Privacy Policy

Effective 2026-06-17

1. Scope and controller

This policy covers checkmeup.net and the public status pages it serves at checkmeup.net/status/* (together, "the Service"). It explains what we collect, why, and who we share it with. The data controller is Andrew Molyuk, a sole proprietor (עוסק פטור) based in Israel, operating Checkmeup ("we", "us").

2. Information you provide

Account data: email address and password (stored as a salted hash, never in plain text). Billing data: handled directly by Paddle — we never see or store your card details. Monitor data: the URLs, cron schedules, and check results you configure. Telegram chat ID, if you connect alerts. Anything you write in a status page's title, description, or a support email.

3. Information we collect automatically

Request metadata (IP address, user agent, timestamp, path) for security and abuse prevention. Two strictly-necessary, httpOnly session cookies (access_token, refresh_token) that keep you signed in — no advertising or analytics cookies, and nothing that tracks you across other sites.

4. How and why we use it

To run the Service: performing checks, sending alerts, serving status pages, enforcing plan limits, and securing accounts against abuse. Legal bases (for visitors covered by GDPR or similar law): performing our contract with you, our legitimate interest in operating and securing the Service, and compliance with tax/billing law for payment records. We don't sell your data or use it for advertising.

5. Subprocessors

We share data with the following subprocessors, each limited to what it needs to do its job:

ServicePurpose
ResendTransactional email — password reset, account notices
TelegramDelivering down/recovery alerts to the chat you connect
PaddlePayment processing and billing for paid plans (merchant of record)
HetznerApplication hosting and database storage (Germany)

6. International transfers

Application hosting and the database are in Germany (Hetzner, within the EU). Some subprocessors above may process or store data outside the EU/EEA as part of their own infrastructure; where that happens, we rely on their standard contractual safeguards.

7. Data retention

Account and monitor data is kept for as long as your account is active. We don't yet have a self-service delete-account button — email us and we'll delete your account, monitors, check history, and status pages. Data may persist briefly afterward in routine backups before they roll over. We retain minimal billing records as required by tax law.

8. Security

Passwords are hashed with bcrypt, never stored in plain text. Sessions use httpOnly, SameSite cookies (see Terms for how this works). No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your data.

9. Your rights

Depending on where you live, you may have rights to access, correct, delete, or export your data, and to object to certain processing, under GDPR or similar law. Email us and we'll handle it directly — no formal request process needed. EU residents may also lodge a complaint with their local supervisory authority.

10. Children's privacy

The Service is not directed at children and isn't intended for anyone under the age stated in our Terms' eligibility requirement. We don't knowingly collect data from children. If you believe a child has provided us data, email us and we'll delete it.

11. Changes to this policy

We may update this policy as the Service evolves. Material changes require re-acceptance on your next sign-in — you'll see a blocking notice before continuing to use the Service.

12. Contact

Questions about this policy or your data: andrew@checkmeup.net.

We use cookies for basic web analytics (page views, traffic sources). No ads, no cross-site tracking.