Security and privacy
Security and privacy
EU hosting, GDPR, DPA, and what data statusloop stores.
statusloop is built for teams that care where their data lives. Infrastructure is centered in the EU.
Where data is processed
| Component | Location |
|---|---|
| PostgreSQL (Supabase) | EU West (Ireland) — aws-1-eu-west-1 |
| App + worker (Fly.io) | Frankfurt (fra) |
| Authentication | Supabase Auth |
| Transactional email | Resend |
| Status page hosting / subdomain SSL | Vercel |
| SMS (when enabled) | Twilio |
Probe checks for monitors run from Frankfurt today.
What we store
Depending on what you use:
- Account: email, name, profile picture, workspace and project metadata
- Monitors: URLs, check results, timings, incident history
- Healthchecks: ping timestamps and schedule configuration
- Servers: metrics (CPU, memory, load, network), host metadata, agent version
- Status pages: public configuration, components, incidents you publish
- Billing: Stripe customer and subscription references (payment details stay with Stripe)
Check logs for monitors are retained about 24 hours. Server metric retention depends on plan (7–90 days).
GDPR
- Legal pages on this marketing site: Privacy, Terms, Imprint
- No in-app GDPR tooling today — no self-serve account deletion, data export, or consent management in the app
Data Processing Agreement (DPA)
Download or request a DPA for B2B customers:
- DPA page on this site (template — contact us for a signed copy)
- Email: hello@statusloop.dev
When you use statusloop to monitor your systems, you remain the controller for your end-user data; statusloop processes monitoring and account data to provide the service.
Security practices
- Authenticated app API routes require a Supabase session token — they are for the web app, not a public customer API
- Public status page JSON and badge endpoints are read-only
- Password minimum length: 6 characters on email sign-up
Was this helpful?