Privacy Policy for Site Spy
Last Updated: August 11, 2026
1. Who We Are and What This Covers
Site Spy is a website change monitoring service. You tell it which web pages to watch, and it checks those pages on a schedule and tells you when they change.
This Privacy Policy explains what data we collect, how we use it, how we store and secure it, who we share it with, how long we keep it, and what control you have over it.
It covers all parts of the service:
- The browser extension for Chrome, Edge, and Firefox
- The web dashboard at
sitespy.app - The backend API at
detect.coolify.vkuprin.com
Data controller: Vitaly Kuprin (sole developer and operator of Site Spy). Privacy contact: support@sitespy.app
If you want a section of this policy explained, or you disagree with something in it, email the address above.
2. Information We Collect
2.1 Account and Authentication Data
| Data | When collected | Why |
|---|---|---|
| Email address | On registration, or from Google Sign-In | Account identity, login, notifications, service and billing emails |
| Display name | On registration, or from Google Sign-In (defaults to the part of your email address before the at-sign) | Personalising the interface and emails |
| Password | Only if you register with email and password | Login. Stored only as a salted hash — we never store or have access to your plaintext password |
| Google account identifier | Only if you use Google Sign-In | Linking your Google login to your account |
| API key | Generated automatically on account creation | Authenticating the extension, the dashboard, and API clients to your account. This is a persistent identifier tied to you |
| Account creation date, email verification status, plan, trial end date | Automatically | Operating the service and enforcing plan limits |
2.2 Monitoring Data — The Core of the Service
This is the data Site Spy exists to handle. When you add a page to monitor, we collect and store:
- The URL you choose to monitor. If you use "Track Current Page", the extension reads the URL of the tab that is active at that moment. It reads that URL only when you click the button — it does not read your tabs in the background.
- The page title and favicon of that URL.
- The content of that page, fetched by our servers on a schedule. We store snapshots of the text content (and, on paid plans, screenshots) so we can compare one check against the next. Snapshots are the substance of pages you chose to monitor — treat them as being as sensitive as those pages are.
- Computed differences between consecutive snapshots.
- Your monitoring configuration: check interval, tags, CSS/XPath selectors, keyword and ignore filters, trigger text, and the free-text description of what changes matter to you.
- Element selections. If you use the element inspector, the extension sends the CSS selector of the element you picked plus up to the first 100 characters of its text, so the selection can be confirmed and saved.
- Operational metadata: when each check ran, whether it succeeded, error messages from failed fetches, and change counts.
Important: our servers fetch monitored pages themselves, from our own infrastructure. The extension does not scrape or upload the content of pages you browse. Only pages you explicitly add as a watch are fetched, and Site Spy sees those pages as an anonymous visitor would — it does not use your cookies, your session, or your logged-in state.
2.3 Notification Settings
Depending on which notification channels you enable, we store the destination and credentials needed to deliver alerts:
- Email address for alerts
- Telegram chat ID and bot token
- Webhook URLs (and any headers you configure)
- Web Push subscription endpoints and keys
- Your notification preferences, quiet settings, and per-watch mutes
Notifications we send contain the watch URL and an excerpt of what changed.
2.4 Billing Data
Paid plans are processed by Lemon Squeezy, which acts as the merchant of record.
- We never receive or store your card number, CVC, or bank details. Those go directly to Lemon Squeezy.
- We store: your plan, subscription status, renewal/expiry date, and the Lemon Squeezy subscription and customer IDs used to reconcile your account.
2.5 Information Collected Automatically
- Server and HTTP logs. Our servers log IP address, user agent, timestamp, requested endpoint, and response status for every request. These are used for security, abuse prevention, rate limiting, and debugging.
- Error diagnostics. Both the extension and the dashboard report unhandled errors — exception message, stack trace, application version, browser version — to a GlitchTip instance we host ourselves on our own infrastructure. This is not sent to a third-party error-tracking company. We filter out routine network and server-availability errors before they are recorded.
- Product analytics — web dashboard only, never in the extension. The dashboard records page views and feature interactions (for example, which upgrade button was clicked), along with referrer and coarse browser/device information, using an OpenPanel instance we host ourselves. The browser extension contains no analytics of any kind.
- AI usage records. If you use AI features, we log the interaction type, model name, token counts, latency, and the generated summary text, so we can enforce plan quotas and debug failures.
2.6 Support and Feedback
If you contact support, answer the in-product survey, or mark a detected change as useful or noise, we store what you send along with your account identifier so we can reply and improve detection quality.
2.7 Data Stored Locally in Your Browser
The extension keeps the following in your browser's local extension storage. This never leaves your device except as described elsewhere in this policy:
- Your API key and the backend URL
- A cached copy of your watch list, for fast popup rendering
- Notification preferences, refresh interval, and theme/UI settings
- Dismissed prompts and onboarding state
Uninstalling the extension deletes all of it.
