Privacy Policy

Last updated: 23 June 2026

Contents

Introduction and who we are

Checkilo is a heartbeat monitoring service. Your automations send us a small signal (a “ping”) on a schedule. If a ping does not arrive on time, we alert you so you can fix the problem.

Checkilo is operated by an independent sole proprietor. Our legal name is available on request by emailing support@checkilo.app. If you have any question about this policy or your data, email us at the same address.

In plain terms: we collect the email you sign up with, a few account settings, the billing identifiers Stripe gives us, and the monitoring pings your automations send. We do not sell your personal data, and we do not share it for advertising. The rest of this policy explains the details.

What we collect

We keep what we collect small. Here is the full list.

  • Account email. You sign up with an email and a password. Your password is handled entirely by our authentication provider, Supabase. Checkilo never stores your password.
  • Account settings. Your plan tier and your quiet-hours settings (a timezone and a start and end time for when you do not want alerts).
  • Billing identifiers. When you upgrade, Stripe handles the payment and sends us identifiers such as your customer ID, subscription ID, subscription status, the price and billing period, and invoice details. Card numbers never reach Checkilo.
  • Monitoring pings. Each ping your automation sends can include a status, a short optional label, optional metadata (your own data, as JSON, up to 4 KB), and a correlation ID. We also record the IP address the ping came from and the user-agent string of whatever sent it.
  • Website analytics. When you visit our public website, we record aggregate usage — page views, the referring site, and approximate country (derived from your IP address) — using a privacy-first, cookieless tool. This is not linked to your account. See the Cookies section.
  • Cookies. Only the cookies needed to keep you signed in. See the Cookies section for the full list.

We do not collect your name, postal address, phone number, or company. We never ask for them.

The data inside your pings

The metadata inside a ping is yours. You choose what to put in it. Checkilo treats it as opaque content: we store it and display it back to you verbatim in your dashboard, and we forward it inside the alert messages we send to the destinations you connect.

Because of this, please follow one rule: do not put secrets or sensitive personal data inside your pings. Passwords, API keys, full payment details, health information, and similar data do not belong in ping metadata.

If you choose to include personal data about other people in your pings, you are the controller of that data and Checkilo processes it on your behalf to provide the monitoring service.

How we use data

We use your data only to run Checkilo:

  • Operate the service so your automations can send pings and you can see them.
  • Detect and alert when a run is missing, late, or failed, and send those alerts to the destinations you set up.
  • Handle billing for paid plans through Stripe.
  • Provide support when you contact us.
  • Keep the service safe, including preventing abuse and protecting the integrity of the service.
  • Understand website traffic in aggregate, using privacy-first analytics that set no cookies, so we can improve our website.

If you are in Thailand, we rely on the Personal Data Protection Act (PDPA). If you are in the European Union or the United Kingdom, we rely on the GDPR and UK GDPR. Our legal bases are:

  • Performance of a contract. We process your account email, settings, billing identifiers, and pings to provide the service you signed up for and to bill paid plans.
  • Legitimate interests. We process limited data — such as IP addresses and user-agents on pings, and aggregate, cookieless website analytics — to keep the service secure, prevent abuse, maintain its integrity, and understand how our website is used.
  • Consent. Where consent is required, we rely on it and you can withdraw it at any time.

How we share data and subprocessors

We share data only with the service providers we need to run Checkilo. Each one receives only what it needs for its task.

ProviderPurposeWhat is sent
SupabaseAuthentication and database hostingEmail and password for authentication (stored only by Supabase, never by Checkilo); all application data in the database
StripePayment processingCustomer email and plan tier; Stripe returns subscription state (no card numbers reach Checkilo)
ResendEmail deliveryRecipient email and the rendered alert or health summary content
SentryError monitoringError events, with personal data scrubbed (emails redacted and PII sending disabled)
Fly.ioApplication and worker hostingAll application traffic and data in transit
CloudflareDNS, CDN, proxy, and privacy-first website analyticsRequest routing; aggregate cookieless analytics — page views, referrer, and approximate country from your IP

In addition, when you connect an alert channel, we send your alert content (the automation name, labels, correlation ID, and any metadata) to whichever destination you choose: Slack, Discord, Telegram, LINE, Teams, Webhook, or Email. You control which channels are connected.

We do not sell your personal data, and we do not share it for advertising.

International transfers

Our infrastructure and the providers above may process data in the United States and in other countries. When data is transferred out of your region, we rely on the safeguards those providers offer, such as Standard Contractual Clauses or the EU-US Data Privacy Framework, where applicable. You can ask us for more information about these safeguards by emailing support@checkilo.app.

Retention

We keep your monitoring data only as long as your plan allows.

  • Runs and their pings are kept for 90 days on every plan. A background job runs every day and deletes runs older than that; the pings attached to a deleted run are removed with it.
  • Alert logs are kept as an audit record even after the related run has been deleted, so there is a history of what we sent you.
  • Your profile is kept for as long as your account exists.

There is no self-serve account deletion today. Your profile stays until it is removed manually. To delete your account and data, email support@checkilo.app and we will handle it.

Security

We take reasonable steps to protect your data:

  • All traffic to and from Checkilo is encrypted in transit over HTTPS.
  • Access to the systems and database is limited by access controls.
  • Your password is handled by Supabase and is never stored by Checkilo.
  • Our error logs are scrubbed of personal data, including redacting email addresses.

No online service can promise perfect security, and we do not. But we work to keep your data safe.

Your rights

Depending on where you live, you have rights over your personal data. Under the PDPA, the GDPR, and UK GDPR these include the right to:

  • Access the personal data we hold about you.
  • Correct data that is wrong or incomplete (rectification).
  • Delete your data (erasure).
  • Restrict how we process it.
  • Receive a copy of your data in a portable form (portability).
  • Object to certain processing.
  • Withdraw consent where we relied on it.
  • Complain to a supervisory authority. In the United Kingdom this is the Information Commissioner’s Office (ICO). In the European Union this is your local data protection authority.

If you are a California resident, you also have the right to know what we collect, to delete it, and to correct it. As stated above, we do not sell your personal data and we do not share it for advertising.

To exercise any of these rights, email support@checkilo.app.

Cookies

We use only the cookies that are strictly necessary to sign you in and keep you signed in:

  • sb-access-token and sb-refresh-token keep your session active. They are HttpOnly, Secure in production, and set with SameSite set to Lax.
  • sb-oauth-state and sb-oauth-pkce-verifier are temporary cookies used only during sign-in with an outside provider. They last about 600 seconds and are then discarded.

For measuring website traffic we use Cloudflare Web Analytics, a privacy-first tool that records aggregate page views, referrers, and approximate country (derived from your IP address). It sets no cookies and does not track you across other websites. We use no advertising cookies and no cross-site tracking cookies anywhere. Because only strictly necessary cookies exist, there is no cookie consent banner.

Children

Checkilo is not directed to children under 16, and we do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, email support@checkilo.app and we will remove it.

Changes to this policy

We may update this policy from time to time. When we do, we change the “Last updated” date at the top. If a change is material, we will give reasonable notice.

Contact

For any privacy question or request, email us at support@checkilo.app.