Last updated: March 30, 2026
CheckSite is operated by:
Karol Furgol
Poland
Email: support@checksite.app
For privacy-specific inquiries, including exercising your data protection rights: support@checksite.app
CheckSite ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website monitoring service at checksite.app and our browser extension. As a company operating in the European Union, we comply with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
We have assessed our processing activities and determined that the appointment of a Data Protection Officer is not required under GDPR Article 37. For all data protection matters, please contact us at support@checksite.app.
We collect the following personal information when you create an account and use our service:
As part of providing our monitoring service, we collect and process:
Website content captured during monitoring checks is sent to third-party AI analysis providers for intelligent change detection. This is a core function of every monitoring check and is used to detect meaningful changes, filter noise, and generate summaries. See the "Third-Party Services and Sub-Processors" section for details on these providers and their data handling practices.
Automated analysis may occasionally produce inaccurate or incomplete results. See our Terms of Service for details.
If you use our Chrome browser extension:
We automatically collect certain technical information when you visit our website:
We use the information we collect to:
We do not use your personal data for automated decision-making or profiling that produces legal effects or similarly significant effects on you.
We process your personal data under the following legal bases:
We do not sell, trade, or rent your personal information to third parties. We share information only in these limited circumstances:
We use the following third-party services to operate CheckSite. Each processes data on our behalf under appropriate contractual safeguards:
| Provider | Purpose | Data processed | Location | Transfer safeguard |
|---|---|---|---|---|
| Supabase (US) | Database, authentication | Account data, monitoring data | US (AWS) | EU-US Data Privacy Framework |
| Vercel (US) | Web application hosting | HTTP requests, IP addresses | Global edge, US origin | EU-US Data Privacy Framework + SCCs |
| Hetzner (DE) | Monitoring worker hosting | Monitored page content, extraction data | Germany (EU) | N/A (EU-based) |
| OpenRouter (US) | AI model routing for change analysis | Monitored page content (for analysis duration only) | US | Standard Contractual Clauses |
| Resend (US) | Email notification delivery | Email addresses, notification content | US | EU-US Data Privacy Framework |
| Polar.sh (US) | Payment processing | Payment details, email, subscription status | US | Standard Contractual Clauses |
| Cloudflare (US) | DNS, CDN, DDoS protection | IP addresses, HTTP metadata | Global edge | EU-US Data Privacy Framework |
Regarding AI analysis providers: Monitored page content is sent to AI models (currently Google Gemini via OpenRouter) for change analysis. Based on OpenRouter's terms, content submitted via API is not used to train models and is not retained beyond the duration of the request. We do not control these providers' internal data handling beyond what their terms and data processing agreements specify. We recommend reviewing OpenRouter's privacy policy for full details.
We implement technical and organizational measures to protect your information, including:
No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee absolute security.
We retain your information according to the following schedule:
When you delete your account, we will delete or anonymize your personal information within 30 days, except where retention is required by law (e.g., payment records for tax compliance).
Under the GDPR and applicable data protection laws, you have the following rights:
To exercise any of these rights, please contact us at support@checksite.app. We will respond within 30 days of receiving your request, as required by GDPR.
We do not use cookies for analytics or tracking. No cookie consent banner is required for analytics purposes.
We use Rybbit, a cookieless, privacy-friendly analytics tool, to understand how our website and service are used. Rybbit is self-hosted on our own EU infrastructure and does not perform cross-site tracking. No cookies or local storage are used for analytics.
For unauthenticated visitors, Rybbit collects only anonymous, aggregated usage data:
Legal basis: Legitimate interest (Article 6(1)(f)). This anonymous data collection is necessary for understanding website usage patterns, improving our service, and ensuring our marketing efforts are effective. No personal data is processed for unauthenticated visitors' analytics.
For authenticated users, we associate analytics events with your account (user ID) to understand product usage patterns, perform retention and funnel analysis, and improve the service. This includes custom events such as account actions (sign-up, login), monitor management (creation, deletion, configuration changes), and subscription events (checkout, purchase, cancellation).
Legal basis for authenticated user analytics: Performance of a contract (Article 6(1)(b)) — understanding how you use the service is necessary to maintain and improve the features you are paying for. You may object to this processing under Article 21 by contacting us at support@checksite.app.
The analytics script is served from our own domain (checksite.app) to ensure accurate traffic measurement and avoid false blocking by browser extensions that target third-party analytics domains. All analytics data is processed exclusively on our self-hosted infrastructure within the European Union. No analytics data is sent to third parties.
To maintain service reliability and diagnose issues, we collect operational telemetry data using OpenTelemetry, an industry-standard observability framework. This data is sent to our self-hosted SigNoz instance within the European Union.
What is collected:
What is NOT collected in telemetry:
Legal basis: Legitimate interest (Article 6(1)(f)) — ensuring service reliability, performance monitoring, and incident response.
Retention: Telemetry data is retained for 30 days and automatically deleted.
Location: All telemetry data is processed on our self-hosted infrastructure within the European Union.
As an EU-based service, we primarily process data within the European Economic Area (EEA). Where we transfer personal data outside the EEA to our sub-processors (see table above), we ensure appropriate safeguards are in place as required by GDPR Chapter V:
Details of the specific safeguards in place for each sub-processor are available on request by contacting support@checksite.app.
Our service is not intended for use by children. We do not knowingly collect personal information from anyone under the age of 16 in the European Economic Area, or under the age of 13 in other jurisdictions. If we become aware that we have collected personal data from a child below the applicable age, we will take steps to delete that information promptly.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, as required by GDPR Article 34.
We may update this Privacy Policy to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by email to the address associated with your account at least 14 days before the changes take effect. Non-material changes may be posted on this page with an updated "Last updated" date.
Your continued use of our service after the effective date of a revised Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you may delete your account before the effective date.
If you have questions about this Privacy Policy, our privacy practices, or wish to exercise your data protection rights:
We aim to respond to all privacy-related inquiries within 30 days.
We collect only the information necessary to provide our website monitoring service, protect your data with industry-standard security measures, comply with GDPR requirements, and never sell your personal information to third parties.