3. What We Do Not Collect
- We do not track your general browsing history or the pages you visit. Only URLs you deliberately add as a watch are recorded.
- We do not read your cookies, passwords, form data, or logged-in sessions on the sites you visit or monitor.
- We do not collect health, biometric, government-ID, or precise-location data.
- We do not store card or bank details.
- We do not sell your data, and we do not use it for advertising, ad targeting, or profiling.
- The browser extension contains no analytics, no tracking pixels, and no advertising SDKs.
4. How We Use Your Information
| Purpose | Data used | GDPR legal basis |
|---|---|---|
| Monitoring your chosen pages and detecting changes | Monitoring data | Performance of a contract |
| Showing you diffs, history, and screenshots | Monitoring data | Performance of a contract |
| Sending change notifications | Notification settings, monitoring data | Performance of a contract |
| Authenticating you and keeping your account secure | Account data, API key | Performance of a contract |
| Taking payment and managing subscriptions | Billing data, email | Performance of a contract |
| Service emails (verification, password reset, plan changes, outage notices) | Email, account data | Performance of a contract |
| Occasional product emails and onboarding tips | Legitimate interest — you can unsubscribe from any of them | |
| Preventing abuse, spam signups, and fraud; enforcing rate limits | Logs, IP, account data | Legitimate interest |
| Fixing bugs and keeping the service reliable | Error diagnostics, logs | Legitimate interest |
| Understanding which dashboard features are used | Self-hosted analytics | Legitimate interest |
| Answering support requests | Support correspondence | Performance of a contract |
| AI summaries and smart filters | Monitored page content | Consent — off unless you enable it |
We do not make automated decisions about you that produce legal or similarly significant effects.
5. How and When We Share Your Information
We share data only in the circumstances below. We never sell personal data, and we never share it with advertisers or data brokers.
5.1 Service Providers We Rely On
| Provider | What they receive | Why |
|---|---|---|
| netcup GmbH (Germany) | All service data, as our hosting provider | Servers and storage |
| Lemon Squeezy | Your name, email, and payment details you enter on their checkout | Payment processing, invoicing, tax handling. They are the merchant of record |
| Apple iCloud Mail (SMTP) | Recipient address and message content of service and notification emails | Delivering email |
| Resend | Recipient address and message content of support-form emails | Delivering support correspondence |
Google Fonts (fonts.googleapis.com, fonts.gstatic.com) | Your IP address and user agent, when the extension popup or a page loads its webfonts | Rendering the interface typefaces |
Our analytics (OpenPanel) and error tracking (GlitchTip) run on our own servers, not on a third-party platform.
5.2 Destinations You Choose
Some sharing happens because you configured it, and only to the destination you specified:
- Notification channels. If you enable Telegram, a webhook, or Web Push, the change notification — including the watch URL and a content excerpt — is delivered to that destination and is then subject to that provider's privacy practices.
- AI providers. AI summaries and smart filters are off by default and available only on paid plans, and you supply your own API key. If you enable them, excerpts of the content of the pages you monitor are sent to the AI provider you selected — OpenAI, Anthropic, or Google — for processing under your own account with them. Turn the feature off, or leave the API key blank, and no page content is ever sent to any AI provider.
- Team members. If you add someone to your account, they can see the watches shared with them.
5.3 Other Circumstances
- Legal requirement. If we are legally compelled by a valid order from a competent authority.
- Security. Where necessary to investigate abuse, fraud, or a security incident.
- Business transfer. If Site Spy is ever merged, acquired, or sold, your data may transfer to the acquirer. You will be notified by email before any such transfer takes effect, and the acquirer will be bound by this policy until you are given notice of any change.
5.4 Human Access to Your Data
Your data is not read by people as a matter of routine. The developer may access it only when:
- You ask for support that requires it, and you consent to that access;
- It is necessary to investigate abuse or a security incident;
- The law requires it; or
- The data has been aggregated and anonymised for internal statistics (for example, "how many watches errored this week").
6. Limited Use Disclosure (Chrome Web Store)
Site Spy's use of information received from Google APIs, and all data obtained through Chrome extension permissions, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:
- Allowed use. We only use the data we collect to provide and improve the extension's single, user-facing purpose: monitoring web pages you explicitly choose and notifying you when they change. We do not use it for any unrelated purpose.
- Allowed transfer. We do not transfer user data to third parties, except: to the service providers listed in Section 5.1 who process it on our behalf strictly to operate the service; to destinations you yourself configure (Section 5.2); where necessary to comply with applicable law; where necessary for security purposes such as investigating abuse; or as part of a merger, acquisition, or sale of assets, with prior notice to you.
