Legal
Privacy Policy
Effective date: July 24, 2026
This Privacy Policy describes how CronEcho ("we", "us", or "our") collects, uses, and shares information when you use our job and agent monitoring service ("Service"). We take your privacy seriously and are committed to being transparent about our practices.
1. Information We Collect
Account information — When you sign up, we collect your email address and name (via our authentication provider, Clerk). We do not store raw passwords.
Ping and telemetry data — When a job or agent calls your unique ping URL, we record the timestamp, duration, exit status, and any metadata you include in the request body.
Agent run data — For AI agent monitoring, we collect cost per run, token usage, run duration, step counts, and any governance events you emit.
Alert channel configuration — We store the webhook URLs, bot tokens, and contact details you provide to configure alert destinations (Slack, Telegram, PagerDuty, etc.).
Billing data — Payment information is handled by Stripe and never stored on our servers. We receive subscription status, plan type, and billing period information from Stripe.
Usage data — We collect standard web logs including IP addresses, browser type, pages viewed, and request timestamps for security and performance monitoring.
2. How We Use Your Information
- To provide the Service — processing pings, triggering alerts, displaying dashboards
- To send you alerts when a job misses its schedule or an agent exceeds a cost threshold
- To manage your subscription and process billing via Stripe
- To improve the Service — analysing aggregate usage patterns to inform product decisions
- To communicate with you about your account, service updates, and security notices
- To detect and prevent fraud, abuse, and security incidents
We do not sell your personal data to third parties. We do not use your data for advertising.
3. Data Sharing
We share your information only with the following categories of third parties:
- Supabase — our database provider, used to store your jobs, agents, pings, and alert configurations
- Clerk — our authentication provider, which handles sign-up, sign-in, and session management
- Stripe — our payment processor for subscriptions and billing
- Railway — our infrastructure provider for hosting the backend API
- Alert destinations you configure — when an alert fires, we send a payload to the webhook URL, Slack workspace, Telegram bot, or other destination you have configured
We may share your information with law enforcement or regulatory authorities if required by applicable law.
4. Data Retention
We retain your ping history and agent run data for the period allowed by your plan (7 days on Free, 30 days on Starter, 90 days on Pro, 365 days on Team).
Account data is retained while your account is active. If you cancel your account, we will retain your data for 30 days to allow for export, after which it will be permanently deleted.
5. Security
We use industry-standard security measures including TLS encryption in transit, encrypted storage at rest via Supabase, and row-level security policies to isolate tenant data.
Alert channel credentials (webhook URLs, bot tokens) are stored encrypted. No raw credentials are exposed in API responses.
Despite our efforts, no transmission over the internet is completely secure. We cannot guarantee the security of information transmitted to or from the Service.
6. Cookies
We use essential cookies required for authentication (session tokens managed by Clerk). We do not use third-party advertising or tracking cookies.
You can configure your browser to refuse cookies, but this may prevent you from signing in to the Service.
7. Your Rights
Depending on your location, you may have rights under applicable data protection law, including:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — ask us to delete your personal data
- Portability — receive your data in a machine-readable format
- Objection — object to certain types of processing
To exercise any of these rights, email us at privacy@cronecho.com. We will respond within 30 days.
8. International Transfers
Your data may be processed in countries outside your own, including the United States, where our infrastructure providers operate. We ensure appropriate safeguards are in place for such transfers in accordance with applicable law.
9. Children
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice in the Service. Your continued use of the Service after changes take effect constitutes your acceptance of the revised policy.
11. Contact
For privacy-related questions or requests, contact us at privacy@cronecho.com.