Privacy Policy
Effective date: 15 July 2026
This policy explains what data ZeroDrop collects and why. It also explains how long ZeroDrop keeps the data, and what rights you have over it.
ZeroDrop is a free service. It monitors your HTTP endpoints and mail servers from several locations around the world. When a consensus of those locations agrees that a service is down, ZeroDrop alerts you. ZeroDrop is a personal project. There is no company behind it, the source code is not public, and there is no self-hosted version.
1. Who is the controller?
ZeroDrop is operated by:
Christian Joergensen (sole operator) Email: christian@technobabble.dk
I am the data controller for the personal data that ZeroDrop processes. Use the email address above for any privacy question, request, or complaint.
2. What data is collected?
ZeroDrop collects only the data that it needs to run the service.
Account data
- Your email address, for sign-in, password reset, and service notices.
- A hashed password, if you sign in with an email address and a password. ZeroDrop stores it as an argon2id hash and never stores the plaintext.
- An OAuth subject identifier and email address, if you sign in with Google or GitHub.
- A two-factor authentication secret, if you turn on 2FA. ZeroDrop encrypts it at rest with AES-256-GCM.
- Passkey (WebAuthn) credentials, if you register a passkey. These credentials are public keys and credential IDs. Your biometrics stay on your device.
- Your account name, timezone, and theme preference.
Monitoring settings
- Check definitions: the URLs and mail-server hostnames that you ask ZeroDrop to monitor, and the settings that you enter on them (expected status codes, request headers, STARTTLS settings, intervals).
- The maintenance windows that you schedule.
- Notification channels: the email addresses and webhook URLs that receive your alerts. The settings of a channel often contain secrets such as webhook tokens, so ZeroDrop encrypts them at rest with AES-256-GCM.
Monitoring results (metrics kept for 30 days)
For every check, from every probing location, ZeroDrop records the result of each probe:
- Whether the probe succeeded, its response time, and the status text (for example,
200 OK). - The TLS certificate issuer and subject, for HTTPS and STARTTLS checks.
- Any error message from the connection.
- Incidents: when a check opened and closed, the cause, and which locations were failing.
ZeroDrop stores the time-series metrics (the timing and status for each check and location) in VictoriaMetrics. The retention window is 30 days, and ZeroDrop then deletes them automatically. It keeps the latest result of each check until a new result replaces it.
ZeroDrop does not store the response bodies of the endpoints that it probes. It records the pass or fail result, the timing, the status text, the certificate metadata, and the error text. It does not keep the content that your server returns.
Notification log
- Which channel ZeroDrop notified for which incident, the event type, the delivery status, and the timestamp.
Audit log (kept for 1 year)
To let you review activity that is relevant to security, and to protect your account, ZeroDrop records:
- The event type (for example,
auth.loginandcheck.created). - The timestamp of the action.
- The client IP address of the action, and an approximate country and city from that address.
- The user agent, and the request method and path.
- Short metadata about the resource, but never secrets.
ZeroDrop deletes audit events that are more than one year old.
Cookies
- A session cookie (HTTP-only) that keeps you signed in.
- A CSRF token cookie that protects form submissions.
- Before public launch, an early-access cookie. ZeroDrop sets it after you enter the access password. This cookie only removes the "coming soon" page.
There are no marketing, advertising, or analytics cookies. ZeroDrop does not use third-party analytics.
3. Why is this data collected?
| Data | Purpose | Lawful basis (GDPR) |
|---|---|---|
| Account email and credentials | Authenticate you to the service | Contract, Art. 6(1)(b) |
| Monitoring settings | Operate the monitoring that you signed up for | Contract |
| Monitoring results and metrics | Show you uptime, timing, and incidents, and decide when to alert | Contract |
| Notification log | Show you which alerts ZeroDrop sent, and help you debug delivery | Contract and legitimate interest |
| Audit log | Record security and settings changes for your review and account protection | Contract and legitimate interest |
| Cookies (session, CSRF) | Keep you signed in and prevent CSRF attacks | Strictly necessary |
| OAuth identifiers | Let you sign in with Google or GitHub | Contract |
4. How long is data kept?
| Data | Retention |
|---|---|
| Endpoint response bodies | Not stored, held in memory during the probe only |
| Monitoring metrics (time series for each check and location) | 30 days, then deleted automatically |
| Audit log | 1 year, then deleted automatically |
| Incidents and notification log | Until you delete the related check or channel |
| Account and settings data | Until you delete your account |
| Backups | Encrypted backups are kept for up to 1 year for disaster recovery (see Section 7) |
You can delete your account at any time on the account settings page. The deletion immediately removes your account data, checks, incidents, and notification channels from the live database.
