Privacy Policy
Privacy Policy
Effective date: the publication date shown above
This policy explains what data Witch collects and how it is used. Witch is operated by XODO Services SRL.
Data we collect
Account data
- Name and email address
- Authentication data: password (stored only as a hash), session records
- Session metadata: IP address and browser user-agent for sessions you create
- Account timestamps: creation, last login
Monitoring data (from targets you configure)
- Monitored URLs and site names
- HTTP/TLS telemetry: status codes, latency, TLS certificate validity and expiry
- Browser telemetry from Chromium renders: page titles, final URLs, resolved IPs, console errors, network failures
- DOM-derived evidence (for example, presence of expected elements)
- Screenshots and visual snapshots of monitored pages, and visual diffs against baselines
- Incident records combining the above
Workspace data
- Team/workspace membership and roles
- Workspace invitations
- Status page configuration and subscriber email addresses (for status pages you publish)
- API key metadata (names and hashes; the secret is shown once at creation and never stored in plain text)
Billing data
- Billing metadata processed through Stripe (customer and subscription identifiers, plan state). Payment instrument details are held by Stripe, not by Witch.
Operational data
- Audit log entries (actor, action, target, timestamp, IP)
- Email delivery records (type, recipient, status; never message bodies or links)
- AI usage records when AI analysis is enabled (provider, model, token counts)
How we use data
To operate the monitoring service, send alerts and notifications you request, process billing, secure and maintain the service, and communicate about your account.
Retention
Monitoring evidence retention follows your plan's history window. Account data is retained while your account is active. You may request export or deletion of your account data.
Your role for monitored pages
Where you use Witch in a professional capacity, you are typically the controller for personal data contained in the pages you monitor, and Witch acts as a processor with respect to that monitoring activity. We cannot guarantee that monitored customer pages contain no personal data.
Sharing
We share data with the subprocessors listed on our Subprocessors page, strictly to operate the service. We do not sell personal data.
Security
We apply sensible technical controls (hashed credentials, TLS in transit, access controls, audit logging). We do not hold security certifications.
Contact
Privacy questions: [email protected]