Privacy Policy
Last updated: 2026-05-07
1. Who We Are
KEEPitALIVE is an uptime, workflow monitoring, incident tracking, notification, and automation service operated by Pedro Salabert, an individual based in Portugal.
Contact: support@keepitalive.dev
Data protection authority: CNPD - Comissao Nacional de Protecao de Dados, Portugal, https://www.cnpd.pt
2. What This Policy Covers
This policy explains how KEEPitALIVE collects, uses, stores, and deletes personal data when you use our website, app, API, monitoring services, notification integrations, OAuth sign-in, public status pages, or related services.
3. Data We Collect
OAuth scopes currently used by KEEPitALIVE are limited to basic identity/profile scopes needed for account login. GitHub sign-in requests email access so KEEPitALIVE can retrieve your primary email address if it is not returned by the basic GitHub profile endpoint. Microsoft sign-in requests basic OpenID/profile/email access and User.Read so KEEPitALIVE can retrieve your Microsoft account ID, display name, and email or user principal name.
We do not receive or store your OAuth provider password. For Sign in with Apple, Apple may provide a private relay email address if you choose Hide My Email. We treat that relay address as your account email.
- OAuth account data: email address, display name or username, avatar URL, provider name, and provider user ID.
- Session and security data: session token hash, IP address, user agent, created time, and last-used time.
- Monitor and workflow data: URLs, hosts, ports, DNS records, heartbeat tokens, event receiver configuration, game server addresses, names, groups, tags, intervals, timeouts, assertions, status pages, triggers, signing secrets, and execution logs.
- Notification data: email recipients, webhook URLs, Telegram bot token and chat ID, Pushover credentials, PagerDuty routing keys, web push endpoints, and Firebase Cloud Messaging tokens.
- Support data: email address, message contents, and related support context if you contact us directly.
4. What We Do Not Do
KEEPitALIVE uses Stripe to process payments, subscriptions, invoices, taxes, and billing-related customer records. We do not store full payment card numbers. Stripe may collect and process billing details such as name, email address, billing address, tax information, payment method details, transaction records, invoice history, and subscription status according to Stripe's own terms and privacy policy.
- We do not sell personal data.
- We do not use advertising cookies or third-party behavioral advertising.
- We do not collect OAuth account passwords.
- We do not intentionally collect sensitive personal data such as health, biometric, or government ID data.
- We do not access private OAuth provider content beyond profile fields needed for sign-in.
5. How We Use Data
- Create and manage accounts.
- Authenticate users.
- Run monitors, checks, heartbeats, event receivers, browser checks, DNS checks, and game server checks.
- Detect incidents, recoveries, degraded states, flapping, missed heartbeats, and related events.
- Send alerts and notifications.
- Execute user-configured triggers and webhooks.
- Provide public monitor and public status page features.
- Enforce quotas, plans, abuse limits, and security controls.
- Debug, secure, and improve the service.
- Comply with legal obligations.
6. Legal Bases Under GDPR
- Contract: providing the KEEPitALIVE service, account login, monitors, alerts, status pages, and triggers.
- Legitimate interests: security logging, abuse prevention, service reliability, debugging, and fraud prevention.
- Legal obligation: tax, accounting, compliance, and lawful requests where applicable.
- Consent: optional features that explicitly ask for consent.
7. Third-Party Services
We share data only as needed to provide the service, protect the service, or comply with law.
- OAuth providers for authentication.
- Hetzner Cloud for hosting.
- Cloudflare for DNS, TLS, security, and traffic protection.
- ZeptoMail / Zoho for transactional email and alert delivery.
- Stripe for payments, subscriptions, invoices, tax handling, and billing portal access.
- Firebase Cloud Messaging for mobile push notifications.
- Browser checker service for browser-based checks.
8. International Availability
KEEPitALIVE is operated from Portugal and is available to users worldwide. Your data may be processed in the European Union and in other locations where our service providers operate. Where required, we rely on appropriate safeguards for international transfers.
9. Cookies
KEEPitALIVE uses essential cookies or similar technologies to keep you signed in and protect sessions. We do not use advertising cookies or third-party tracking cookies.
10. Data Retention and Account Deletion
Account data is retained until account deletion, subject to a 30-day deletion grace period. Monitor configuration is retained until deleted by you or your account is deleted. Check and incident history is retained on a rolling basis depending on plan and system limits. Trigger execution logs are normally retained for 30 days. Session records are retained until revoked or expired.
When you delete your account, the account is first soft-deleted for 30 days. During that period, your account is inaccessible and sessions are revoked, but the account can be reactivated by signing in again. During the grace period, monitors owned by the deleted account are deactivated so checks stop running. If you reactivate the account, monitors may need to be manually re-enabled.
After the 30-day period, account data is permanently deleted according to our deletion process. The deleted-account audit record contains limited data needed for abuse prevention and deletion tracking, such as deletion time and a hashed version of the account email.
11. Security
No online service can guarantee perfect security. You are responsible for keeping your OAuth provider account secure and for protecting webhook URLs, tokens, and secrets you configure.
- HTTPS for service traffic.
- Hashed session tokens.
- OAuth state validation.
- Encrypted storage for sensitive integration credentials where implemented.
- SSRF protections for outgoing monitor and trigger requests.
- Private/internal network target restrictions.
- Session revocation controls.
- Plan and abuse limits.
12. Your Rights
To exercise these rights, use Account Settings or contact us at support@keepitalive.dev. We aim to respond within 30 days where GDPR applies. If you believe your data has not been handled correctly, you may complain to CNPD in Portugal or to your local data protection authority.
- Access personal data we hold about you.
- Correct inaccurate data.
- Delete your account and associated data.
- Export data where available.
- Object to certain processing.
- Restrict certain processing.
- Withdraw consent where processing is based on consent.
13. Children
KEEPitALIVE is not directed to children. You must be at least 16 years old in the EEA or at least 13 years old elsewhere to use the service, unless a higher age applies in your country.
14. Changes and Contact
We may update this policy from time to time. Material changes will be posted with an updated Last updated date. If a change materially affects your rights or how we use data, we will provide additional notice where required.
Pedro Salabert - support@keepitalive.dev