Privacy Policy
Last updated: 10 June 2026
Notdown is a one-person operation run from the Czech Republic. This page explains what data we collect, why we collect it, who we share it with, and how to get rid of it. No dark patterns, no fine print buried in §27 — what you read here is what actually happens.
Notdown is currently free with no paid plans. If that changes, billing details will appear in this policy before the first charge, not after.
1. What we collect
- Account data: email address and a bcrypt-hashed password. Optional display name.
- Monitor configuration: the URLs, hostnames, schedules, and alert channels you set up.
- Check results: HTTP status codes, response times, response-body snippets you asked us to look at, certificate metadata, RDAP responses.
- API and MCP tokens: hashed Sanctum tokens you issue for the REST API, the MCP server, or the CLI.
- Operational data: request logs (IP, user agent, timestamp), error reports, queue activity. Kept 30 days.
2. Why we collect it
- To run the monitoring you signed up for.
- To send you alerts when something you watch changes state.
- To debug the product and stop abuse.
- To comply with EU law where it applies (security, fraud prevention).
3. Legal basis (GDPR)
Under the EU General Data Protection Regulation we rely on:
- Contract: the data we need to actually deliver the service.
- Legitimate interest: security, abuse prevention, and debugging.
4. How long we keep it
| Data | Retention |
|---|---|
| Account profile | Until you delete your account |
| Monitor configuration | Until you delete it |
| Check results | 30 days |
| Incident records | As long as the account exists |
| Notification logs | 30 days |
| Request logs | 30 days |
| Deleted accounts | Permanently removed within 30 days |
5. Sub-processors
The short list of services we genuinely need to run Notdown. Each one is bound by a GDPR-compliant Data Processing Addendum.
- Laravel Cloud — application hosting (runs on AWS, EU region).
- Cloudflare — DNS, DDoS protection, TLS termination.
- Resend — transactional email delivery (alerts, account email).
This list is kept current.
6. AI and your data
Notdown ships an MCP server and a REST API so your AI agent (Claude, Cursor, ChatGPT, anything MCP-compatible) can read and write your monitors on your behalf. That is the only AI involvement on our side. We do not train any AI model on your data. We do not feed your monitors, incidents, or response bodies to any third-party model. The agent you choose to use is yours.
7. Your rights
Under GDPR and similar regulations you can:
- Access a copy of the data we hold about you.
- Correct anything inaccurate.
- Delete your account and everything attached to it.
- Export your monitor configuration and incident history as JSON or CSV.
- Object to processing based on legitimate interest.
- Lodge a complaint with your local data-protection authority.
Email privacy@notdown.dev to exercise any of these rights. Responses fall under the GDPR statutory timeframe.
8. International transfers
Primary infrastructure runs on Laravel Cloud (AWS, EU region). Cloudflare and Resend operate globally. Transfers outside the EEA rely on Standard Contractual Clauses approved by the European Commission.
9. Security
Passwords are hashed with bcrypt. Connections use TLS 1.2+. Database access is restricted to the application server. Backups are encrypted at rest and stored in a separate region. We never log passwords, full tokens, or session contents.
10. Children
Notdown is not directed at people under 16. If you believe a child has registered, email us and we'll delete the account.
11. Changes
The current version always lives at this URL. Check back occasionally if it matters to you.
12. Contact
Privacy questions: privacy@notdown.dev
Support: support@notdown.dev
Data controller: Martin Macháček, Czech Republic.