Site SpySite Spy
← Site Spy

Privacy Policy for Site Spy

Last Updated: August 11, 2026

1. Who We Are and What This Covers

Site Spy is a website change monitoring service. You tell it which web pages to watch, and it checks those pages on a schedule and tells you when they change.

This Privacy Policy explains what data we collect, how we use it, how we store and secure it, who we share it with, how long we keep it, and what control you have over it.

It covers all parts of the service:

  • The browser extension for Chrome, Edge, and Firefox
  • The web dashboard at sitespy.app
  • The backend API at detect.coolify.vkuprin.com

Data controller: Vitaly Kuprin (sole developer and operator of Site Spy). Privacy contact: support@sitespy.app

If you want a section of this policy explained, or you disagree with something in it, email the address above.


2. Information We Collect

2.1 Account and Authentication Data

DataWhen collectedWhy
Email addressOn registration, or from Google Sign-InAccount identity, login, notifications, service and billing emails
Display nameOn registration, or from Google Sign-In (defaults to the part of your email address before the at-sign)Personalising the interface and emails
PasswordOnly if you register with email and passwordLogin. Stored only as a salted hash — we never store or have access to your plaintext password
Google account identifierOnly if you use Google Sign-InLinking your Google login to your account
API keyGenerated automatically on account creationAuthenticating the extension, the dashboard, and API clients to your account. This is a persistent identifier tied to you
Account creation date, email verification status, plan, trial end dateAutomaticallyOperating the service and enforcing plan limits

2.2 Monitoring Data — The Core of the Service

This is the data Site Spy exists to handle. When you add a page to monitor, we collect and store:

  • The URL you choose to monitor. If you use "Track Current Page", the extension reads the URL of the tab that is active at that moment. It reads that URL only when you click the button — it does not read your tabs in the background.
  • The page title and favicon of that URL.
  • The content of that page, fetched by our servers on a schedule. We store snapshots of the text content (and, on paid plans, screenshots) so we can compare one check against the next. Snapshots are the substance of pages you chose to monitor — treat them as being as sensitive as those pages are.
  • Computed differences between consecutive snapshots.
  • Your monitoring configuration: check interval, tags, CSS/XPath selectors, keyword and ignore filters, trigger text, and the free-text description of what changes matter to you.
  • Element selections. If you use the element inspector, the extension sends the CSS selector of the element you picked plus up to the first 100 characters of its text, so the selection can be confirmed and saved.
  • Operational metadata: when each check ran, whether it succeeded, error messages from failed fetches, and change counts.

Important: our servers fetch monitored pages themselves, from our own infrastructure. The extension does not scrape or upload the content of pages you browse. Only pages you explicitly add as a watch are fetched, and Site Spy sees those pages as an anonymous visitor would — it does not use your cookies, your session, or your logged-in state.

2.3 Notification Settings

Depending on which notification channels you enable, we store the destination and credentials needed to deliver alerts:

  • Email address for alerts
  • Telegram chat ID and bot token
  • Webhook URLs (and any headers you configure)
  • Web Push subscription endpoints and keys
  • Your notification preferences, quiet settings, and per-watch mutes

Notifications we send contain the watch URL and an excerpt of what changed.

2.4 Billing Data

Paid plans are processed by Lemon Squeezy, which acts as the merchant of record.

  • We never receive or store your card number, CVC, or bank details. Those go directly to Lemon Squeezy.
  • We store: your plan, subscription status, renewal/expiry date, and the Lemon Squeezy subscription and customer IDs used to reconcile your account.

2.5 Information Collected Automatically

  • Server and HTTP logs. Our servers log IP address, user agent, timestamp, requested endpoint, and response status for every request. These are used for security, abuse prevention, rate limiting, and debugging.
  • Error diagnostics. Both the extension and the dashboard report unhandled errors — exception message, stack trace, application version, browser version — to a GlitchTip instance we host ourselves on our own infrastructure. This is not sent to a third-party error-tracking company. We filter out routine network and server-availability errors before they are recorded.
  • Product analytics — web dashboard only, never in the extension. The dashboard records page views and feature interactions (for example, which upgrade button was clicked), along with referrer and coarse browser/device information, using an OpenPanel instance we host ourselves. The browser extension contains no analytics of any kind.
  • AI usage records. If you use AI features, we log the interaction type, model name, token counts, latency, and the generated summary text, so we can enforce plan quotas and debug failures.

2.6 Support and Feedback

If you contact support, answer the in-product survey, or mark a detected change as useful or noise, we store what you send along with your account identifier so we can reply and improve detection quality.

