Privacy Policy
Last updated 27 September 2026
PulseKeeper watches websites and servers and tells you when they break. This page explains what personal data that takes, why, who else sees it and how long we keep it.
Who is responsible
The controller for the personal data described here is BRAINCUP, Blaž Cigale s.p. ("we", "us"). For anything about your data, write to info@pulsekeeper.io.
When you use PulseKeeper to monitor services and alert other people (your team, your clients, their contacts), you decide whose data goes in, and for that data you are the controller and we are your processor. We offer a data processing agreement (DPA) on request.
What we collect
| Data | Why | Legal basis |
|---|---|---|
| Account: name, e-mail, password (stored only as a hash), organization name, time zone; if you sign in with Google or GitHub, the account ID they give us | To create your account, let you sign in and send you the alerts you set up | Contract |
| Security: two-factor secret and recovery codes (encrypted), session data, IP address and user agent of requests | To keep your account secure and detect abuse | Legitimate interest |
| What you monitor: hostnames, URLs, ports, request settings and headers for API monitors (headers encrypted), keywords, schedules | To run the checks you asked for | Contract |
| Measurements: response times, status codes, errors, certificate and DNS records, page speed results; heartbeat pings with the sender's IP address, user agent and up to 1,000 characters of what your job sends | To detect outages, show history and reports | Contract |
| Alert destinations: e-mail addresses, phone numbers for SMS, webhook, Slack, Discord and Telegram addresses you add, and a log of every alert we sent or held back | To deliver alerts and prove what was sent | Contract |
| Team and clients: e-mail addresses of people you invite to your team or to the client portal | To give them the access you granted | Contract (you are the controller for your clients' data) |
| Billing: plan, subscription status, invoices and the country and currency of payment. Card details go to Paddle only, and we never see them | To bill you and keep accounting records | Contract, legal obligation |
| Product analytics: which steps of sign-up and setup you completed and which features you used, linked to a pseudonymous ID, never your name, e-mail, hostnames or URLs | To understand where people get stuck and improve the product | Legitimate interest |
| Error reports: technical details of errors on our servers, with e-mail addresses, hostnames, URLs, IP addresses and database values removed before sending | To find and fix bugs | Legitimate interest |
| Support and requests: what you write to us, including the custom plan form | To answer you | Contract or pre-contract steps |
We do not sell personal data, and we do not use it for advertising.
Cookies
The app uses only the cookies it needs to work: a session cookie, a security token against forged requests (XSRF), and, if you tick "Remember me", a sign-in cookie. Analytics cookies are set only if you allow them (see below); there are no advertising cookies.
Our public pages (home, pricing, products) count visits with PostHog in cookieless mode: nothing is stored in your browser and there is no identifier across visits.
All our pages (including the app, sign-in pages, public status pages and the client portal) load Google Tag Manager, through which we use Google Analytics to understand how people find and use PulseKeeper. Analytics cookies are off by default and are set only after you agree in the cookie notice; you can change your choice at any time. Without your consent Google receives only cookieless signals that do not identify you across visits.
Who else processes data
We use these providers to run PulseKeeper. Each gets only what its job needs.
| Provider | What for | Where |
|---|---|---|
| Contabo GmbH | Servers and database | Germany (EU) |
| DigitalOcean, LLC | Probe servers that run checks from Frankfurt, London, New York, San Francisco, Singapore and Sydney | EU, UK, USA, Singapore, Australia |
| Cloudflare, Inc. | DNS, network protection, delivery of our pages | Global |
| Paddle.com Market Ltd | Payments, invoices and sales tax. Paddle is the merchant of record and seller of your subscription | UK, EU |
| Mailgun Technologies (EU region) | Sending e-mail: alerts, confirmations, invitations | EU |
| Twilio Inc. | Sending SMS alerts, if you add a phone number | USA, global carriers |
| PostHog Inc. (EU region) | Product analytics and error reports (see above) | EU |
| Google LLC / Google Ireland Ltd | Tag Manager and Analytics on our pages (analytics cookies only with your consent); Sign in with Google, if you use it; PageSpeed Insights, which receives the URLs of pages you ask us to measure | EU, USA, global |
| GitHub, GitLab, Atlassian (Bitbucket) | Deploy events, if you connect a repository | USA, EU |
Alerts you route to Slack, Discord, Telegram or your own webhook go to those services on your instruction; their own privacy terms apply there.
Where data leaves the EU/EEA (for example to probe servers in the USA or to Twilio), the transfer is covered by an adequacy decision (such as the EU–US Data Privacy Framework or the UK adequacy decision) or by the EU Standard Contractual Clauses.
How long we keep it
- Raw measurements: 7 days. Hourly summaries: about 2 years. Daily summaries: as long as your account exists. They contain no personal data beyond the monitored address.
- Heartbeat pings (with sender IP and output): 30 days.
- Account, monitors, alert settings and incident history: while your account exists. After you ask us to delete your account, within 30 days, except what the law makes us keep.
- Billing records: as long as accounting and tax law requires (in Slovenia, 10 years for invoices). Paddle keeps its own records as the seller.
- Security and audit logs (who changed a plan, invited a member, turned off two-factor): while your account exists, so we can answer "who did this".
- Backups: overwritten on a rolling schedule; deleted data disappears from them within 60 days.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to its use, and to receive it in a portable format. Most of it you can see and change yourself in Settings. Account deletion is by e-mail for now: write to info@pulsekeeper.io from the account's address and we will do it within 30 days.
If you think we handle your data unlawfully, you can complain to a supervisory authority (in Slovenia the Information Commissioner, Informacijski pooblaščenec, ip-rs.si) or to the authority where you live.
Security
Passwords are hashed, two-factor secrets and API monitor headers are encrypted, all traffic uses TLS, and our probe servers have no access to the database. Staff access to customer accounts is limited, requires two-factor authentication and is logged.
Children
PulseKeeper is a tool for businesses and is not meant for anyone under 16.
Changes
When we change this policy in a way that matters, we tell account owners by e-mail before it takes effect. The date at the top shows the latest version.
Contact
BRAINCUP, Blaž Cigale s.p.
Kalce 25e, 1370 Logatec, Slovenia
Registration number: 7294131000 · VAT ID: SI70919836
E-mail: info@pulsekeeper.io