Privacy & Data Governance
WebChecky Privacy Policy
At WebChecky (“we,” “our,” or “us”), operated via https://webchecky.com (the “Service”), we are deeply committed to safeguarding the privacy, confidentiality, and security of our users, developers, agencies, and enterprise customers. This Privacy Policy outlines with complete transparency what data we collect, how that data is processed across our monitoring and security engines, how secrets are encrypted, our retention guidelines, and your privacy rights under applicable data protection laws including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
1 Information We Collect
We collect information in three ways: information you provide directly, information collected automatically during service operation, and diagnostic telemetry gathered from monitored endpoints.
A. Account & Authentication Information
- User Profile: Name, username, email address, password hashes (salted using industry-standard bcrypt hashing algorithms).
- Single Sign-On (SSO): When signing in with Google OAuth, we receive your verified Google account ID, email address, and profile name. We do not receive or store your Google account password.
- Team & Organization Data: Team workspace names, team member email addresses, assigned roles (Admin, Member, Viewer), and team invitations.
- Billing & Payment Data: Subscription tier, billing email, billing addresses, and payment transaction metadata. All credit card processing is handled directly by Stripe. WebChecky never stores full credit card numbers or CVV codes on our servers.
B. Monitored Target Configuration & Credentials
- Website & Hostname Targets: URLs, domains, hostnames, IP addresses, check intervals, SLA uptime targets, and custom content match assertions.
- API Monitoring Configurations: HTTP methods, endpoint URLs, custom request headers, request bodies, expected status code ranges, and JSON assertion paths.
- Encrypted Secrets & Credentials: Sensitive API tokens, Basic Authentication credentials, and synthetic journey secrets are strictly encrypted at rest using AES-128/256 symmetric Fernet encryption before being written to our database.
- Playwright Synthetic Journeys: Automated multi-step browser user flows (navigation, selectors, assertions, and automated interaction sequences).
C. Diagnostic Telemetry & Continuous Scan Data
- Uptime & Latency Metrics: Response times, HTTP response codes, SSL/TLS handshake latency, DNS resolution timing, and historical uptime percentages.
- Error Capture & Failure Screenshots: On check failures or synthetic assertion errors, automated screenshots and error logs are captured to provide visual proof and root cause diagnostics. Screenshots are stored securely in encrypted cloud storage with automatic 7-day retention cleanup.
- Core Web Vitals & Performance: Largest Contentful Paint (LCP), Cumulative Layout Shift (CLS), Time to First Byte (TTFB), First Contentful Paint (FCP), total page weight, and resource breakdown distributions.
- DNS Records & Email Security: Public DNS zone records (A, AAAA, CNAME, MX, TXT, NS, SOA, CAA, SRV, DNSSEC), SPF records, DKIM selectors, DMARC policies, and DNSBL blacklist reputation metrics.
- Security & Attack Surface Intelligence: HTTP security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy), OWASP Top 10 indicators, public admin portal exposures (`/admin`, `/wp-admin`, `/login`), debug traces, source maps, and detected technology stacks (CMS, frameworks, web servers, cloud infrastructure, analytics).
- Cron Job & Heartbeat Pings: Incoming heartbeat pings, source IP addresses, execution duration, and optional log payloads dispatched by your background worker jobs.
D. Agency White-Label Branding Data
For agency users generating PDF reports: agency name, custom agency logo URLs, primary and accent brand colors, client names, and custom audit notes.
E. Local Monitoring Agent Telemetry
When deploying the optional webchecky-agent for internal network/LAN monitoring: agent pairing tokens, operating system name, hostname, agent version, and local latency metrics. Local agents communicate with WebChecky over secure HTTPS.
2 How We Use Your Information
We process your data strictly for legitimate operational purposes:
- Execute Continuous Monitoring: To conduct automated uptime checks, API synthetic tests, SSL certificate verification, and DNS tracking according to your configured schedule.
- Multi-Channel Alert Dispatch: To transmit instant incident notifications, downtime alerts, SSL expiration warnings, DNS drift notifications, and heartbeat failure alerts via your chosen notification channels (Email via Microsoft Graph, Slack, Discord, Microsoft Teams, and custom Webhooks).
- Generate Diagnostic Audits & PDF Reports: To compile technical SEO audits, cybersecurity reports, performance dashboards, and downloadable white-label agency PDFs.
- Prevent Abuse & Ensure Platform Stability: To enforce rate limits, detect brute-force attacks, mitigate DDoS threats, and verify that our service is not used for unlawful scanning or malicious reconnaissance.
- Account & Workspace Management: To administer team access, authentication sessions, billing lifecycle, and customer support.
3 Data Encryption & Security Measures
Security is at the heart of WebChecky’s architecture. We implement robust physical, administrative, and technical safeguards:
Encryption in Transit
All data transmitted between your browser, monitoring agents, external APIs, and WebChecky servers is encrypted using modern TLS 1.2 / TLS 1.3 with strict HSTS enforcement.
Encryption at Rest
API credentials, authorization tokens, and synthetic test secrets are encrypted with Fernet symmetric cryptography prior to database storage.
Automatic Data Lifecycle
Failure screenshots and heavy telemetry snapshots are automatically pruned on a weekly rotation (7-day retention) to minimize data footprint.
Role-Based Access Isolation
Multi-tenant workspaces are strictly isolated at the database query layer, ensuring team members can only access resources they have permission to view.
4 Third-Party Subprocessors & Integrations
We do not sell, rent, or trade your personal information. We share data only with trusted third-party service providers (subprocessors) necessary to deliver WebChecky:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe Inc. | Payment processing & subscription billing | Customer email, billing address, transaction IDs |
| Microsoft Graph API | Transactional email & incident alert delivery | Recipient email, alert contents, incident summaries |
| Slack / Discord / Teams | Optional user-configured alert channels | Downtime status, website names, latency metrics |
| Google Cloud Platform | Secure infrastructure & temporary snapshot storage | Encrypted screenshot artifacts (7-day lifecycle) |
5 Your Data Rights (GDPR & CCPA/CPRA)
Depending on your jurisdiction, you have specific legal rights concerning your personal data:
- Right to Access: You can view all monitored assets, metrics, and audit history directly inside your WebChecky dashboard at any time.
- Right to Data Portability: You can export comprehensive historical reports as PDF or export website configuration data.
- Right to Rectification: You may update your account details, organization name, branding, or monitoring settings directly from the Settings page.
- Right to Erasure (“Right to be Forgotten”): Deleting a monitored website or deleting your account permanently removes all associated check history, diagnostic scans, and encrypted secrets from our active databases.
- Right to Opt-Out: You can enable or disable alert notifications across any channel (Email, Slack, Discord, Teams, Webhooks) per website.
To exercise any of these rights, contact us at privacy@webchecky.com or via our in-app support channels.
6 Cookies & Local Storage
WebChecky uses essential cookies for secure session authentication, CSRF defense, and user interface preferences (such as light/dark theme selection). We do not deploy third-party advertising tracking cookies. For complete details, please read our dedicated Cookie Policy.
7 Changes to this Privacy Policy
We may update this Privacy Policy periodically to reflect new features, infrastructure enhancements, or legal standards. When substantive changes occur, we will update the "Last Updated" date at the top of this policy and notify registered users via email or an in-app announcement.
8 Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data governance practices, please reach out:
WebChecky Privacy & Data Protection
Email: privacy@webchecky.com
Support: support@webchecky.com
Website: https://webchecky.com