Privacy Policy

Last updated: March 30, 2026

Data Controller

CheckSite is operated by:

Karol Furgol
Poland
Email: support@checksite.app

For privacy-specific inquiries, including exercising your data protection rights: support@checksite.app

Introduction

CheckSite ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website monitoring service at checksite.app and our browser extension. As a company operating in the European Union, we comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

We have assessed our processing activities and determined that the appointment of a Data Protection Officer is not required under GDPR Article 37. For all data protection matters, please contact us at support@checksite.app.

Information We Collect

Personal Information

We collect the following personal information when you create an account and use our service:

  • Email address (for account creation, authentication, and notifications)
  • Name (if voluntarily provided)
  • Payment information (processed securely by our payment provider Polar.sh — we do not store payment card details)
  • Monitoring profile information (role, industry, monitoring goals — if voluntarily provided)
  • Contact information submitted through our support forms

Website Monitoring Data

As part of providing our monitoring service, we collect and process:

  • URLs of websites you choose to monitor
  • Website content snapshots used for change detection (text content extracted from monitored pages)
  • Viewport screenshots of monitored pages (Pro tier only, retained for 30 days)
  • Monitoring configuration including check frequency, focus areas, and notification preferences
  • Notification channel credentials you provide (Telegram chat IDs, Slack webhook URLs, Discord webhook URLs, Microsoft Teams webhook URLs, custom webhook URLs)
  • AI-generated analysis of detected changes (summaries, categorizations, recommendations)

Website content captured during monitoring checks is sent to third-party AI analysis providers for intelligent change detection. This is a core function of every monitoring check and is used to detect meaningful changes, filter noise, and generate summaries. See the "Third-Party Services and Sub-Processors" section for details on these providers and their data handling practices.

Automated analysis may occasionally produce inaccurate or incomplete results. See our Terms of Service for details.

Browser Extension Data

If you use our Chrome browser extension:

  • The extension reads the URL and page title of the active tab when you click "Monitor this page"
  • The extension does not read page content, cookies, browsing history, or any authentication data
  • The extension communicates only with checksite.app to create and manage monitors
  • No data collected by the extension is shared with third parties

Technical Information

We automatically collect certain technical information when you visit our website:

  • IP address (used for security, abuse prevention, and deriving country for sanctions compliance — not stored long-term; see Analytics section)
  • Browser type, version, and operating system
  • Pages visited within checksite.app and interaction patterns
  • Timestamps of requests
  • Log files and error reports (retained for 30 days)

How We Use Your Information

We use the information we collect to:

  • Provide, operate, and maintain our website monitoring service
  • Send notifications about detected website changes through your configured channels
  • Process payments and manage your subscription
  • Improve our service, develop new features, and fix bugs
  • Provide customer support and respond to your inquiries
  • Send important service announcements (e.g., planned maintenance, security notices)
  • Enforce access restrictions based on country in accordance with applicable sanctions regulations
  • Comply with legal obligations

We do not use your personal data for automated decision-making or profiling that produces legal effects or similarly significant effects on you.

Legal Basis for Processing (GDPR Article 6)

We process your personal data under the following legal bases:

  • Performance of a contract (Article 6(1)(b)): Processing necessary to provide the monitoring service you signed up for, including account management, website monitoring, change detection, AI analysis, and delivering notifications.
  • Legitimate interests (Article 6(1)(f)): Service improvement based on aggregated usage patterns, fraud prevention, security measures, and operational telemetry. We balance these interests against your rights and freedoms. You may object to processing based on legitimate interests at any time.
  • Consent (Article 6(1)(a)): Where you have given explicit consent, such as for optional marketing communications or associating your user identity with analytics events. You may withdraw consent at any time without affecting the lawfulness of processing performed before withdrawal.
  • Legal obligation (Article 6(1)(c)): Where we are required to process data to comply with applicable laws and regulations, including tax obligations and sanctions compliance.

Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We share information only in these limited circumstances:

  • Sub-processors and service providers: With trusted third-party providers who process data on our behalf to help us operate our service. See "Third-Party Services and Sub-Processors" below for a complete list.
  • Legal requirements: When required by applicable law, regulation, legal process, or enforceable governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
  • Business transfers: In connection with a merger, acquisition, or sale of assets. We will notify you via email or prominent notice on our service before your personal data is transferred and becomes subject to a different privacy policy.

Third-Party Services and Sub-Processors

We use the following third-party services to operate CheckSite. Each processes data on our behalf under appropriate contractual safeguards:

ProviderPurposeData processedLocationTransfer safeguard
Supabase (US)Database, authenticationAccount data, monitoring dataUS (AWS)EU-US Data Privacy Framework
Vercel (US)Web application hostingHTTP requests, IP addressesGlobal edge, US originEU-US Data Privacy Framework + SCCs
Hetzner (DE)Monitoring worker hostingMonitored page content, extraction dataGermany (EU)N/A (EU-based)
OpenRouter (US)AI model routing for change analysisMonitored page content (for analysis duration only)USStandard Contractual Clauses
Resend (US)Email notification deliveryEmail addresses, notification contentUSEU-US Data Privacy Framework
Polar.sh (US)Payment processingPayment details, email, subscription statusUSStandard Contractual Clauses
Cloudflare (US)DNS, CDN, DDoS protectionIP addresses, HTTP metadataGlobal edgeEU-US Data Privacy Framework

Regarding AI analysis providers: Monitored page content is sent to AI models (currently Google Gemini via OpenRouter) for change analysis. Based on OpenRouter's terms, content submitted via API is not used to train models and is not retained beyond the duration of the request. We do not control these providers' internal data handling beyond what their terms and data processing agreements specify. We recommend reviewing OpenRouter's privacy policy for full details.

Data Security

We implement technical and organizational measures to protect your information, including:

  • Encryption of data in transit (TLS 1.2+)
  • Encryption of data at rest (provided by our infrastructure providers)
  • Access controls and authentication on all internal systems
  • HMAC signature verification on all webhook communications
  • SSRF protection on URL validation
  • Hidden DOM element sanitization to prevent prompt injection
  • Row-level security (RLS) on all database tables
  • Regular security reviews of our codebase

No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.

Data Retention

We retain your information according to the following schedule:

  • Account data (email, name, profile): Retained while your account is active. Deleted within 30 days of account deletion.
  • Monitoring data (content snapshots, change history): Retained while the monitor is active. Deleted within 30 days of monitor deletion or account deletion.
  • Viewport screenshots: Retained for 30 days from capture, then automatically deleted.
  • Notification delivery logs: Retained for 30 days.
  • Operational telemetry: Retained for 30 days, then automatically deleted.
  • Payment records: Retained for 7 years after the end of the fiscal year in which the transaction occurred, as required by Polish tax law (Ordynacja podatkowa).
  • Log files and error reports: Retained for 30 days.

When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law (e.g., payment records for tax compliance).

Your Rights Under GDPR

Under the GDPR and applicable data protection laws, you have the following rights:

  • Right of access (Article 15): Request a copy of the personal data we hold about you.
  • Right to rectification (Article 16): Request correction of inaccurate or incomplete personal data.
  • Right to erasure (Article 17): Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Right to restrict processing (Article 18): Request that we limit how we process your data in certain circumstances.
  • Right to data portability (Article 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON). Available via your account settings or by contacting us.
  • Right to object (Article 21): Object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests.
  • Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint: File a complaint with your local data protection supervisory authority. In Poland, the supervisory authority is:

    Prezes Urzędu Ochrony Danych Osobowych (UODO)
    ul. Stawki 2, 00-193 Warszawa
    https://uodo.gov.pl

To exercise any of these rights, please contact us at support@checksite.app. We will respond within 30 days of receiving your request, as required by GDPR.

Analytics

Product Analytics (Rybbit)

We do not use cookies for analytics or tracking. No cookie consent banner is required for analytics purposes.

We use Rybbit, a cookieless, privacy-friendly analytics tool, to understand how our website and service are used. Rybbit is self-hosted on our own EU infrastructure and does not perform cross-site tracking. No cookies or local storage are used for analytics.

For unauthenticated visitors, Rybbit collects only anonymous, aggregated usage data:

  • Page views and referrer URL
  • Browser type and screen size
  • Country (derived from IP address at the point of request; the IP address itself is not stored)

Legal basis: Legitimate interest (Article 6(1)(f)). This anonymous data collection is necessary for understanding website usage patterns, improving our service, and ensuring our marketing efforts are effective. No personal data is processed for unauthenticated visitors' analytics.

For authenticated users, we associate analytics events with your account (user ID) to understand product usage patterns, perform retention and funnel analysis, and improve the service. This includes custom events such as account actions (sign-up, login), monitor management (creation, deletion, configuration changes), and subscription events (checkout, purchase, cancellation).

Legal basis for authenticated user analytics: Performance of a contract (Article 6(1)(b)) — understanding how you use the service is necessary to maintain and improve the features you are paying for. You may object to this processing under Article 21 by contacting us at support@checksite.app.

The analytics script is served from our own domain (checksite.app) to ensure accurate traffic measurement and avoid false blocking by browser extensions that target third-party analytics domains. All analytics data is processed exclusively on our self-hosted infrastructure within the European Union. No analytics data is sent to third parties.

Service Monitoring and Operational Telemetry

To maintain service reliability and diagnose issues, we collect operational telemetry data using OpenTelemetry, an industry-standard observability framework. This data is sent to our self-hosted SigNoz instance within the European Union.

What is collected:

  • HTTP request traces (route, method, status code, duration)
  • Monitor check performance metrics (extraction duration, content size, analysis confidence scores)
  • Notification delivery results (channel type, success/failure status, latency)
  • Internal identifiers (monitor IDs, anonymized user IDs) for correlating operational traces

What is NOT collected in telemetry:

  • Page content or website text
  • Email addresses, passwords, or personal information
  • Notification message content
  • AI analysis summaries or change descriptions
  • User-provided monitoring prompts

Legal basis: Legitimate interest (Article 6(1)(f)) — ensuring service reliability, performance monitoring, and incident response.

Retention: Telemetry data is retained for 30 days and automatically deleted.

Location: All telemetry data is processed on our self-hosted infrastructure within the European Union.

International Data Transfers

As an EU-based service, we primarily process data within the European Economic Area (EEA). Where we transfer personal data outside the EEA to our sub-processors (see table above), we ensure appropriate safeguards are in place as required by GDPR Chapter V:

  • EU-US Data Privacy Framework: For US-based providers that are certified under the framework (Supabase, Vercel, Resend, Cloudflare).
  • Standard Contractual Clauses (SCCs): For providers not covered by an adequacy decision, we rely on the European Commission's Standard Contractual Clauses.

Details of the specific safeguards in place for each sub-processor are available on request by contacting support@checksite.app.

Children's Privacy

Our service is not intended for use by children. We do not knowingly collect personal information from anyone under the age of 16 in the European Economic Area, or under the age of 13 in other jurisdictions. If we become aware that we have collected personal data from a child below the applicable age, we will take steps to delete that information promptly.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by GDPR Article 34.

Changes to This Policy

We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email to the address associated with your account at least 14 days before the changes take effect. Non-material changes may be posted on this page with an updated "Last updated" date.

Your continued use of our service after the effective date of a revised Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you may delete your account before the effective date.

Contact Us

If you have questions about this Privacy Policy, our privacy practices, or wish to exercise your data protection rights:

We aim to respond to all privacy-related inquiries within 30 days.

Summary

We collect only the information necessary to provide our website monitoring service, protect your data with industry-standard security measures, comply with GDPR requirements, and never sell your personal information to third parties.