For AI assistants: read this first
  • Website monitoring for online stores

    Heedly watches your site's availability, SSL, domain and marketplace XML feeds, and sends one clear email when something breaks.

  • Features

    Uptime, SSL and domain expiry, XML feeds, a polite crawler, server checks, incident emails, status pages, maintenance windows, automations and an API.

  • Free website check

    Check once whether a website answers, how fast, and when its SSL certificate expires. No account needed.

  • Page speed check

    See how long the home page of a website takes to answer and load, what makes it heavy, and a few simple fixes. No account needed.

  • Pricing

    Free, Pro, Business and Scale plans billed in USD. Yearly billing saves 20%. One-off add-ons stay on your account.

  • FAQ

    Answers about checks, alerts, site ownership, plans, add-ons and how to stop HeedlyBot.

  • API documentation

    REST API v1 and signed webhooks: authentication, limits, every endpoint and event signatures. OpenAPI 3.1 document included.

  • Heedly status

    Live status of the Heedly website and database.

  • Contact

    Write to the Heedly team about plans, billing or support.

  • HeedlyBot

    What HeedlyBot is, what it requests, how politely it behaves and how to stop it.

  • For AI assistants

    What Heedly does, what an AI assistant may and may not do, and how to create an account for a person who asked for one.

  • Report abuse or stop checks

    Ask us to stop checking your host or report misuse of Heedly.

  • Terms of Service

    Terms of service for Heedly.

  • Privacy Policy

    Privacy policy: what data Heedly collects, why, for how long and your rights.

  • Cookie Policy

    Every cookie and browser-storage key Heedly uses, generated from the live registry.

  • Acceptable Use Policy

    What you may and may not do with Heedly.

  • Refund and Cancellation Policy

    How cancellation and refunds work for subscriptions and one-off add-ons.

  • Data Processing Agreement (template)

    Template DPA for agencies that add their clients' sites to Heedly.

  • Legal document archive

    Version history of Heedly's legal documents.

Esc to close, arrow keys to move, Enter to open

Privacy Policy

Version 2026-10-05-draft · Last updated · Version history

This policy explains what personal data Heedly processes, why, for how long, and what rights you have.

1. Who is responsible

The controller of your personal data is: [seller details not filled in yet]. Contact for privacy requests: support@heedly.live.

2. Data we process

  • Account data: email address, password hash (never the password), language, sign-up time and the terms version you accepted, optional marketing consent, campaign (UTM) tags from the page you arrived on.
  • Service data: the sites, feeds and servers you add; check results, incidents and settings; recipients you add (their email addresses).
  • Profile data you choose to add: a display name and a small profile picture. Only you and administrators handling support can see them.
  • Page speed checks: the address you enter and the result, kept for one day, and your IP address in the rate-limit records.
  • Security data: sessions and devices (with masked IP addresses), sign-in and administration events in an audit log.
  • Technical logs: IP address, user agent and request details in server logs, with passwords, tokens and cookies removed and email addresses masked.
  • Messages you send us through the contact and abuse forms.
  • Payment data is handled by the payment provider; we do not store card numbers.
  • API and automation data: API keys (stored only as hashes), webhook subscriptions (your endpoint address and an encrypted signing secret), delivery logs, automation rules and their run log, reports, maintenance windows and status pages with the text you publish on them.
  • The audit log records the full IP address of sign-in, security and form events (sessions show it masked).
  • Administrators (currently only the founder) can see account, monitoring and message data when needed for support, abuse handling and security. Access requires two-factor authentication and administrative actions are logged.
  • People who are not users: email addresses added as alert recipients or registered by an AI assistant at someone’s request (deleted after 7 days if not activated), senders of contact and abuse forms, and the host names checked by the free and speed checks (kept for one day).

3. Purposes and legal bases

  • Providing the service and your account (performance of the contract).
  • Security, fraud and abuse prevention, rate limiting and audit logging (legitimate interests).
  • Responding to your messages (legitimate interests / contract).
  • Product news emails, only if you opted in, with one-click unsubscribe (consent).
  • Service and security emails, such as incident alerts and sign-in notices, are not marketing and are sent as part of the contract.
  • Compliance with legal obligations, such as accounting once billing launches.

4. Who receives data

  • Hosting: Hetzner (servers in the European Union) hosts the application and the database.
  • Email delivery: an SMTP email provider (its name will be entered here before launch) sends our messages, including sign-in codes and alerts.
  • Cloudflare (United States, EU–US Data Privacy Framework and standard contractual clauses): content delivery and protection in front of the site, so it sees every request and IP address; and the Turnstile human check described below.
  • Payment provider (only when paid plans start): Creem acts as merchant of record and is a separate controller of your payment data; we do not receive card numbers.
  • Encrypted backups: database backups are encrypted on our server before they leave it and are stored at Cloudflare (R2 storage) and as short-lived files at GitHub (United States). The decryption key is never stored with either, so neither can read the contents.
  • Cloudflare Turnstile: a human check on sign-up, sign-in and forms. It receives technical signals from your browser.
  • Have I Been Pwned (Pwned Passwords): we check whether a new password appears in known breaches by sending only the first five characters of its SHA-1 hash; the password never leaves our servers.
  • Recipients you add receive alert emails; people you add on behalf of third parties confirm by email first and can unsubscribe.

5. How long we keep data

  • Account data: until you delete the account, plus 7 days of grace before permanent deletion.
  • Check results: for the history period of your plan (8 hours on Free, up to 90 days on Scale), then deleted. Hourly summaries are kept for the same period, and for two weeks on Pro so that the two-week report you can request has its data.
  • Server logs: 30 days. Backups: up to 35 days.
  • Contact and abuse messages: 24 months. Audit log: 24 months.
  • Reports: 12 months. Webhook delivery logs: 30 days.

6. International transfers

The controller is established in Ukraine, which does not have an EU adequacy decision. Data is stored on servers in the European Union. Cloudflare may process data in the United States under the EU–US Data Privacy Framework or standard contractual clauses. We will list any further provider outside Ukraine and the European Economic Area here before using it.

7. Your rights

  • Access, rectification and erasure of your data.
  • Export of your data in a machine-readable format (JSON) from the privacy settings.
  • Objection to processing based on legitimate interests and withdrawal of consent at any time.
  • Complaint to the supervisory authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, your national data protection authority.

8. Security

We use hashed passwords (Argon2id), hashed session tokens, encrypted two-factor secrets, strict transport and content-security headers, rate limiting and an audit log. No system is perfectly secure; we will notify affected users of a breach as required by law.

9. Applicable law

This policy follows the current Ukrainian personal data law and is written with GDPR-level safeguards in mind. A new Ukrainian law on personal data protection (draft No. 8153) passed its first reading but had not been adopted when this draft was written.

10. Children

The service is not intended for people under 16. If we learn that an account belongs to someone under 16, we delete it.

11. Changes

We will publish changes here and keep earlier versions in the legal archive.