1. Scope and contact
This notice applies to checkfast.io and the CheckFast service. CheckFast, the operator of checkfast.io, determines how service account and product data is processed. For privacy, security, access, correction, or deletion questions, contact security@checkfast.io.
This notice does not cover a website you ask CheckFast to inspect or the independent services linked from a report. Their own notices and practices apply.
2. Information processed
- Account and authentication: email address, name when supplied, account and provider identifiers, plan, sign-in events, and Telegram identity details when you choose Telegram sign-in or linking.
- Checks and reports: submitted domains or URLs, tool inputs, technical results, scores, findings, timestamps, and whether a report is public.
- Monitoring and alerts: targets, schedules, expected results, monitor history, cron-heartbeat events, alert messages, and the Telegram, Slack, email, or webhook destinations you configure.
- Billing: plan, Lemon Squeezy customer, subscription and variant identifiers, status, and paid-period dates. Payment-card details are collected by Lemon Squeezy, not stored in the CheckFast database.
- Security and operations: session data, API-key hashes, rate-limit counters, request metadata, audit records, error telemetry, and IP-derived data needed to prevent abuse or diagnose failures. Cron pings and Webhook Tester captures can include a source IP, user agent, headers, query values, and a capped payload supplied by the caller.
- Product analytics: event name, sanitized page path, low-cardinality feature and acquisition properties, and keyed hashes of session or submitted host identifiers. The first-party analytics contract excludes raw emails, full URLs, user IDs, record IDs, and raw IP addresses.
3. How information is obtained and used
Information comes from you, your browser or API client, configured integrations, authentication and billing providers, the public internet, and the target systems you ask CheckFast to inspect. It is used to authenticate users, run checks, publish reports, schedule monitoring, send alerts, enforce limits, process subscriptions, provide support, prevent abuse, diagnose incidents, improve product flows, and comply with applicable obligations.
CheckFast does not use generated policy text as legal advice and does not require you to submit private personal data to use public diagnostic tools.
4. Public reports and outbound checks
Supported diagnostic flows persist a normalized host and findings in shareable public reports. Public reports can be viewed without an account and indexed by search engines. Do not place credentials, tokens, personal data, private hostnames, or confidential URL paths in a public-check input. When an account is deleted, retained public reports are detached from the account identity.
Waitlist entries, public reports, pseudonymous analytics, runtime logs, and backups are not necessarily removed by account deletion and follow separate operational or legal retention requirements.
Running a check sends requests to the target host and may query DNS, certificate, registration, performance, reputation, or other public technical services. Those recipients receive the network information ordinarily needed to answer the request and may process it under their own policies.
5. Service providers and disclosures
Information is disclosed only as needed to operate the requested function, including:
- Supabase for authentication and application database services;
- Google or GitHub when you choose the corresponding OAuth provider;
- Lemon Squeezy as merchant of record and subscription provider;
- Telegram, Slack, email-delivery, or webhook recipients when you configure an alert channel;
- Sentry when production error reporting is enabled, and a self-hosted Umami endpoint when optional external analytics is enabled;
- hosting, network, DNS, and security providers needed to operate checkfast.io;
- authorities or other parties when required by law or necessary to protect rights.
The documented service design does not implement the sale of personal information or cross-context behavioral advertising. The operator must update this notice and provide any required choices before activating either use.
6. Retention
Configured cleanup targets currently include:
- Webhook Tester endpoints and captures: approximately 24 hours;
- Telegram login state: up to 24 hours;
- rate-limit counters, including keyed IP hashes: 7 days;
- Lemon Squeezy webhook payloads: 30 days;
- cron-heartbeat pings and API usage logs: 90 days;
- first-party product analytics: 180 days;
- waitlist entries, delivered alert history, and mutation audit records: 365 days;
- unlinked anonymous Auth identities: 90 days by default, with a 30-day floor;
- monitor-run history: the current month plus up to 12 prior monthly partitions.
Account resources are otherwise retained while the account is active or as needed to provide the service. Deletion removes private checks, monitors, alerts, cron jobs, API keys, local subscription records, account-linked provider payloads and audit records, then removes the authentication identity. Public reports remain without account linkage. Providers can retain transaction, security, and compliance records under their own legal obligations and policies.
7. Choices, access, and deletion
Account settings let you change notification destinations, manage billing, and delete the account. Account deletion first verifies cancellation of chargeable Lemon Squeezy subscriptions; it fails closed if provider cancellation cannot be confirmed. You can also contact the address above to request access, correction, deletion, restriction, or another privacy right that applies to your circumstances. Identity verification and lawful exceptions may be required.
Browser session storage holds theme, attribution, and analytics-session values. You can clear it in browser settings. Optional self-hosted Umami remains disabled unless the deployment explicitly configures it. CheckFast does not load Google Analytics in the documented application runtime.
8. Security and international processing
CheckFast uses access controls, row-level database policies, scoped service operations, keyed hashes, bounded retention, signed webhooks, rate limits, and encrypted transport. No online service can guarantee absolute security. Report a suspected vulnerability to security@checkfast.io.
The service and its providers may process information in countries other than your own. Applicable contractual, legal, and provider safeguards govern those transfers. Contact CheckFast if you need information for a specific jurisdiction or procurement review.
9. Children and changes
CheckFast is a technical service for people able to authorize website testing and is not directed to children. Do not submit a child's personal information through public tools or monitoring inputs.
The effective date and version above identify this notice. Material changes will be published here and, where appropriate, communicated through the service or account contact. The Terms of Service explain the service contract separately from this notice.