Privacy Policy
Last updated September 3, 2026
This policy explains what DTSaaS Labs LLC collects when you use CronWarden, why, who else sees it, and how long we keep it. It covers the CronWarden website, dashboard, API, and iOS app.
Three things worth stating up front, because they are the questions people usually have to dig for:
- The product itself has no trackers. The dashboard, API, and iOS app contain no analytics, no session recorder, and no third-party error-reporting service. Our public marketing pages carry one Google Ads tag so we can tell which of our ads work; it stays cookieless until you accept the consent banner, and it never loads in the signed-in product. Details in the cookies section.
- We never see your card details.They are entered inside our payment provider’s own form and never reach our servers.
- We do not sell your data, and we do not use the contents of your check-ins to train machine learning models.
1. What we collect
Account
Your email address, and your name if you give one. If you sign in with a password we store only a hash of it, never the password. If you sign in with GitHub or Apple we store the link to that account — for Apple, the stable identifier Apple issues rather than anything you typed. We also store your chosen time zone and interface preferences, and the tokens behind magic sign-in links while they are valid.
Teams and billing
Your team name, its members and their roles, and pending invitations (which contain the invited email address until they are accepted or expire). For paid teams we store a customer identifier from our payment provider, the plan, billing cycle, subscription status, and renewal date. Of your card we hold only the brand and last four digits and a payment token that cannot be used to reconstruct the number.
Monitors and check-ins
The monitors you create — names, schedules, grace periods, thresholds, tags — and a record of every check-in they receive. Each check-in record includes the time, the reported duration or value, the IP address and user agent it came from, and the request body your job sent, truncated to 10 KB on the free plan and 100 KB on paid plans.
That body is whatever your job posts. If your job includes personal data in it, we store that personal data. Send only what you need for the check to be meaningful.
Alerts and integrations
Alert records, including when an alert fired, resolved, or was acknowledged, and the email address of whoever acknowledged it. The configuration of your alert channels — webhook URLs, bot tokens, service keys, and destination email addresses — is stored so we can deliver to them, and is masked in the interface after you save it.
Mobile app
If you enable push notifications, the push token Apple issues for your device, plus the device name you gave it, its platform, app version, and your notification preferences. This token identifies the device, not you.
Sales enquiries and feature requests
If you contact sales we store the name, email, company, team size, and message you send. If you file or upvote a feature request, we store it against your account so the same person cannot vote twice.
2. Why we process it
To provide the service you signed up for: authenticating you, running your monitors, delivering your alerts, billing you, and answering your support requests. To keep the service secure and working — investigating abuse, debugging failures, and enforcing plan limits. And to send you service messages such as alerts, invitations, billing notices, and material changes to these documents. We do not send marketing email you did not ask for.
Where the GDPR or UK GDPR applies, our lawful bases are performance of a contract (running the service and billing), legitimate interests (security, abuse prevention, service communications), and consent where you have given it.
3. Who else sees it
We use a small number of service providers, and only for the purposes below. We do not sell, rent, or trade personal data.
| Provider | Purpose | What they receive |
|---|---|---|
| Our own mail service | Sending alerts, invitations, sign-in links, and billing email | Recipient address and message contents |
| GitHub | “Sign in with GitHub” | Standard OAuth exchange; GitHub returns your email and name to us |
| Apple | “Sign in with Apple” and push notifications | For sign-in, nothing is sent to Apple by us. For push, the device token and the alert text — which includes the monitor name |
| Our payment provider | Taking payment and managing subscriptions | Your card details, entered directly into their form, plus the team owner’s email and name |
| Google (Ads) | Measuring which ads bring visitors to the public site | No advertising cookies unless you accept the cookie banner. Until you do, the tag runs cookieless: nothing is stored on your device, though Google still receives limited, cookieless signals (such as the page address) that it uses only in aggregate — and if you subscribe to a paid plan, a cookieless conversion event carrying the plan price (never your card details or your identity). If you accept, Google additionally sets its advertising cookies and receives the page views and ad-click identifiers it uses for conversion measurement. It never runs in the signed-in product. |
| Our hosting provider | Running the servers and database | Everything above, at rest and in transit through their infrastructure |
Alert destinations you choose are different.When you connect Slack, Discord, Microsoft Teams, PagerDuty, Opsgenie, Telegram, Pushover, ntfy, Gotify, Matrix, Google Chat, Mattermost, Rocket.Chat, Zulip, or a plain webhook, we send your alerts there at your direction. Each alert contains the monitor name, the alert type, and links back to the dashboard. Once it arrives, that service’s own privacy policy governs it. We are not able to delete messages we have already delivered to a destination you control.
