Legal / Privacy

Privacy Policy

What SystemVitals collects, why we need it, and the controls you have over your data.

Effective July 25, 2026
01

Scope and controller

This Privacy Policy explains how SystemVitals collects, uses, shares, and protects personal data when you use our websites, applications, APIs, MCP integrations, monitoring infrastructure, and related services (the “Service”).

SystemVitals is the controller of account and product-usage data. An organization may be the controller of data it submits to the Service, with SystemVitals acting as its processor or service provider.

02

Data we collect

  • Account data: email address, encrypted password credentials, Google account identifiers when used, organization memberships, roles, and preferences.
  • Monitoring data: check names, target URLs, hostnames, IP addresses, heartbeat events, response metadata, incidents, status-page content, and alert configuration.
  • Integration data: notification destinations, webhook configuration, API-token metadata and permissions. Secret token values are shown only when created and are stored as hashes.
  • Telegram connection data: Telegram destination identifiers, titles, and topic identifiers, connection commands, and notification delivery results. We process connection commands used to set up a destination, not ordinary group messages. Alert content is shared with Telegram for delivery.
  • Billing data: plan, subscription status, billing identifiers, and transaction metadata. Stripe receives and processes full payment-card details; SystemVitals does not store them.
  • Technical data: IP address, user agent, request logs, timestamps, error reports, security events, and approximate location inferred from IP where available.
  • Communications: messages and support requests you send to us.

Monitoring targets and payloads may contain personal data depending on how you configure them. Do not submit sensitive data that is not necessary for monitoring.

03

How we use data

We process data to:

  • provide checks, incident history, alerts, status pages, APIs, and MCP access;
  • authenticate users and administer organizations, roles, plans, and billing;
  • secure the Service, prevent abuse, investigate incidents, and enforce our terms;
  • support users and communicate service, security, and policy updates;
  • measure reliability and improve features using aggregated or de-identified data; and
  • meet tax, accounting, legal, and regulatory obligations.

We do not sell personal data or use monitoring data for third-party behavioral advertising.

05

How data is shared

We share data only as needed with:

  • infrastructure, database, email, observability, and security providers that operate the Service for us;
  • Stripe for payment and subscription management;
  • Google when you choose Google sign-in;
  • email, Slack, Telegram, and webhook providers you configure to receive alerts;
  • members of organizations according to their roles and permissions;
  • professional advisers, authorities, or other parties when required by law or necessary to protect rights and safety; and
  • a successor in a merger, financing, acquisition, or sale, subject to appropriate confidentiality protections.

Public status pages intentionally disclose the names, status, and incident information that an authorized user chooses to publish.

06

Retention

We retain account and configuration data while your account is active and as needed to provide the Service. Monitoring events and operational logs are retained according to plan limits, security needs, and reasonable backup cycles.

After deletion, data may remain temporarily in backups and may be retained longer where required for fraud prevention, dispute resolution, accounting, or law. We delete or de-identify it when the applicable purpose and retention period end.

07

Security

We use administrative, technical, and organizational safeguards designed to protect data, including access controls, encryption in transit, credential hashing, secret minimization, logging, and infrastructure isolation.

No system is completely secure. You are responsible for securing your account, limiting token permissions, revoking unused tokens, and protecting notification destinations and monitored systems.

08

International transfers

Our providers may process data in countries other than yours. Where required, we use recognized safeguards for international transfers, such as contractual protections, adequacy decisions, or another lawful transfer mechanism.

09

Your privacy rights

Depending on your location, including under Brazil’s LGPD or the European GDPR, you may have rights to confirm processing; access, correct, export, delete, or anonymize data; restrict or object to processing; withdraw consent; and receive information about sharing.

Send requests to support@systemvitals.link. We may verify your identity and authority before acting. You may also complain to your local data-protection authority. If your organization controls the data, contact its owner first; we will assist the organization as required.

10

Cookies and local storage

We use storage necessary to authenticate you, maintain security, and remember essential preferences. The web application stores the session token in your browser’s local storage. We do not use third-party advertising cookies. Browser settings may clear stored data, but disabling required storage can prevent sign-in.

11

Children

The Service is intended for people who can legally enter a contract and is not directed to children under 13. If local law requires a higher minimum age for independent consent, that age applies. Contact us if you believe a child provided personal data improperly.

12

Changes and contact

We may update this policy as the Service or law changes. We will post the revised version, update the effective date, and provide reasonable notice of material changes.

Questions, complaints, and data requests can be sent to support@systemvitals.link.

Questions about these terms?

Contact us at support@systemvitals.link.