Privacy
What this status site collects (very little), what it never stores (your IP address), and how long it keeps the rest.
What we collect
- Problem reports: a count per service per 5 min. Nothing else. Your IP address is held in memory for 10 min, so that one visitor is counted for 1 report per service in that time. It is not written to our database, and our request log records the method, path, time, status and browser of a request, not the address it came from. The other limits (sign-in links, suggestions, the public API) hold the address in memory the same way, for at most 60 min.
- Accounts: your email address, and your name and Google account number if you sign in with Google. A session is an HTTP-only cookie,
opensi_session, that lasts 30 days; we store only a hash of its token. Signing in with Google sets a second cookie,opensi_oauth, for 10 minutes. - Your team: the alerts, channels, private probes and API keys you add, the email addresses of people you invite, your plan and subscription status, a record of the alerts we sent, and the number of API calls per month.
- Suggestions: the service name and the link you send us.
- Newsletter: your email address, only after you confirm it (double opt-in). Every email has a one-click unsubscribe.
- Contribution offers: on the Contribute page you can tell us what you would like to offer. We store what you choose and write, and your email address, and use them only to answer you. The form refuses anything that looks like a key.
- Waitlist: where a feature is marked “coming soon” you can leave your email address. We store the address, the feature you asked about and the page the form was on, so that we can tell you when it is ready. Our operators can read the list. We use it for one email about that feature (for the weekly email, one confirmation link) and nothing else. There is no removal form yet: the address stays on the list until an operator removes it.
- Your own API keys (private probes) and webhook addresses are encrypted with AES-256-GCM. A saved key or signing secret is never shown again, not even to you; of a webhook address only the host and a masked form are shown.
- Payments are handled by Stripe or Razorpay. We never see or store card numbers.
- Product analytics: Product analytics is on. We use PostHog to count page views and actions such as “alert created”; its library is served through our own address, which forwards your page views to PostHog, and it may keep an identifier in your browser. Problem reports and suggestions are counted without any identity. Joining a waitlist or sending a contribution offer is counted with the same anonymous browser identifier as your page views, never with your email address. Signed-in actions are tied to an opaque account number, never to your email address.
How long we keep it
- Single check results are kept for 14 days. After that only per-minute, hourly and daily summaries remain; they hold no personal data.
- Report counts are numbers per service; they were never tied to a visitor.
What we do not do
- Fonts and scripts are served from our own domain, except the analytics library named above. No third-party font and no advertising script is loaded.
- We do not sell personal data.
Deleting your data
You can delete what you added yourself, today: every alert, channel and private probe has a Remove button and every API key a Revoke button on your dashboard, and every newsletter email has an unsubscribe link. There is no button that deletes the account itself yet, and no contact address is published on this site yet.