Legal
Privacy Policy
How Alertum collects, uses, and protects information across the platform.
Last updated: May 24, 2026
1. Introduction
Alertum (“Alertum”, “we”, “our”, or “us”) operates a SaaS platform for uptime monitoring, incident management, alerting, synthetic journey monitoring, heartbeat monitoring, public and private status pages, maintenance windows, diagnostics, and related operational observability services (collectively, the “Service”).
This Privacy Policy describes how we collect, use, disclose, and protect information when you access or use the Service. By using Alertum you agree to the practices described here. If you do not agree, please stop using the Service.
2. Information We Collect
Account Information
When you register, we collect your name, email address, hashed password or third-party authentication provider identifiers, and any other profile details you provide.
Team and Workspace Information
We collect team and workspace names, member email addresses, roles, and invitation details for the workspaces you create or join within Alertum.
Monitoring Configuration
We store the configuration data you provide to operate the Service, including monitor names, target URLs, domains and endpoints, HTTP methods and headers, expected response patterns, check intervals and timeouts, synthetic journey steps, heartbeat names and schedules, and related operational parameters.
Do not include secrets, passwords, private API keys, authentication tokens, or sensitive personal data in monitor names, URLs, request headers, request bodies, or expected response fields unless strictly necessary for the monitoring function. See Section 4 for more detail.
Incident and Operational Data
We collect data generated by the Service’s incident management features, including incident reports, comments, assignments, status changes, escalation activity, alert records, maintenance window configurations, and timeline events.
Notification Data
We store notification preferences, delivery channels, and the email addresses and integration endpoints you configure for alert and incident notifications.
Billing Information
Billing and payment data is processed by our payment processor. We retain limited billing metadata such as subscription plan, renewal dates, billing email address, and invoice records. We do not store full payment card numbers.
Usage, Log, and Device Data
We automatically collect technical data when you use the Service, including IP addresses, browser type, device identifiers, pages and features used, session durations, timestamps, application actions, diagnostic information, and error logs.
Support Communications
We retain the content of support requests and communications you send us in order to assist you and improve the Service.
3. How We Use Information
- Provide and operate the Service, including running monitors, journeys, and heartbeat checks.
- Send alert notifications, on-call pages, escalation messages, and operational updates via channels you configure.
- Manage incidents and maintenance windows.
- Power public and private status pages.
- Process billing and manage subscriptions.
- Detect and prevent security threats, abuse, and unauthorized access.
- Improve the reliability, performance, and features of the Service.
- Provide customer support and respond to inquiries.
- Send service announcements and policy updates.
- Comply with applicable legal obligations.
4. Monitoring Data and Sensitive Information
As part of the Service, Alertum executes HTTP requests, DNS lookups, heartbeat checks, and synthetic journey steps against the targets you configure. We store configuration data, check results, response metadata, and uptime history to power dashboards, alerts, and status pages.
You are responsible for the content you include in monitor and journey configurations. Do not place passwords, private API keys, authentication tokens, personally identifiable information (PII), protected health information (PHI), or other sensitive or confidential data in monitor names, target URLs, request headers, request bodies, expected response patterns, incident comments, or status page content unless strictly necessary. If sensitive credentials must appear in a request header or authentication field, treat them as production secrets and rotate them regularly.
Public status pages expose the content you intentionally publish. You are responsible for ensuring that content does not include sensitive, confidential, or personally identifiable information you do not intend to make publicly visible.
5. Cookies and Similar Technologies
We use cookies and similar technologies to maintain authenticated sessions, remember preferences, and understand how the Service is used. You may configure your browser to refuse cookies, but some Service features may not function correctly without them.
We may use first-party analytics to understand product usage patterns. We do not use advertising cookies or sell cookie data to third parties.
6. Third-Party Services and Processors
We work with trusted third-party service providers who process data on our behalf under appropriate data processing agreements. Categories include:
- Hosting and infrastructure: Cloud servers, databases, and storage providers required to operate the Service.
- Email and notification delivery: Providers used to send transactional email, SMS, and other notifications.
- Payment processing: Payment card processing and subscription management (currently Stripe). Your payment data is handled directly by the payment processor under their own terms.
- Analytics and error tracking: Services that help us detect application errors and understand product usage.
- User-configured integrations: Third-party services you explicitly connect to Alertum (such as Slack, webhooks, or on-call tools). Data shared with these services is governed by your configuration and the third party’s own policies.
7. How We Share Information
We do not sell your personal data. We share information only in these circumstances:
- With service providers operating on our behalf as described in Section 6.
- With other members of your Alertum team or workspace to the extent required for collaborative features.
- If required by law, regulation, legal process, or governmental authority.
- To protect the rights, property, or safety of Alertum, our users, or the public.
- In connection with a merger, acquisition, or sale of business assets, subject to confidentiality protections.
- Through integrations and delivery channels you explicitly configure.
8. Data Retention
We retain your data while your account is active or as needed to provide the Service. Upon account deletion, we delete or anonymize your data within a reasonable period except where we are required to retain it for legal, compliance, or audit purposes. Check results, uptime history, and incident data may be retained for periods defined by your subscription plan.
9. Security
We apply industry-standard security practices including encrypted data transmission (TLS), hashed password storage, access controls, and monitoring for unauthorized activity. No system is completely secure, and we cannot guarantee absolute security. Use strong, unique credentials and keep them confidential.
10. International Data Transfers
Alertum may store and process data in countries other than your own. If you are located in a jurisdiction with data transfer restrictions, we rely on applicable lawful transfer mechanisms. Contact us with questions about data transfers.
11. Your Rights and Choices
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Correct inaccurate personal data.
- Request deletion of your personal data, subject to legal obligations.
- Object to or restrict certain processing.
- Receive a portable copy of your data.
- Withdraw consent where processing is based on consent.
To exercise these rights, contact us at product@alertum.co.
12. Team and Workspace Administrators
If you use Alertum within an organization, the workspace administrator may have access to account activity, monitor configurations, incidents, and other workspace data. Administrators are responsible for ensuring appropriate use within their teams.
13. Public Status Pages
Content published to a public status page — including service names, incident messages, and uptime information — is visible to anyone with the page URL or custom domain. You are responsible for the content you publish and must not include sensitive, confidential, or personally identifiable information you do not intend to make public.
14. Children’s Privacy
The Service is not directed at individuals under 16. We do not knowingly collect personal data from children. If you believe we have done so inadvertently, contact us and we will delete it promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by updating the “Last updated” date and, where appropriate, via email or in-app notice. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
16. Contact
For privacy questions or requests, contact us at: