Privacy Policy
Last updated: 2026-05-18
This Privacy Policy describes how Monitelia ("we", "us") collects, uses, and shares personal data when you use our service.
1. Data we collect
1.1 Account data
When you sign up we collect your email address and password (stored hashed, never in plaintext). We use these to authenticate your account and send transactional emails (invoices, security alerts, password resets).
1.2 Usage data
- Projects and websites you choose to monitor
- Crawl results, keyword rankings, mentions, and other module data you generate through the service
- Audit log of sensitive actions (member changes, API token creation, subscription changes) with IP and user-agent
- Token usage counters for rate limiting
1.3 Billing data
We use Stripe for billing. We store only your Stripe customer ID and subscription metadata; full payment details are stored by Stripe. See Stripe's privacy policy.
1.4 Cookies
See our Cookie Policy.
2. How we use your data
- To provide the service (crawling, monitoring, alerting)
- To send transactional emails you need to operate your account
- To bill you and handle disputes
- To detect abuse and prevent fraud
- To improve the service (aggregate usage analytics only — never your raw project data)
3. Legal basis (GDPR Art. 6)
- Contract: account, usage, billing data — needed to deliver the service you signed up for.
- Legitimate interest: abuse detection, security logging.
- Consent: optional analytics cookies (see cookie banner).
4. Sub-processors
We share necessary data with the following processors. Each is bound by their own data-processing terms:
- Supabase — database + auth hosting (EU or US region as configured at project creation)
- Vercel — web app hosting (global)
- Fly.io — crawler hosting (region you select)
- Stripe — payment processing (US, GDPR adequacy via SCCs)
- Resend — transactional email (US)
- DataForSEO — rank tracking + keyword research APIs (only your tracked keywords are shared, not account data)
- Anthropic / OpenAI / Perplexity — only when you enable AI Visibility tracker; we send the prompts you configure
- Google — Search Console + Business Profile, via your OAuth consent, only when you connect those
5. International transfers
If your data is stored in a region different from yours we rely on Standard Contractual Clauses (SCCs) for compliance with EU data- transfer rules.
6. Retention
- Active account: indefinitely while you use the service
- Closed account: deleted within 30 days of your request, except for invoices and audit log retained for 7 years (legal requirement)
- Audit log: 2 years
- Backups: 12 weeks application-level + 7 days Supabase PITR
7. Your rights (GDPR Art. 15-22)
- Access — request a JSON export of your data: Account → Export my data
- Erasure — delete your account and all associated data: Account → Delete account
- Rectification — correct data via the dashboard or contact us
- Portability — the JSON export is in a portable format
- Objection / restriction — email us
- Withdraw consent — for analytics cookies, in the banner
- Complaint — to your national data-protection authority
8. Security
HTTPS everywhere, TLS 1.2+. Passwords hashed by Supabase Auth (bcrypt). API tokens stored as SHA-256 hashes. Row-level security enforces tenant isolation. We use OAuth refresh tokens for third-party integrations (you can revoke them anytime).
9. Children
The service is not directed at children under 16.
10. Contact
Data controller / DPO contact: privacy@yourdomain.com(replace with your real address).