Privacy policy
Effective July 10, 2026
Tell Me When Down is a monitoring service: you give us URLs, we check them and email you when something breaks. That works with very little personal data, so we keep very little. This page lists all of it.
What we collect
- Your account. Your email address, and a password if you sign up with one (stored hashed — we never see it). If you sign in with Google or GitHub, we receive your name, email, and avatar from them instead.
- Your monitored apps. The URLs you add, their check settings, and everything our checks observe about them: response times, status codes, TLS certificate details, security headers, and incident history.
- Alerts we send you. A log of the notification emails we sent and whether they were delivered.
- Payments. If you subscribe to a paid plan, Stripe processes the payment. We never see or store card numbers — only your plan and subscription status.
What we don't do
- No advertising and no ad trackers, anywhere on this site.
- We never sell or share your data with anyone, except the infrastructure providers below who run the service for us.
- We don't track you across other websites, and nothing we measure is tied to your account or your monitored apps.
- Our checks only look at what your site shows any visitor. We don't log in to your apps or read their private data.
Analytics and cookies
We measure how people find and use this site, so we know which pages are worth writing. Two tools, held to different standards:
- Plausible— our day-to-day traffic stats, which we run on our own server rather than sending to a third party. Cookieless: it sets nothing on your device, collects no personal data, and can't follow you to another site. It counts pages, referrers, and rough country-level location, and it runs for everyone.
- Google Analytics— used for a deeper view of where our search traffic comes from. It does set cookies, so we ask first: if you're in the EU, EEA, UK, or Switzerland, it stays off until you accept the banner, and declining is permanent — we won't re-ask or nag. Elsewhere it runs by default; if you'd rather it didn't, browser tracking protection or an ad blocker will stop it, and nothing on this site breaks when it's blocked.
The cookies we set ourselves are the ones that sign you in, plus two small ones for the above: your consent choice, so we can honour it, and a coarse region marker (country-level, from your connection) so we know whether to ask you in the first place.
Where your data lives
The service runs on a small set of infrastructure providers, each processing data only on our instructions:
- Supabase — database and authentication (US)
- Vercel — web application hosting
- Fly.io — check workers in the US, Europe, and Asia
- Resend — alert email delivery
- Stripe — payment processing, for paid plans
- Cloudflare — DNS and domain services
- Google Analytics — search and audience analytics, only with your consent where required
How long we keep it
As long as you have an account. Delete your account and we delete your data — monitored apps, check history, incidents, and alert logs — from the live database. Backups age out on a rolling basis shortly after.
Your rights
You can ask us for a copy of your data, ask us to correct it, or ask us to delete it, at any time. Email [email protected] and we'll handle it — no forms, no runaround.
Changes
If this policy changes in a way that matters, we'll email account holders before the change takes effect and update the date at the top of this page.