← Back

Privacy policy

Last updated: 26 May 2026 · plain English version

What we collect

When you sign up: your email address and your name. When you create monitors: the URLs and configurations you give us. When you use the dashboard: standard server logs (IP, user agent, timestamps).

When the engine probes your services: the response status, response time, and any error text from the probe. We do not store response bodies.

What we don't collect

We don't sell data. We don't train AI models on customer monitoring data. We don't store the bodies of the HTTP responses we probe. We don't run advertising or retargeting pixels, and we don't load anything at all inside the app that watches what you do with your monitors.

Where data lives

Your application data — workspaces, users, monitors, incidents, probe results — is stored in a managed Postgres instance in the EU (AWS Frankfurt), and the app is served from Frankfurt too. Storage is one thing and processing is another, so plainly: our probe machines run in Amsterdam, Virginia and Singapore, which means the URL being checked and the response we get back are handled in the US and Singapore before the result is written to the EU database. That is what multi-continent consensus requires. Mercury sends the evidence for an incident to Anthropic in the US to write its summary. Every vendor above is a US company, including the ones storing data in Europe.

Who can see it

Only members of your workspace, your Repose admin (for support, only when you explicitly ask), and our SOC 2-targeted set of infrastructure providers (Neon for Postgres, Vercel for app hosting, Fly.io for the probe machines, Resend for email, Cloudflare for DNS, Stripe for billing, Anthropic for the Mercury incident summaries, Simple Analytics for page counts on our public pages, and Slack or Discord if you connect them). Our analytics provider sees page views on public pages only — never your monitoring data, and never anything behind a login.

How long we keep it

Application data: until you delete your account. Individual probe results: 30 days, on every plan. Daily uptime and latency totals, incidents and the alert decision trail: until you delete your account. The public down checker keeps the URL you typed and its three results for 24 hours; it never stores your IP address, only a salted hash of it so the rate limit can count. The alert_decision audit trail is kept forever (or until you delete the workspace) — that's what powers the "why this fired" tab.

Your rights

You can export everything you've given us (per workspace) at any time. You can delete your account and all associated data via the dashboard. We respond to deletion requests within 7 days.

Cookies

We use two essential cookies and nothing else: one for your login session, and — only if you belong to more than one workspace and switch between them — one that remembers which workspace you were last in. Both exist to make the app work and neither tracks you.

We set no analytics or advertising cookies, on any page. Our public pages — the marketing site, sign-in, sign-up, this page and the terms — load Simple Analytics, which counts page views without storing anything on your device and without building a profile of you. There is nothing to consent to, which is why you aren't being asked.

It doesn't run inside the signed-in app, so no third party sees the URLs of your dashboard, monitors or incidents — those addresses name your infrastructure. It doesn't run on password-reset or invite links, which carry a single-use token in the address. And it doesn't run on the status pages we host for customers: those visitors are our customers' audience, not ours.

Simple Analytics is a Dutch company and stores its data in the EU. If we ever needed something that couldn't work this way, you'd get a banner and this page would say so the same day.

Contact

Email [email protected] for anything related to data, this policy, or your rights under GDPR / CCPA.

Note from the founder: this is a plain-English boilerplate. Before public launch the team should run it past a lawyer (especially for EU GDPR compliance and US state privacy laws). The text here represents the spirit of our intent; the legally-binding version may be slightly different.
Privacy — Repose