- Prohibited advertising. We never use or transfer user data to serve personalised, re-targeted, or interest-based advertising. The extension contains no advertising of any kind.
- Prohibited human interaction. We do not allow humans to read user data, except in the limited cases listed in Section 5.4.
- No sale of data. We do not sell user data to anyone, and we do not use or transfer it to determine creditworthiness or for lending purposes.
7. Extension Permissions and Why We Need Them
| Permission | Why it is required |
|---|---|
tabs | To read the URL and title of the current tab at the moment you click "Track Current Page" or use the context menu. Not used to observe browsing in the background |
storage | To save your API key, cached watch list, and preferences locally in your browser |
alarms | To schedule the periodic refresh of your watch list at the interval you configure |
notifications | To show a browser notification when a monitored page changes |
contextMenus | To add the right-click "Track this page" entry |
scripting | To inject the element inspector into a page only when you start it, so you can point at the region to monitor |
host_permissions (http://*/*, https://*/*) | Site Spy cannot know in advance which sites you will want to monitor, so the element inspector must be able to run on any site you choose. It runs only when you invoke it |
8. Data Storage, Location, and Security
Where. All server-side data is stored on servers operated by netcup GmbH in Germany (European Union). Some of the service providers in Section 5.1 process data outside the EU; see Section 11.
Security measures. We:
- Transmit all data over TLS (HTTPS). No user data is sent over an unencrypted connection.
- Store passwords only as salted hashes, using a strong one-way hashing function. Plaintext passwords are never written to disk or logs.
- Scope every API request to the caller's own account, so one account cannot read another's data.
- Harden our servers with key-only SSH access, a firewall (UFW), intrusion banning (fail2ban), kernel hardening, and automatic security updates.
- Restrict administrative access to the single developer who operates the service.
Honest limitation. Application data at rest sits on our provider's storage and is not additionally encrypted with a separate application-level key. We tell you this rather than overstate our protections. If you monitor pages whose content you consider highly confidential, factor this in.
No system is perfectly secure. If a breach affects your personal data, we will notify affected users and the competent supervisory authority without undue delay, and within 72 hours of becoming aware where GDPR requires it.
9. How Long We Keep Data
| Data | Retention |
|---|---|
| Page snapshots and diffs | By plan: Free 30 days or the 8 most recent per watch; Starter 90 days or the 25 most recent; Pro 365 days or the 100 most recent. Whichever limit is reached first — older snapshots are pruned automatically |
| Watch configuration | Until you delete the watch or your account |
| Account data | Until you delete your account |
| Unverified accounts | Deleted automatically after 14 days if the email address was never verified, provided the account has no watches and no subscription |
| AI interaction records | 90 days, then deleted automatically |
| Notification credentials | Until you remove the channel or delete your account |
| Billing records | Retained as long as required by tax and accounting law, typically up to 10 years, even after account deletion |
| Server and HTTP logs | Rotated on a short cycle and kept only for security and debugging |
| Error diagnostics | Kept on our self-hosted instance for a limited debugging window |
| Support correspondence | Kept while needed to resolve the issue and for a reasonable period afterwards |
| Data in your browser | Until you uninstall the extension or clear browser data |
10. Your Rights and How to Use Them
Wherever you live, you can:
- Access your data — everything is visible in the dashboard, and Settings → Data Export produces a machine-readable copy.
- Correct your name, email, notification settings, and watch configuration at any time in Settings.
- Delete individual watches from the dashboard or extension, or your entire account and all associated data via Settings → Delete Account. Account deletion is permanent.
- Withdraw consent to optional processing — turn off AI features, remove a notification channel, or unsubscribe from product emails — without losing access to the core service.
- Object or restrict: email support@sitespy.app and we will action it.
If you are in the EEA or UK, you also have the right to data portability and the right to lodge a complaint with your national data protection supervisory authority.
If you are in California, we confirm we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not discriminate against you for exercising your rights.
We respond to rights requests within 30 days, free of charge.
11. International Data Transfers
Our servers are in Germany. Some service providers in Section 5.1 — Lemon Squeezy, Resend, and Google Fonts — process data in the United States or other countries. Where personal data leaves the EEA, those transfers rely on the safeguards those providers offer, such as Standard Contractual Clauses or an applicable adequacy decision.
12. Children's Privacy
Site Spy is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has created an account, email support@sitespy.app and we will delete it.
13. Changes to This Policy
We may update this policy as the service changes. When we do, we will update the "Last Updated" date above. For changes that materially affect how we handle your data, we will notify registered users by email before the change takes effect.
14. Contact
Questions, requests, or complaints about this policy or your data:
Email: support@sitespy.app Developer: Vitaly Kuprin — https://vkuprin.com/contact
A postal address for formal data protection correspondence is available on request.