We may also disclose data where the law requires it, or to establish or defend legal claims. If we are ever acquired, data may transfer as part of the business, and we will say so before it happens.
4. How long we keep it
Check-in history and resolved alerts are pruned daily against a window that depends on your plan:
| Plan | Check-in and resolved-alert history |
|---|---|
| Free | 7 days |
| Starter | 30 days |
| Pro | 365 days |
| Business | 18 months |
| Enterprise | 18 months, or as agreed |
Unresolved alerts are never pruned — an open incident stays until it is closed.
Everything else follows the shortest window that still lets the feature work:
- Sign-in links expire 15 minutes after they are sent.
- Team invitations expire 7 days after they are sent.
- Mobile sessions expire 90 days after last use.
- Account, team, monitor, and integration records are kept until you delete them or close your account.
5. Cookies and local storage
The signed-in product sets no advertising or analytics cookies. Its only cookies are the ones that keep you signed in and protect the sign-in flow against cross-site request forgery, set by our authentication library on the cronwarden.com domain. Clearing them signs you out.
Our public pages (the landing page, pricing, docs, and other pages you can read without signing in) load a Google Ads tag. By default it runs in cookieless mode: it stores nothing on your device, and Google receives only limited, cookieless signals (such as the page address) used in aggregate. If you accept the consent banner, Google sets its advertising cookies for conversion measurement; if you decline, or never answer, no advertising cookies are set and no identifier ties your visit to you. You can change your choice at any time with the “Cookie preferences” link in the footer. The tag does not load anywhere in the signed-in product.
In your browser’s local storage we keep three preferences: whether the dashboard sidebar is collapsed, whether you chose light or dark mode, and your cookie-banner answer (under cw-ads-consent). None of them leaves your device.
6. Security
Traffic is encrypted in transit. Passwords are stored hashed. API keys, mobile session tokens, and sign-in links are stored as hashes — we can verify one you present, but we cannot show you an existing one, which is why a new API key is displayed exactly once. Access to production data is limited to the people who operate the service.
Check-in URLs, badge keys, and acknowledgement links are unguessable by design and act as credentials in their own right. Treat them accordingly: anyone who has one can use it. You can rotate a check-in key or a badge key at any time.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and any required regulator without undue delay.
7. Your rights
You can access and correct most of your data directly in the dashboard. For anything else — a copy of your data, correction, deletion, restriction, objection, or portability — or write to support@cronwarden.com, and we will respond within 30 days.
Deleting your account.You can delete your account from the CronWarden iOS app, or by writing to us. Deletion removes your monitors, check-in history, alerts, integrations, API keys, invitations, and sessions for every team you solely own, along with the account itself. A team with other members has to be transferred to another admin first — we will not delete other people’s data along with yours. Deletion is permanent and we cannot undo it.
If you are in the EU, UK, or Switzerland you may also complain to your supervisory authority. If you are a California resident: we do not sell personal information, and the only “sharing” as the CCPA uses that term is the consent-gated Google Ads tag on our public pages — declining the cookie banner (or never accepting it) prevents the advertising cookies and identifiers that cross-context behavioral advertising relies on, and we will not discriminate against you for exercising your rights.
8. International transfers
CronWarden is operated from the United States, and data is stored and processed there. If you use the service from outside the US, you are sending your data to the US, where protections may differ from those in your country.
9. Children
CronWarden is not for people under 16. We do not knowingly collect their data; if we learn that we have, we will delete it.
10. Changes
We will update this policy as the service changes. The date at the top always reflects the latest revision, and we will give notice by email or in the app before a material change takes effect.
11. Contact
DTSaaS Labs LLC
support@cronwarden.com
See also our Terms of Service.