ping·dan
Legal

Privacy Policy

What we collect, why we collect it, who else sees it, and how long we keep it — in plain English, with no clauses designed to be skipped.

Last updated 2 August 2026

Before publishing: replace the bracketed fields below with your registered company details. GDPR Article 13 requires the controller to be identifiable, so this policy is not complete until they are filled in.

Who we are

pingdan is an uptime and API monitoring service operated by [LEGAL COMPANY NAME], a company registered in [COUNTRY] under company number [REGISTRATION NUMBER], with its registered office at [REGISTERED ADDRESS]. In this policy, “we” and “us” mean that company. We are the data controller for the personal data described here.

For anything privacy-related, email [email protected].

The short version

  • We collect what we need to run your monitors and tell you when they fail.
  • We do not sell your data, and we do not use it for advertising.
  • Analytics cookies are only set if you accept them. Declining changes nothing else.
  • pingdan is free, so we never handle payment or card details.
  • Nothing expires on a timer, and nothing lingers after you delete it — removing a monitor takes its full check history with it, immediately.

What we collect

Account data

Your email address, and — if you sign in with Google or GitHub — the name and avatar URL those providers return, along with the provider's account identifier. If you register with a password instead, we store a bcrypt hash of it. We never store your password in a readable form and cannot recover it for you.

Monitor configuration

Everything you enter when setting up a check: the name, the URL or host, the HTTP method, the check interval and timeout, the failure threshold, and the assertions you define. If you point a monitor at a URL that contains an API key or token, that value is stored as part of the monitor.

Check results

For every check we run we store the status code, the response time in milliseconds, whether it passed, any connection error message, and the time it ran.

One thing worth knowing: when an assertion fails, we store the actual value it compared against so you can see why. For a body or JSON-path assertion, that value is taken from the response your endpoint returned. If you assert on an endpoint that returns personal data, that data can end up in your failure history. Point monitors at dedicated health endpoints where you can, and keep assertions narrow. Deleting the monitor clears that history immediately.

Alert channels

Whatever a channel needs in order to reach you: an email address, a Telegram chat ID, a phone number, a Slack, Discord, Teams or custom webhook URL, a PagerDuty or Opsgenie key, an ntfy topic, or a Pushover key. These are credentials — treat the ones you paste in the same way you would treat any other secret.

Status pages

If you publish a status page, its slug, title, description and the monitors you add to it are visible to anyone with the link. That is the point of a status page, but it does mean you choose what goes on it.

Technical data

Our servers keep short-lived logs containing IP addresses and request metadata. We use them to keep the service running and to investigate abuse, nothing else.

Cookies and analytics

We use Google Analytics 4 to understand how the site is used. It runs in Google's Consent Mode with every storage category denied by default, so no analytics cookie is set on your first visit. Nothing is stored on your device for analytics unless you press Accept on the cookie banner.

You can change your mind at any time — reopens the banner, and declining is as easy as accepting.

Separately, when you sign in we store a session token in your browser's local storage. This is not an analytics cookie and is not optional: without it you would be signed out on every page load. Signing out removes it.

Who we share data with

We do not sell personal data. We share it only with the providers below, and only the parts they need to do their job. Providers are used only where you have configured the relevant feature.

ProviderWhat it receivesWhy
ResendRecipient email address and the contents of the messageSends account email (verification, password reset) and email alerts
TelegramThe chat ID you configure and the alert textDelivers Telegram alerts
TwilioThe phone number you configure and the alert textDelivers SMS alerts
PushoverThe user or device key you configure and the alert textDelivers push alerts
GoogleYour email address, name and avatar URL, returned to us after you approve sign-inGoogle sign-in
GitHubYour email address, name and avatar URL, returned to us after you approve sign-inGitHub sign-in
Google AnalyticsPseudonymous usage data — pages viewed, approximate location, device and browserUnderstanding how the site is used. Only ever loaded with cookies after you accept

If you configure a webhook, Slack, Discord, Teams, PagerDuty, Opsgenie or ntfy channel, we send alert content to the address you supply. What happens to it after that is governed by that service's privacy policy, not ours.

We may also disclose data where the law requires it, or where it is necessary to establish or defend a legal claim.

Where your data is processed

Our servers and database are located in the European Union. Some of the providers listed above process data outside the EU; where they do, those transfers are covered by the European Commission's Standard Contractual Clauses or an equivalent safeguard under Chapter V of the GDPR.

How long we keep it

We do not expire your data on a timer. Everything you create stays for as long as you want it — and the moment you delete it, it is gone.

  • Monitors, assertions and alert channels — kept until you delete them. Deletion is immediate: the record is removed from the live database as part of the request, not queued for later. There is no soft delete and no recycle bin, so we cannot undo it for you.
  • Check results and assertion failure history — kept for as long as the monitor exists. Deleting a monitor deletes its entire history in the same operation, including any response data a failed assertion captured along the way.
  • Status pages — kept until you delete them, at which point the public URL stops resolving.
  • Server logs — kept briefly for operational and security purposes, then rotated out.

To close your account entirely, email [email protected]. We delete the account along with every monitor, check result, alert channel and status page attached to it. There is no self-service account deletion in the product yet, so this one goes through a human — we will confirm once it is done.

One caveat, so the word “instantly” is not overstated: routine database backups may hold a copy for a short period after deletion, until those backups are rotated out in the normal course. Nothing is restored from them except to recover from a failure.

Our legal basis for using your data

Under the GDPR, we rely on:

  • Performance of a contract — running your monitors, sending your alerts and maintaining your account. Without this data there is no service.
  • Legitimate interests — keeping the service secure, preventing abuse, and diagnosing faults.
  • Consent — analytics cookies, and only those. You can withdraw it at any time without affecting anything else.

Your rights

If you are in the EEA or the UK you have the right to access your data, correct it, have it deleted, restrict or object to how we use it, receive a portable copy, and withdraw consent you have given. Email [email protected] and we will respond within one month.

You also have the right to complain to your local data protection authority if you think we have handled your data badly. We would rather you told us first so we can put it right.

Security

Traffic to pingdan is encrypted with TLS. Passwords are hashed with bcrypt. Sessions use signed, expiring tokens. Access to the production database is limited to those who need it to operate the service. No system is perfect, and we will not pretend otherwise — but if we ever discover a breach affecting your data, we will tell you.

Children

pingdan is a tool for people running software in production. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, email us and we will remove it.

Changes to this policy

If we change how we handle your data in a way that affects you, we will update this page and change the date at the top. This version is dated 2 August 2026.

Contact

Questions about any of this go to [email protected]. A real person reads it.

Monitoring that respects your data

Set up your first monitor free. No card, no tracking you didn't agree to.

Start free