Skip to content
statusloopDocs
Security and privacy

Security and privacy

EU hosting, GDPR, DPA, and what data statusloop stores.

statusloop is built for teams that care where their data lives. Infrastructure is centered in the EU.

Where data is processed

ComponentLocation
PostgreSQL (Supabase)EU West (Ireland) — aws-1-eu-west-1
App + worker (Fly.io)Frankfurt (fra)
AuthenticationSupabase Auth
Transactional emailResend
Status page hosting / subdomain SSLVercel
SMS (when enabled)Twilio

Probe checks for monitors run from Frankfurt today.

What we store

Depending on what you use:

  • Account: email, name, profile picture, workspace and project metadata
  • Monitors: URLs, check results, timings, incident history
  • Healthchecks: ping timestamps and schedule configuration
  • Servers: metrics (CPU, memory, load, network), host metadata, agent version
  • Status pages: public configuration, components, incidents you publish
  • Billing: Stripe customer and subscription references (payment details stay with Stripe)

Check logs for monitors are retained about 24 hours. Server metric retention depends on plan (7–90 days).

GDPR

  • Legal pages on this marketing site: Privacy, Terms, Imprint
  • No in-app GDPR tooling today — no self-serve account deletion, data export, or consent management in the app

Data Processing Agreement (DPA)

Download or request a DPA for B2B customers:

When you use statusloop to monitor your systems, you remain the controller for your end-user data; statusloop processes monitoring and account data to provide the service.

Security practices

  • Authenticated app API routes require a Supabase session token — they are for the web app, not a public customer API
  • Public status page JSON and badge endpoints are read-only
  • Password minimum length: 6 characters on email sign-up
Was this helpful?

On this page