2.7 Data Stored Locally in Your Browser

The extension keeps the following in your browser's local extension storage. This never leaves your device except as described elsewhere in this policy:

  • Your API key and the backend URL
  • A cached copy of your watch list, for fast popup rendering
  • Notification preferences, refresh interval, and theme/UI settings
  • Dismissed prompts and onboarding state

Uninstalling the extension deletes all of it.


3. What We Do Not Collect

  • We do not track your general browsing history or the pages you visit. Only URLs you deliberately add as a watch are recorded.
  • We do not read your cookies, passwords, form data, or logged-in sessions on the sites you visit or monitor.
  • We do not collect health, biometric, government-ID, or precise-location data.
  • We do not store card or bank details.
  • We do not sell your data, and we do not use it for advertising, ad targeting, or profiling.
  • The browser extension contains no analytics, no tracking pixels, and no advertising SDKs.

4. How We Use Your Information

PurposeData usedGDPR legal basis
Monitoring your chosen pages and detecting changesMonitoring dataPerformance of a contract
Showing you diffs, history, and screenshotsMonitoring dataPerformance of a contract
Sending change notificationsNotification settings, monitoring dataPerformance of a contract
Authenticating you and keeping your account secureAccount data, API keyPerformance of a contract
Taking payment and managing subscriptionsBilling data, emailPerformance of a contract
Service emails (verification, password reset, plan changes, outage notices)Email, account dataPerformance of a contract
Occasional product emails and onboarding tipsEmailLegitimate interest — you can unsubscribe from any of them
Preventing abuse, spam signups, and fraud; enforcing rate limitsLogs, IP, account dataLegitimate interest
Fixing bugs and keeping the service reliableError diagnostics, logsLegitimate interest
Understanding which dashboard features are usedSelf-hosted analyticsLegitimate interest
Answering support requestsSupport correspondencePerformance of a contract
AI summaries and smart filtersMonitored page contentConsent — off unless you enable it

We do not make automated decisions about you that produce legal or similarly significant effects.


5. How and When We Share Your Information

We share data only in the circumstances below. We never sell personal data, and we never share it with advertisers or data brokers.

5.1 Service Providers We Rely On

ProviderWhat they receiveWhy
netcup GmbH (Germany)All service data, as our hosting providerServers and storage
Lemon SqueezyYour name, email, and payment details you enter on their checkoutPayment processing, invoicing, tax handling. They are the merchant of record
Apple iCloud Mail (SMTP)Recipient address and message content of service and notification emailsDelivering email
ResendRecipient address and message content of support-form emailsDelivering support correspondence
Google Fonts (fonts.googleapis.com, fonts.gstatic.com)Your IP address and user agent, when the extension popup or a page loads its webfontsRendering the interface typefaces

Our analytics (OpenPanel) and error tracking (GlitchTip) run on our own servers, not on a third-party platform.

5.2 Destinations You Choose

Some sharing happens because you configured it, and only to the destination you specified:

  • Notification channels. If you enable Telegram, a webhook, or Web Push, the change notification — including the watch URL and a content excerpt — is delivered to that destination and is then subject to that provider's privacy practices.
  • AI providers. AI summaries and smart filters are off by default and available only on paid plans, and you supply your own API key. If you enable them, excerpts of the content of the pages you monitor are sent to the AI provider you selected — OpenAI, Anthropic, or Google — for processing under your own account with them. Turn the feature off, or leave the API key blank, and no page content is ever sent to any AI provider.
  • Team members. If you add someone to your account, they can see the watches shared with them.

5.3 Other Circumstances

  • Legal requirement. If we are legally compelled by a valid order from a competent authority.
  • Security. Where necessary to investigate abuse, fraud, or a security incident.
  • Business transfer. If Site Spy is ever merged, acquired, or sold, your data may transfer to the acquirer. You will be notified by email before any such transfer takes effect, and the acquirer will be bound by this policy until you are given notice of any change.

5.4 Human Access to Your Data

Your data is not read by people as a matter of routine. The developer may access it only when:

  • You ask for support that requires it, and you consent to that access;
  • It is necessary to investigate abuse or a security incident;
  • The law requires it; or
  • The data has been aggregated and anonymised for internal statistics (for example, "how many watches errored this week").

6. Limited Use Disclosure (Chrome Web Store)

Site Spy's use of information received from Google APIs, and all data obtained through Chrome extension permissions, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:

  1. Allowed use. We only use the data we collect to provide and improve the extension's single, user-facing purpose: monitoring web pages you explicitly choose and notifying you when they change. We do not use it for any unrelated purpose.
  2. Allowed transfer. We do not transfer user data to third parties, except: to the service providers listed in Section 5.1 who process it on our behalf strictly to operate the service; to destinations you yourself configure (Section 5.2); where necessary to comply with applicable law; where necessary for security purposes such as investigating abuse; or as part of a merger, acquisition, or sale of assets, with prior notice to you.
  3. Prohibited advertising. We never use or transfer user data to serve personalised, re-targeted, or interest-based advertising. The extension contains no advertising of any kind.
  4. Prohibited human interaction. We do not allow humans to read user data, except in the limited cases listed in Section 5.4.
  5. No sale of data. We do not sell user data to anyone, and we do not use or transfer it to determine creditworthiness or for lending purposes.

