Privacy policy

Last updated: 13 September 2026

DRAFT — not yet reviewed by a lawyer. The factual parts below (what is stored, where, and how it is protected) describe what the software actually does as built on 13 September 2026. The legal framing needs review, and the owner must fill in the controller's legal name and address, the contact address, the ICO registration if one is required, and the retention periods. Every [ ] is a blank only the owner can fill.

Who is the controller

[legal name of the operator] of [registered or trading address], contactable at [privacy contact email].

What we store

Account
Your email address, a hashed password (Argon2 — we cannot read it back), whether the email has been verified, a random internal identifier, and if you turn it on, your two-factor secret.
Billing
Your Stripe customer and subscription identifiers, your plan, its status and the renewal date. Card details are held by Stripe and never reach our servers.
Configuration
The Discord webhook URLs, proxy lists or gateway credentials, and captcha provider keys that you add. These are encrypted at rest with a key held only on the server, are shown back to you only as a hint (a channel id, a last-four), and are decrypted only into the environment of your own monitor's process.
Monitors
The event URLs you watch, your settings for them, counters (polls, finds, blocks), and the recent run log for each monitor. Logs are redacted before they are written and again before they are shown.
Security records
An audit trail of sign-ins, two-factor changes, and credential and monitor changes, with the IP address the request came from.

What we do not store

  • Card numbers, expiry dates or security codes.
  • Any ticketing-site account of yours. The service never signs in as you.
  • Third-party analytics or advertising identifiers. There are no tracking cookies on this site; the only cookies are the ones that keep you signed in and protect forms against cross-site posting.

Why we store it, and on what basis

  • To provide the service you asked for (performance of a contract): account, configuration, monitors.
  • To take payment (contract, and legal obligation for tax records): billing identifiers and invoices.
  • To keep the service secure (legitimate interests): the audit trail, rate-limit counters and server logs.
  • To send service email (contract): verification, password reset, billing and pause notices. We do not send marketing email.

Who it is shared with

  • Stripe — payments and the billing portal.
  • Resend — delivery of the service emails above.
  • Cloudflare — sits in front of the site and filters abusive traffic.
  • Discord — receives the alert cards, because that is what a webhook is.
  • A captcha-solving provider, when your monitors use Firm credits. It is sent the challenge, not your identity, and no account or billing detail of yours.

We do not sell personal data and we do not share it for advertising.

Where it is held

On a server in [hosting region, owner to confirm], in a Postgres database that is backed up nightly. Our processors above may process data outside the UK under their own safeguards.

How long we keep it

  • Monitor logs: [7 days by default — owner to confirm].
  • Heartbeat samples: [24 hours by default].
  • Account, configuration and audit records: while your account exists, then [retention period, owner to choose].
  • Invoices and payment records: as long as tax law requires.

Your rights

You can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to a use of it. Write to [privacy contact email] and we will answer within one month. If you are not satisfied you can complain to the Information Commissioner's Office at ico.org.uk.

You can delete most of it yourself: removing a webhook, proxy or key deletes the encrypted row, and deleting a monitor deletes its configuration and history.

Changes

If this policy changes materially we will email account holders before the change takes effect.

Terms of service