sessions. A stolen copy of our database yields no usable logins.
- Your monitors and their results. URLs, settings, status codes, response times, and an excerpt of the response body when a check fails — because when something breaks, what the server actually said is the entire explanation.
Two things are stored in a form we can read, and you should know which: HTTP basic auth passwords and custom request headers. They have to be sent on the outgoing request, so they cannot be one-way hashed. Do not put a credential there that would hurt if it leaked, and prefer a token scoped to reading one health endpoint.
Where it lives
Accounts, monitors and results are stored in a Cloudflare D1 database in the Eastern Europe region, inside the EU. Checks themselves are made from the region you pick per monitor, which may be outside the EU if you choose the US or Australia — that request contains your monitor's URL and headers and nothing about you.
Outgoing email is sent through Cloudflare's email service from email.pingdomain.io. We are a data processor for what you put into monitors, and a controller for your account itself.
How long it is kept
Check history is pruned automatically every night — we do not keep results forever, because storing five hundred thousand rows per monitor per year to answer questions nobody asks is a cost with no reader. Expired sessions and used login tokens are removed on the same schedule.
Delete a monitor and its entire history goes with it, immediately and by database constraint rather than by a cleanup job that might not run. Ask us to close your account and everything follows the same path.
GDPR, in plain words
- Access and portability. Everything we hold about you is visible in the interface. Ask and we will export it.
- Erasure. Write to us and the account, its organisations and their monitors are deleted. There is no thirty-day limbo.
- Sub-processors. Cloudflare, for compute, storage and email. That is the list.
- A data processing agreement is available on request. If you need one signed before you can start, say so.
How the service treats other people's sites
We check one URL at a time, at the interval the person who set it up asked for. We do not crawl, we do not follow links, and we never fetch anything a monitor was not pointed at. For addresses discovered from a sitemap, robots.txt is obeyed.
Our requests are identifiable on purpose and we will not work around a block — a 403 is a clear answer and we report it as one. The bot page explains how to verify a request really came from us, and how to stop us if the checks are unwanted.
Security posture
- HSTS, a strict content security policy, and framing denied on every response.
- Ownership is re-checked on every lookup, and a monitor belonging to someone else answers 404 rather than 403 — the difference between the two is itself a way to count what exists.
- The login page answers identically for a known and an unknown address, so it cannot be used to find out who has an account here.
- Rate limits on login requests, both per address and per IP.
Found something wrong? Write to security@pingdomain.io. We would rather hear it from you.
Try it without handing over anything
No card, no phone number, no sales call. An email address, and three monitors that stay free.
Get started — free