Privacy Policy

Effective date: 15 July 2026

This policy explains what data ZeroDrop collects and why. It also explains how long ZeroDrop keeps the data, and what rights you have over it.

ZeroDrop is a free service. It monitors your HTTP endpoints and mail servers from several locations around the world. When a consensus of those locations agrees that a service is down, ZeroDrop alerts you. ZeroDrop is a personal project. There is no company behind it, the source code is not public, and there is no self-hosted version.

1. Who is the controller?

ZeroDrop is operated by:

Christian Joergensen (sole operator) Email: christian@technobabble.dk

I am the data controller for the personal data that ZeroDrop processes. Use the email address above for any privacy question, request, or complaint.

2. What data is collected?

ZeroDrop collects only the data that it needs to run the service.

Account data

Monitoring settings

Monitoring results (metrics kept for 30 days)

For every check, from every probing location, ZeroDrop records the result of each probe:

ZeroDrop stores the time-series metrics (the timing and status for each check and location) in VictoriaMetrics. The retention window is 30 days, and ZeroDrop then deletes them automatically. It keeps the latest result of each check until a new result replaces it.

ZeroDrop does not store the response bodies of the endpoints that it probes. It records the pass or fail result, the timing, the status text, the certificate metadata, and the error text. It does not keep the content that your server returns.

Notification log

Audit log (kept for 1 year)

To let you review activity that is relevant to security, and to protect your account, ZeroDrop records:

ZeroDrop deletes audit events that are more than one year old.

Cookies

There are no marketing, advertising, or analytics cookies. ZeroDrop does not use third-party analytics.

3. Why is this data collected?

Data Purpose Lawful basis (GDPR)
Account email and credentials Authenticate you to the service Contract, Art. 6(1)(b)
Monitoring settings Operate the monitoring that you signed up for Contract
Monitoring results and metrics Show you uptime, timing, and incidents, and decide when to alert Contract
Notification log Show you which alerts ZeroDrop sent, and help you debug delivery Contract and legitimate interest
Audit log Record security and settings changes for your review and account protection Contract and legitimate interest
Cookies (session, CSRF) Keep you signed in and prevent CSRF attacks Strictly necessary
OAuth identifiers Let you sign in with Google or GitHub Contract

4. How long is data kept?

Data Retention
Endpoint response bodies Not stored, held in memory during the probe only
Monitoring metrics (time series for each check and location) 30 days, then deleted automatically
Audit log 1 year, then deleted automatically
Incidents and notification log Until you delete the related check or channel
Account and settings data Until you delete your account
Backups Encrypted backups are kept for up to 1 year for disaster recovery (see Section 7)

You can delete your account at any time on the account settings page. The deletion immediately removes your account data, checks, incidents, and notification channels from the live database.

5. Third-party processors

These providers process data for ZeroDrop:

Provider Purpose Data shared
HostHatch Server hosting for the control plane (United States) Everything stored by ZeroDrop (database, metrics)
Amazon Web Services (SES) Transactional email: account confirmation, password reset, alert delivery, service notices (region us-east-1) Your email address and the message content
Cloudflare DNS hosting and Turnstile (anti-bot challenge on auth forms) Your IP address and a Turnstile token at sign-up and sign-in
Google OAuth sign-in, if you choose to sign in with Google Your Google profile email and subject ID
GitHub OAuth sign-in, if you choose to sign in with GitHub Your GitHub profile email and subject ID

These providers act as data processors. Their own terms require them to handle the data only for the purposes in the table.

ZeroDrop also runs its own probing agents in several locations: San Francisco, New York, Amsterdam, and Sydney. When you add a check, these agents connect to the target that you entered. The operator of that target sees connections from the probing addresses of ZeroDrop.

6. Your rights

The major privacy frameworks give you almost the same set of rights. They include GDPR, UK GDPR, Swiss FADP, and CCPA. These rights apply wherever you live. You can:

To exercise any of these rights, email christian@technobabble.dk. This includes an export of your data, or the deletion of your data from the backups. I answer requests within 30 days.

7. Backups

ZeroDrop keeps encrypted backups of the live database for disaster recovery, for up to 1 year. A rolling schedule then deletes them. If you delete your account, copies of your data can stay in the backups until those backups expire.

To also remove your data from the backups, for example for a GDPR erasure request, email christian@technobabble.dk. The request then includes the removal from backup storage.

8. International transfers

The control-plane servers of ZeroDrop are in the United States, and its probing agents run in several countries. Some jurisdictions have data-export rules, for example the European Economic Area, the United Kingdom, and Switzerland. If you use ZeroDrop from one of them, your personal data is transferred to the United States to operate the service.

The legal basis for this transfer is the Standard Contractual Clauses (SCCs) that the European Commission approved. Section 9 lists the additional safeguards: encryption at rest, TLS in transit, and no storage of endpoint response bodies. Some sub-processors operate globally and can also transfer data outside the EEA. They are Cloudflare, Google, GitHub, and Amazon Web Services. Each one relies on the SCCs, or on the EU-US Data Privacy Framework when it applies.

To request a copy of the current SCCs, or more detail about the safeguards, email christian@technobabble.dk.

9. Security

ZeroDrop takes reasonable technical measures to protect your data:

No service is perfectly secure. If you find a security problem, email christian@technobabble.dk.

10. Children

ZeroDrop is not for children under 16, and it does not knowingly collect data from them. If a child signed up, email christian@technobabble.dk. I will remove the account.

11. Changes to this policy

If this policy changes in a material way, the new version appears at this URL with a new effective date. Signed-in users also get an email. I can make minor edits, such as typos, clarifications and formatting, without notice.

12. Contact

For any privacy question or request:

Christian Joergensen christian@technobabble.dk