AlertKite
← AlertKite

Privacy

What we collect, why we collect it, who else touches it, and how long we keep it. Specific rather than general, because a policy that could describe any company describes nothing.

Last updated 16 September 2026

What we collect about you

Only what the product needs to work:

  • Your email address, to sign you in and to send you alerts. Authentication is handled by Supabase; we never see or store your password.
  • What you asked us to watch — the URLs, hostnames and schedules of your monitors, and the names you gave them.
  • Alert recipients — the email addresses, phone numbers and chat webhooks you tell us to notify.
  • Credentials you give a monitor, where you are checking an authenticated endpoint. These are sealed with AES-256-GCM before they are written down, are never returned to the browser, and can be replaced but not read back — including by us.
  • Billing details are handled entirely by Polar, our merchant of record. We receive a subscription status and a customer id. We never see your card.

What we collect about your visitors

Site Insights is our analytics product. If you add a site and install the snippet, we record a page view, the path, the referring domain, a coarse device and browser, a country, and real performance timings from the visitor's own device.

There is no cookie, and nothing is stored on the visitor's device. A visitor is identified by a hash of their IP address, their user agent, the site, and a secret salt that includes the current UTC date. The IP is used to compute that hash and to resolve a country, and is then discarded — it is never written to our database.

Because the date is part of the salt, the identifier changes at midnight UTC and the same person cannot be recognised across two days. That is a deliberate limit on what we are able to know: it means we cannot tell you how many unique people visited last week, and it means no profile of a visitor can be built, by us or by anyone who obtained our data.

What we never do

  • We do not sell your data, or your visitors' data, to anyone.
  • We do not run advertising, and we do not embed anyone else's advertising or tracking code on our site or in our snippet.
  • We do not read the content of the pages we monitor beyond the check you configured — a status code, a keyword, or a JSON path.
  • We do not store raw IP addresses of your visitors.

Who else processes it

We are a small operation and we do not run our own hardware. These are the companies that necessarily handle data on our behalf:

  • Supabase — the database and authentication. Hosted in AWS ap-northeast-2 (Seoul).
  • Vercel — hosts the website and dashboard.
  • Fly.io — runs the checker that performs monitoring and sends alerts, in Tokyo.
  • Resend — delivers alert email.
  • Polar — merchant of record for all payments.
  • Cloudflare — DNS and inbound email routing.
  • Meta — WhatsApp delivery, once that channel is live. Nothing is sent to Meta today.

How long we keep it

Check results and analytics events are kept for as long as your plan retains them — one day on Free, 90 days on Pro, 365 days on Business — and are then deleted. Daily summaries outlive the individual events.

Everything else lasts as long as your account. Delete a monitor and its history goes with it; delete your account and we remove your data.

Your rights

You can export or delete your data at any time, and you can ask us what we hold about you. Write to hello@alertkite.com and a person will answer.

If you use Site Insights, you are the controller of your visitors' data and we are your processor. We believe the design above means you do not need a consent banner for our analytics, because nothing is stored on a visitor's device and no identifier survives the day — but we are not your lawyers, and your own obligations are yours to assess.

Changes

If we change this in a way that affects what we collect, we will say so by email before it takes effect rather than quietly changing the date at the top.