Privacy Policy

Last updated: August 2026

What we collect

Account information. Your name and email address when you sign up, and whatever profile information you add afterward. Authentication is handled by better-auth; if you sign in with GitHub, we store the OAuth access token issued for that sign-in.

Site data you submit. The URLs of sites you ask us to monitor. To do that, our monitor loads each URL with a real browser and records what it finds — layout-shift measurements, console error text, broken image URLs, and text-overflow details. This data is about the pages you asked us to check, not about visitors to those pages.

Usage data. An anonymous, random identifier stored in your browser's local storage and the path of pages you visit, logged so we can see aggregate traffic. No cookies, no cross-site tracking, no third-party analytics vendor — this stays on our own servers.

Payment information. If you upgrade to a paid plan, billing is handled entirely by Stripe. We never see or store your card number — we receive only your subscription status and billing history from Stripe.

How we use it

To run the product: monitor your sites on the schedule you configure, detect issues, and generate the dashboard you see. Issue reports are assembled on our own servers from what the monitor observed — no part of your site and no part of your source code is sent to any AI provider. To alert you, we send email through Resend and, if you configure it, post to Slack.

We do not sell your data. We do not share your site data or account information with anyone except the service providers strictly needed to run the product (listed below), and we do not use your data to train any model.

Who else touches your data

Every subprocessor below exists to run a specific feature — none is optional plumbing:

  • Resend — sends alert emails and account emails on our behalf.
  • Stripe — processes payment for paid plans; handles your card details directly, we never receive them.
  • GitHub — verifies your identity if you choose to sign in with GitHub. We do not read or write your repositories.
  • Sentry (if configured) — receives error reports to help us fix bugs; we scrub secrets and tokens before anything is sent.
  • Our database host — stores everything above at rest.

How long we keep it

Account and site data for as long as your account is active. Detected issues and fix history accumulate as a timeline — you can delete a monitored site at any time, which removes its issues and fixes. Delete your account and we delete your account data; some records may persist briefly in backups before they age out.

Your choices

  • Remove a monitored site at any time from the dashboard.
  • Disconnect your GitHub account from Settings without losing your history.
  • Export or delete your account data by emailing us (below).
  • Opt out of anonymous usage logging isn't currently a toggle in the product; the data collected is minimal (a random ID and a path) and never leaves our servers. Contact us if this matters to you and we'll work something out.

Security

Passwords are never stored in plain text. Long-lived third-party credentials (like a linked Reddit account's OAuth token) are encrypted at rest. All traffic is served over HTTPS. We use a strict Content-Security-Policy to reduce the blast radius of a compromised dependency. No system is perfectly secure; if we discover a breach affecting your data, we'll notify you.

Children

This product is not directed at anyone under 16, and we don't knowingly collect data from them.

Changes to this policy

If we materially change what we collect or how we use it, we'll update the date at the top of this page and, for significant changes, email active accounts.

Contact

Questions about this policy or a request about your data: hello@lampwatch.com