7. Extension Permissions and Why We Need Them

PermissionWhy it is required
tabsTo read the URL and title of the current tab at the moment you click "Track Current Page" or use the context menu. Not used to observe browsing in the background
storageTo save your API key, cached watch list, and preferences locally in your browser
alarmsTo schedule the periodic refresh of your watch list at the interval you configure
notificationsTo show a browser notification when a monitored page changes
contextMenusTo add the right-click "Track this page" entry
scriptingTo inject the element inspector into a page only when you start it, so you can point at the region to monitor
host_permissions (http://*/*, https://*/*)Site Spy cannot know in advance which sites you will want to monitor, so the element inspector must be able to run on any site you choose. It runs only when you invoke it

8. Data Storage, Location, and Security

Where. All server-side data is stored on servers operated by netcup GmbH in Germany (European Union). Some of the service providers in Section 5.1 process data outside the EU; see Section 11.

Security measures. We:

  • Transmit all data over TLS (HTTPS). No user data is sent over an unencrypted connection.
  • Store passwords only as salted hashes, using a strong one-way hashing function. Plaintext passwords are never written to disk or logs.
  • Scope every API request to the caller's own account, so one account cannot read another's data.
  • Harden our servers with key-only SSH access, a firewall (UFW), intrusion banning (fail2ban), kernel hardening, and automatic security updates.
  • Restrict administrative access to the single developer who operates the service.

Honest limitation. Application data at rest sits on our provider's storage and is not additionally encrypted with a separate application-level key. We tell you this rather than overstate our protections. If you monitor pages whose content you consider highly confidential, factor this in.

No system is perfectly secure. If a breach affects your personal data, we will notify affected users and the competent supervisory authority without undue delay, and within 72 hours of becoming aware where GDPR requires it.


9. How Long We Keep Data

DataRetention
Page snapshots and diffsBy plan: Free 30 days or the 8 most recent per watch; Starter 90 days or the 25 most recent; Pro 365 days or the 100 most recent. Whichever limit is reached first — older snapshots are pruned automatically
Watch configurationUntil you delete the watch or your account
Account dataUntil you delete your account
Unverified accountsDeleted automatically after 14 days if the email address was never verified, provided the account has no watches and no subscription
AI interaction records90 days, then deleted automatically
Notification credentialsUntil you remove the channel or delete your account
Billing recordsRetained as long as required by tax and accounting law, typically up to 10 years, even after account deletion
Server and HTTP logsRotated on a short cycle and kept only for security and debugging
Error diagnosticsKept on our self-hosted instance for a limited debugging window
Support correspondenceKept while needed to resolve the issue and for a reasonable period afterwards
Data in your browserUntil you uninstall the extension or clear browser data

10. Your Rights and How to Use Them

Wherever you live, you can:

  • Access your data — everything is visible in the dashboard, and Settings → Data Export produces a machine-readable copy.
  • Correct your name, email, notification settings, and watch configuration at any time in Settings.
  • Delete individual watches from the dashboard or extension, or your entire account and all associated data via Settings → Delete Account. Account deletion is permanent.
  • Withdraw consent to optional processing — turn off AI features, remove a notification channel, or unsubscribe from product emails — without losing access to the core service.
  • Object or restrict: email support@sitespy.app and we will action it.

If you are in the EEA or UK, you also have the right to data portability and the right to lodge a complaint with your national data protection supervisory authority.

If you are in California, we confirm we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not discriminate against you for exercising your rights.

We respond to rights requests within 30 days, free of charge.


11. International Data Transfers

Our servers are in Germany. Some service providers in Section 5.1 — Lemon Squeezy, Resend, and Google Fonts — process data in the United States or other countries. Where personal data leaves the EEA, those transfers rely on the safeguards those providers offer, such as Standard Contractual Clauses or an applicable adequacy decision.


12. Children's Privacy

Site Spy is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has created an account, email support@sitespy.app and we will delete it.


13. Changes to This Policy

We may update this policy as the service changes. When we do, we will update the "Last Updated" date above. For changes that materially affect how we handle your data, we will notify registered users by email before the change takes effect.


14. Contact

Questions, requests, or complaints about this policy or your data:

Email: support@sitespy.app Developer: Vitaly Kuprin — https://vkuprin.com/contact

A postal address for formal data protection correspondence is available on request.