Privacy
What HookPulse keeps about the people who use it, for how long, which infrastructure it shares, and how to request access or deletion.
Who processes the data
HookPulse is run by the same house as the other products listed in the footer. Requests about personal data go to contato@hookpulse.net and are answered by e-mail.
What this product keeps
- Each monitor stores its name, its interval or cron schedule with time zone and grace period, the alert e-mail and webhook URL you set, and its check-in link.
- Each device environment stores its chosen name and group, operating system and version, architecture, tool versions and available measurement sources. Setup commands display local system facts; you review and paste their output into the page. Only recognized facts are saved, not raw pasted output. No password, environment dump or personal file is requested. Device readings include the requested system measurements, mount paths and interface names.
- When a monitor is created we store, on its row, the user-agent, the origin (scheme and host only) and a salted network hash; when a guest token is issued, the same facts go to one operational log line, without the token or any address. Older records can contain country, region and network-provider information supplied by the former edge. The origin does not invent these fields when they are unavailable. This operational data never appears in public responses or badges.
- Each ping stores the method, the recorded status, latency, content type, whether it was a check-in, a start or a failure with its exit code, a 500-character preview of the body with tokens and secrets redacted, and four request headers: user-agent, content-type, the sender's IP address (cf-connecting-ip) and x-request-id.
- A miss, an explicit failure or a recovery sends an e-mail (Amazon SES) to the alert address or a POST to the alert URL.
- Account: e-mail, password, passkeys, sign-in codes and sessions are kept by the account system shared by our products, in its own database — this product keeps only the account id next to what is yours. Without an account, a signed guest token stored in your browser owns what you create; signing in moves it to your account.
- Pay-per-call payments (x402) settle on the Base network, which is public by design; here we keep the transaction reference and the amount for reconciliation and accounting.
- Prepaid credit: the token is stored only as a SHA-256 hash with its balance and movements; whoever holds the token holds the credit, and it cannot be recovered by e-mail.
- Contact: your message, the e-mail you give and the reply go through Amazon SES to the product mailbox.
For how long
- Each monitor keeps only its last ~100 pings; older ones are pruned as new ones arrive. Deleting a monitor deletes its pings.
- Sign-in codes expire within minutes; the account session ends when you sign out or when it expires.
- Per-network rate-limit counters (guest, contact, sign-in code) expire on their own within minutes or hours.
- Payment and credit records stay as long as accounting requires.
Infrastructure and third parties
- Servers we operate run the service and store your data. Cloudflare provides DNS only.
- Amazon Web Services (SES) sends transactional e-mail on behalf of the product.
- Interface libraries (Bootstrap) are served from the product's own domain, not from a third-party CDN.
- Google Analytics 4 measures pages and events only after the first interaction (tap, click or key), with ad storage denied and no sale or sharing for advertising.
- PayAI (x402 facilitator) verifies and settles payments on the Base network; the paying wallet is yours, and its address is public on-chain.
Cookies and browser storage
- When you sign in, the account session lives in an HttpOnly cookie on this domain; without an account, the guest token stays in your browser and identifies what you created.
- Screen preferences (theme, filters) stay in the browser's local storage and never leave it.
- There is no advertising cookie and no cross-site tracking.
IP address
To limit abuse, the IP address goes into a hash with a secret salt. The approximate country and city come from a geolocation database (MaxMind GeoLite2) looked up on our server, without sending the address to anyone. The raw IP is not stored, except where this page says otherwise.
Your rights
You can request access, correction or deletion of what exists about you by writing to contato@hookpulse.net. We answer within the terms of the Brazilian data protection law (LGPD) and, where it applies, the GDPR. Data from public sources (official registries) stays at the source; only the copy here is removed.
Last updated: 21 September 2026.