Privacy
Last updated 3 October 2026
Who we are
enkelt.design (CVR 45871290), Lille Bygade 13, 2635 Ishøj, Denmark, runs StatOSS and is the controller of the data below. Contact: [email protected].
What we keep and why
- Account: name, email and a password hash, or the Google or GitHub account id. To provide the service (contract).
- Sessions: IP address and browser. For security (legitimate interest).
- Your content: pages, monitors, check results, incidents, alert destinations and API key hashes. To provide the service (contract).
- Billing: plan and Polar customer id. To bill you (contract) and keep accounts (legal obligation).
- Error logs: the visitor's IP address shortened to its network. To fix faults (legitimate interest).
- Email: the count of opened emails, from an image loaded through Amazon, which sees the reader's IP address and browser. Links are not tracked. To check delivery (legitimate interest).
- Forms: sign-up, password reset and subscribe forms use Cloudflare Turnstile. To stop abuse (legitimate interest).
- Support: what you write to support and our answers, with your email address. Mail to support is received and stored by Amazon. New mail to support, and new messages from the form or chat from someone not signed in, go with their subject, the sender's domain and plan to OpenRouter, which passes it to OpenAI or Microsoft Azure to label it (question, billing, spam and so on); both are set to keep nothing. To help you (contract, or legitimate interest when you have no account).
- Chat: starting a chat sets one cookie holding its key, kept 30 days, so the chat opens again on the next page. While a chat is open, support sees the address of the page you are on (without its query string) and its title, the last ten such pages, your browser and system, country, time zone, language and screen size. Pictures you send in the chat are kept with the conversation. To answer you (contract, or legitimate interest).
- Support tools: to help you, support can look at your dashboard as you see it, without being able to change anything; each time is listed under Account with the reason. When support asks for a draft answer, the conversation and what we know of the account (plan and counts) go to OpenRouter, set to keep nothing. To help you (contract).
- Drafts: on Pro, when you ask for a draft, the incident, its monitors (URLs without query strings), failed checks and deploy markers go to OpenRouter. To write the draft (contract).
- Page views: on this site and in the dashboard (not on status pages), the address of the page without its query string except campaign tags, the referring site, browser, system, device type, language, country and screen size, counted by Umami on our own server in Denmark. No cookie is set; a visitor is recognised for the month by a hash of their IP address and browser, and the address itself is not kept. To see which pages people use (legitimate interest).
- Where you came from: when a visit arrives from another site or with campaign tags, the site's name and the tags are kept for 7 days under a hash of the visitor's IP address and browser. If that browser signs up within the week, they are kept with the account. To see which places bring people (legitimate interest).
- Product news: if you tick the box at sign-up or under Account, occasional email about what changed in StatOSS, with when you asked. Every one has an unsubscribe link. To send it (consent, withdrawn at any time).
We send no marketing email to anyone who has not asked for it.
Subscribers and visitors
For people who subscribe to a status page, or sign in to a private one, the page's owner is the controller and we process their data for the owner, under the data processing agreement. Every email has an unsubscribe link. Status pages set no cookies except the ones that open a password-protected or private page, and load no analytics.
How long
- Account and content: until you delete them.
- Check results: 14 days (7 on Free). History: up to your plan.
- Sessions: until sign-out or 7 days after last use.
- Unconfirmed subscribers: 7 days.
- Where a visit came from, before any sign-up: 7 days.
- Sign-in to a private page: the link 15 minutes, the sign-in 30 days.
- Records of bounced or refused mail: 30 days.
- Support conversations: 2 years after they close, or until you delete your account.
- Mail to support as it arrived, with attachments: 30 days.
- Page view counts: 2 years.
- Backups: up to 16 days after deletion.
- Invoices: as bookkeeping law requires.
Where
On servers in Denmark and Germany, with backups in Western Europe. Checks also run from the United States. Some providers are outside the EU; the subprocessors page lists them and the safeguards used.
Your rights
You can ask to see, correct, delete, restrict or move your data, and object to processing based on legitimate interest. Export and deletion are under Account, Your data; for the rest, email [email protected]. You can complain to Datatilsynet (datatilsynet.dk).