5. Third-party processors
These providers process data for ZeroDrop:
| Provider | Purpose | Data shared |
|---|---|---|
| HostHatch | Server hosting for the control plane (United States) | Everything stored by ZeroDrop (database, metrics) |
| Amazon Web Services (SES) | Transactional email: account confirmation, password reset, alert delivery, service notices (region us-east-1) |
Your email address and the message content |
| Cloudflare | DNS hosting and Turnstile (anti-bot challenge on auth forms) | Your IP address and a Turnstile token at sign-up and sign-in |
| OAuth sign-in, if you choose to sign in with Google | Your Google profile email and subject ID | |
| GitHub | OAuth sign-in, if you choose to sign in with GitHub | Your GitHub profile email and subject ID |
These providers act as data processors. Their own terms require them to handle the data only for the purposes in the table.
ZeroDrop also runs its own probing agents in several locations: San Francisco, New York, Amsterdam, and Sydney. When you add a check, these agents connect to the target that you entered. The operator of that target sees connections from the probing addresses of ZeroDrop.
6. Your rights
The major privacy frameworks give you almost the same set of rights. They include GDPR, UK GDPR, Swiss FADP, and CCPA. These rights apply wherever you live. You can:
- Access the personal data that ZeroDrop holds about you
- Correct information that is wrong (you can edit most fields on the account settings page)
- Delete your account and all of its live data (self-service on the account settings page)
- Export your data in a machine-readable format
- Object to the processing, or restrict how ZeroDrop uses your data
- Withdraw consent for any processing that depends on consent
- Lodge a complaint with your local data protection authority
To exercise any of these rights, email christian@technobabble.dk. This includes an export of your data, or the deletion of your data from the backups. I answer requests within 30 days.
7. Backups
ZeroDrop keeps encrypted backups of the live database for disaster recovery, for up to 1 year. A rolling schedule then deletes them. If you delete your account, copies of your data can stay in the backups until those backups expire.
To also remove your data from the backups, for example for a GDPR erasure request, email christian@technobabble.dk. The request then includes the removal from backup storage.
8. International transfers
The control-plane servers of ZeroDrop are in the United States, and its probing agents run in several countries. Some jurisdictions have data-export rules, for example the European Economic Area, the United Kingdom, and Switzerland. If you use ZeroDrop from one of them, your personal data is transferred to the United States to operate the service.
The legal basis for this transfer is the Standard Contractual Clauses (SCCs) that the European Commission approved. Section 9 lists the additional safeguards: encryption at rest, TLS in transit, and no storage of endpoint response bodies. Some sub-processors operate globally and can also transfer data outside the EEA. They are Cloudflare, Google, GitHub, and Amazon Web Services. Each one relies on the SCCs, or on the EU-US Data Privacy Framework when it applies.
To request a copy of the current SCCs, or more detail about the safeguards, email christian@technobabble.dk.
9. Security
ZeroDrop takes reasonable technical measures to protect your data:
- ZeroDrop hashes passwords with argon2id. It stores session, API-token, and password-reset tokens only as SHA-256 hashes of 256-bit random values.
- ZeroDrop encrypts two-factor secrets and notification-channel settings at rest with AES-256-GCM.
- Sign-in and password reset have rate limits and equalized timing, so the system never reveals whether an email address has an account.
- Outbound probes and webhook calls use TLS with certificate validation, and outbound requests have protection against SSRF.
- Sessions use HTTP-only cookies and CSRF tokens.
- ZeroDrop never writes endpoint response bodies to disk or to the database.
No service is perfectly secure. If you find a security problem, email christian@technobabble.dk.
10. Children
ZeroDrop is not for children under 16, and it does not knowingly collect data from them. If a child signed up, email christian@technobabble.dk. I will remove the account.
11. Changes to this policy
If this policy changes in a material way, the new version appears at this URL with a new effective date. Signed-in users also get an email. I can make minor edits, such as typos, clarifications and formatting, without notice.
12. Contact
For any privacy question or request:
Christian Joergensen christian@technobabble.dk