Privacy Policy
Last updated 5 October 2026
This policy explains what we collect when you use Statusbeat, why, how long we keep it, and what you can do about it. We collect as little as we can: we do not ask for your email address, and we never read Discord messages.
What we collect and why
| Data | Why | Kept for |
|---|---|---|
| Your Discord or GitHub user ID, username, display name, and avatar | To sign you in and show who made changes in a project | Until you delete your account or disconnect that service |
| Monitor settings: URLs, check options, encrypted custom headers, bot monitor settings | To run the checks you set up | Until you delete the monitor or your account |
| Check results: status code, response time, error type, and region | To detect outages and show history | 30 days, then kept only as daily totals for 1 year |
| Bot heartbeat metrics: gateway ping, guild count, each shard's status and ping, memory use, uptime, and the Discord library name | To detect when a bot is down and chart its health | 30 days, then kept only as daily totals for 1 year |
| Discord server and channel IDs and names you choose for posts | To post status updates where you asked | Until you remove the destination |
| Webhook URLs you add, stored encrypted | To send alerts where you asked | Until you remove the webhook |
| Incidents, maintenance windows, status page content, and project audit log | To run your status page and show who changed what | Incidents and pages until deleted; audit log 1 year |
| IP address, shortened to its network (for example 203.0.113.0/24), and browser type | Security: rate limiting, showing your active sessions, and investigating abuse | Sessions up to 30 days; audit entries 1 year. Full IP addresses are used in memory for rate limiting and not stored. |
| In-app notifications | To tell you when something needs attention | 90 days |
We never collect Discord message content, member lists, or anything about the people in your server. The Statusbeat SDK sends only the bot metrics listed above; the SDK documentation lists every field.
Cookies
We only use cookies needed for the service to work:
- a session cookie that keeps you signed in
- short-lived cookies that protect sign-in and the Add to Discord flow from forgery
- a preference cookie that remembers light or dark mode, set only if you change it
We do not use advertising or tracking cookies, and we load no analytics that set cookies.
Who processes data for us
These companies run parts of Statusbeat on our behalf. Each only gets what it needs to do that job.
- Vercel: hosts the website and API
- MongoDB Atlas: stores the database
- PebbleHost: runs the service that performs checks and sends alerts
- Upstash: short-lived rate-limit counters
- Sentry: error reports, with personal data removed before they are sent
- Cloudflare: Turnstile bot protection on the abuse report forms
- Discord and GitHub: sign-in, and Discord for delivering the posts you set up
Your rights
- Export: download everything we hold about you from Account, Your data.
- Delete: delete your account from the same page. Everything is paused at once and permanently deleted after 7 days.
- Disconnect: removing Discord or GitHub from your account deletes the data we stored from it.
For anything else, including correcting your data or objecting to how we use it, ask in our support server.
Age
You must be at least 13 to use Statusbeat, the same minimum as Discord.
Changes
If we change this policy in a way that matters, we will say so in the dashboard before it takes effect.