Privacy
What we hold about you, why we hold it, where it lives and how to make us delete it. Written from the actual database rather than from a template, so it says what is true and not what is customary.
Who is responsible
NoMore404, Amsterdam, the Netherlands. For the data we hold about you as our customer, we are the controller. For the monitoring you configure, you are the controller and we act on your instructions as your processor. That relationship is set out in our data processing agreement, which we will sign on request.
What we hold, and why
Listed by what it is rather than by category, because "account data" is not something you can check and a list is.
| What | Why | Basis |
|---|---|---|
| Your email address | Identifies your account, and receives verification and password mail | Contract |
| Your password | Signing in. Stored as an Argon2 hash, which cannot be turned back into your password | Contract |
| Two-factor secret and recovery codes | Only if you switch two-factor on | Contract |
| Last sign-in time | Account security, and telling an abandoned account from a quiet one | Legitimate interest |
| Organisation name, country, timezone | Invoicing, working out the right tax, and knowing when it is the middle of your night | Contract |
| Alert destinations: email addresses, phone numbers, webhook URLs | Sending the alerts you asked for. Webhook and chat URLs are encrypted, because such a URL lets whoever holds it post as you | Contract |
| Language and theme preference | Showing the interface and your alerts the way you chose | Contract |
| Stripe customer and subscription identifiers | Linking your account to your subscription. We never see or store your card number | Contract |
What monitoring produces is not about you. A check result is a monitor number, a probe number, a timestamp, a status, a response time and an error class. There is no person in it.
What we do not do
- No analytics, on any page, including this one.
- No advertising, no advertising identifiers, and nothing sold or shared with anyone for their own purposes.
- No third-party scripts, no fonts loaded from somebody else's server, no embedded widgets. Every request this site makes goes to this site, which you can confirm in your browser's network panel.
- No profiling and no automated decisions with legal effects.
The status light on somebody else's site
A customer with a published status page can put a small status light in their own footer. When one of their visitors loads that page, the visitor's browser asks us for two things: a script, which is the same file for every customer, and one word saying whether that status page is showing everything as working.
Those two requests carry what any web request carries: an address, a browser's user agent string, and the page address being asked for, which names the status page and not the visitor. They go into the same access log as every other request here and are kept for as long as that log is. No cookie is set, nothing is stored about the visitor, and nothing in it lets us tell one visitor from another or recognise them anywhere else. The light asks us the same question every minute while the page is open and asks us nothing when it is closed.
If you are the customer putting it there, this is a request from your site to ours, which is the kind of thing your own privacy notice may need to say. We would rather you were able to describe it accurately than have it be a surprise.
Cookies
Five, all set by this site, none shared with anyone. In full:
- n404_session
- Set when you sign in, holding which account you are using and nothing else. Signed, so it cannot be edited; marked Secure, so it only travels over HTTPS; and marked HttpOnly, so no script can read it. A fortnight.
- n404_pending
- Exists only between your password and your two-factor code, so the second step knows which login it belongs to. Five minutes.
- n404_in
- Holds the digit 1 and means somebody is signed in, which is all the pages outside the app need to know to say "your monitors" instead of "create an account". It carries nothing about who you are, and it exists because the real one above is unreadable to scripts by design.
- n404_celebrated
- Remembers that you have already been thanked for subscribing, so the billing page does not do it twice. One hour, and only on that page.
- n404_partner
- Set only if you arrive through a partner's link, and holds that partner's name so we can pay them if you subscribe. It says nothing about you, it is never read for anything else, and it is gone in thirty days. If you arrive any other way it is never set.
The first four are strictly necessary to sign you in and keep you there, which is why there is no cookie banner asking you to accept anything. The last one is exempt for a different reason: it measures which partner sent somebody, not who the somebody is. There is nothing here to consent to.
Where it lives, and who else touches it
Everything about you is stored in the Netherlands, at TransIP, who also send our mail. A few other companies are involved, each for one job:
- Stripe Payments Europe, Ireland
- Payments and invoices. They handle your card so that we never do.
- EmailOctopus, United Kingdom
- Our mailing list. Your address is sent to them once, when you confirm it, and nothing else about you goes with it: no name, no billing details and nothing about what you monitor. It leaves the European Union at that moment, which is lawful under the UK adequacy decision. Every message they send for us carries a link that takes you off the list, and it works whether or not you keep the account.
- Independent hosting providers, worldwide
- The probes that do the checking, deliberately spread across continents, because a failure confirmed from the same continent confirms our blind spot rather than your outage. A probe is given a hostname to check and reports whether it answered. It holds nothing about you and cannot reach our database. If you give an HTTP monitor a username and password or a token, the probes checking it do hold that, because they are what sends it, and keep it on their own disk so a restart does not interrupt the check.
When we look at it ourselves
One operator can read your organisation's data in order to run and support the service: your monitors, your incidents, who is on your team, and which plan you are on. Not your passwords, which are hashed and cannot be read by anybody, and not your card, which only Stripe ever holds.
Every one of those views is written down as it happens: which organisation was looked at, by whom, and when. We keep that log for a year, and it outlives the account it is about: a record of who read your data is no use if it goes when the data does. The page that does the looking cannot change anything. Ask us through contact and we will send you your organisation's entries.
How long we keep it
- Individual check results
- 90 days
- Hourly summaries, incidents and the record of the alerts we sent, which is what your graphs, reports and incident history are drawn from
-
Free and Starter: 90 days
Pro and Business: 1 year - Your account and everything you configured
- Until you delete it
- Invoices
- 7 years, required by Dutch tax law
When those periods are up, we delete it, checked once a day. Moving to a plan that keeps less deletes whatever is older than the new plan's period on the next day's run.
Our servers' logs record the IP address each request came from. They stay on the servers that write them, are copied nowhere else, and go when those servers are replaced, which every update of the service does. That is not a fixed number of days: until the next update, a log is only trimmed by size.
One request is kept rather than only logged: the one that created your account. We store the name you gave when you signed up and the IP address you signed up from, so that we can tell a person opening an account from the automated signups we otherwise spend our time deleting. Neither is used to contact you or shown to anyone outside our own operators, and both are deleted with the account.
Your rights
You can ask us for a copy of what we hold, correct it, delete it, restrict what we do with it, object to processing based on legitimate interest, or ask for it in a portable form. Where we ever rely on your consent, you can withdraw it at any time, and that does not affect anything done before you did.
Write to us and we will answer within a month. No forms and no identity theatre: if you can sign in, that is who you are.
If we get it wrong, you can complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority. We would rather you told us first, but that is your right and not our permission to give.
Changes to this page
If we add a company that handles your data, or start using it for something new, we will tell you before it happens rather than quietly updating this page and dating it. A change you have to notice for yourself is not a notice.
11 September 2026: added "When we look at it ourselves". We built an operator view of the platform, so for the first time somebody here can read your data without you asking us to. It is logged, and now it is written down.
Questions, or a request about your data: contact us.