CronWarden

Privacy Policy

Last updated September 3, 2026

This policy explains what DTSaaS Labs LLC collects when you use CronWarden, why, who else sees it, and how long we keep it. It covers the CronWarden website, dashboard, API, and iOS app.

Three things worth stating up front, because they are the questions people usually have to dig for:

1. What we collect

Account

Your email address, and your name if you give one. If you sign in with a password we store only a hash of it, never the password. If you sign in with GitHub or Apple we store the link to that account — for Apple, the stable identifier Apple issues rather than anything you typed. We also store your chosen time zone and interface preferences, and the tokens behind magic sign-in links while they are valid.

Teams and billing

Your team name, its members and their roles, and pending invitations (which contain the invited email address until they are accepted or expire). For paid teams we store a customer identifier from our payment provider, the plan, billing cycle, subscription status, and renewal date. Of your card we hold only the brand and last four digits and a payment token that cannot be used to reconstruct the number.

Monitors and check-ins

The monitors you create — names, schedules, grace periods, thresholds, tags — and a record of every check-in they receive. Each check-in record includes the time, the reported duration or value, the IP address and user agent it came from, and the request body your job sent, truncated to 10 KB on the free plan and 100 KB on paid plans.

That body is whatever your job posts. If your job includes personal data in it, we store that personal data. Send only what you need for the check to be meaningful.

Alerts and integrations

Alert records, including when an alert fired, resolved, or was acknowledged, and the email address of whoever acknowledged it. The configuration of your alert channels — webhook URLs, bot tokens, service keys, and destination email addresses — is stored so we can deliver to them, and is masked in the interface after you save it.

Mobile app

If you enable push notifications, the push token Apple issues for your device, plus the device name you gave it, its platform, app version, and your notification preferences. This token identifies the device, not you.

Sales enquiries and feature requests

If you contact sales we store the name, email, company, team size, and message you send. If you file or upvote a feature request, we store it against your account so the same person cannot vote twice.

2. Why we process it

To provide the service you signed up for: authenticating you, running your monitors, delivering your alerts, billing you, and answering your support requests. To keep the service secure and working — investigating abuse, debugging failures, and enforcing plan limits. And to send you service messages such as alerts, invitations, billing notices, and material changes to these documents. We do not send marketing email you did not ask for.

Where the GDPR or UK GDPR applies, our lawful bases are performance of a contract (running the service and billing), legitimate interests (security, abuse prevention, service communications), and consent where you have given it.

3. Who else sees it

We use a small number of service providers, and only for the purposes below. We do not sell, rent, or trade personal data.

ProviderPurposeWhat they receive
Our own mail serviceSending alerts, invitations, sign-in links, and billing emailRecipient address and message contents
GitHub“Sign in with GitHub”Standard OAuth exchange; GitHub returns your email and name to us
Apple“Sign in with Apple” and push notificationsFor sign-in, nothing is sent to Apple by us. For push, the device token and the alert text — which includes the monitor name
Our payment providerTaking payment and managing subscriptionsYour card details, entered directly into their form, plus the team owner’s email and name
Google (Ads)Measuring which ads bring visitors to the public siteNo advertising cookies unless you accept the cookie banner. Until you do, the tag runs cookieless: nothing is stored on your device, though Google still receives limited, cookieless signals (such as the page address) that it uses only in aggregate — and if you subscribe to a paid plan, a cookieless conversion event carrying the plan price (never your card details or your identity). If you accept, Google additionally sets its advertising cookies and receives the page views and ad-click identifiers it uses for conversion measurement. It never runs in the signed-in product.
Our hosting providerRunning the servers and databaseEverything above, at rest and in transit through their infrastructure

Alert destinations you choose are different.When you connect Slack, Discord, Microsoft Teams, PagerDuty, Opsgenie, Telegram, Pushover, ntfy, Gotify, Matrix, Google Chat, Mattermost, Rocket.Chat, Zulip, or a plain webhook, we send your alerts there at your direction. Each alert contains the monitor name, the alert type, and links back to the dashboard. Once it arrives, that service’s own privacy policy governs it. We are not able to delete messages we have already delivered to a destination you control.

We may also disclose data where the law requires it, or to establish or defend legal claims. If we are ever acquired, data may transfer as part of the business, and we will say so before it happens.

4. How long we keep it

Check-in history and resolved alerts are pruned daily against a window that depends on your plan:

PlanCheck-in and resolved-alert history
Free7 days
Starter30 days
Pro365 days
Business18 months
Enterprise18 months, or as agreed

Unresolved alerts are never pruned — an open incident stays until it is closed.

Everything else follows the shortest window that still lets the feature work:

5. Cookies and local storage

The signed-in product sets no advertising or analytics cookies. Its only cookies are the ones that keep you signed in and protect the sign-in flow against cross-site request forgery, set by our authentication library on the cronwarden.com domain. Clearing them signs you out.

Our public pages (the landing page, pricing, docs, and other pages you can read without signing in) load a Google Ads tag. By default it runs in cookieless mode: it stores nothing on your device, and Google receives only limited, cookieless signals (such as the page address) used in aggregate. If you accept the consent banner, Google sets its advertising cookies for conversion measurement; if you decline, or never answer, no advertising cookies are set and no identifier ties your visit to you. You can change your choice at any time with the “Cookie preferences” link in the footer. The tag does not load anywhere in the signed-in product.

In your browser’s local storage we keep three preferences: whether the dashboard sidebar is collapsed, whether you chose light or dark mode, and your cookie-banner answer (under cw-ads-consent). None of them leaves your device.

6. Security

Traffic is encrypted in transit. Passwords are stored hashed. API keys, mobile session tokens, and sign-in links are stored as hashes — we can verify one you present, but we cannot show you an existing one, which is why a new API key is displayed exactly once. Access to production data is limited to the people who operate the service.

Check-in URLs, badge keys, and acknowledgement links are unguessable by design and act as credentials in their own right. Treat them accordingly: anyone who has one can use it. You can rotate a check-in key or a badge key at any time.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and any required regulator without undue delay.

7. Your rights

You can access and correct most of your data directly in the dashboard. For anything else — a copy of your data, correction, deletion, restriction, objection, or portability — or write to support@cronwarden.com, and we will respond within 30 days.

Deleting your account.You can delete your account from the CronWarden iOS app, or by writing to us. Deletion removes your monitors, check-in history, alerts, integrations, API keys, invitations, and sessions for every team you solely own, along with the account itself. A team with other members has to be transferred to another admin first — we will not delete other people’s data along with yours. Deletion is permanent and we cannot undo it.

If you are in the EU, UK, or Switzerland you may also complain to your supervisory authority. If you are a California resident: we do not sell personal information, and the only “sharing” as the CCPA uses that term is the consent-gated Google Ads tag on our public pages — declining the cookie banner (or never accepting it) prevents the advertising cookies and identifiers that cross-context behavioral advertising relies on, and we will not discriminate against you for exercising your rights.

8. International transfers

CronWarden is operated from the United States, and data is stored and processed there. If you use the service from outside the US, you are sending your data to the US, where protections may differ from those in your country.

9. Children

CronWarden is not for people under 16. We do not knowingly collect their data; if we learn that we have, we will delete it.

10. Changes

We will update this policy as the service changes. The date at the top always reflects the latest revision, and we will give notice by email or in the app before a material change takes effect.

11. Contact

DTSaaS Labs LLC
support@cronwarden.com

See also our Terms of Service.