Privacy
Last updated: September 17, 2026.
This MVP collects only the information needed to validate and monitor deep-link association files, measure whether relevant visitors use the validator, and deliver requested operational alerts.
Information processed
Validator requests include the domain you submit. For first-party traffic measurement, the browser keeps a random session identifier in sessionStorage and sends UTM source, medium, campaign and content values when present, the landing path, and the referring hostname when available. The server stores only a one-way hash of the session identifier. It does not store the full referrer URL, advertising click identifiers such as gclid, or cookies for this measurement.
Monitoring additionally stores the verified domain, alert email address, monitor configuration, validation history, and a one-way hash of the management token. The browser stores the management token locally so you can manage the monitor without an account.
Purpose
First-party traffic fields are used to compare acquisition channels and validator usage. The domain and alert email are used to verify domain ownership, run scheduled checks, show monitor history, prevent duplicate alerts, and send breaking-change notifications you requested. Alert email addresses are not added to traffic measurement metadata and are not used for marketing during this MVP.
Service providers
Cloudflare Workers and D1 provide application hosting and data storage. Resend delivers transactional alert email. No third-party analytics or advertising SDK is used for traffic measurement. These providers process information needed to provide their services under their own terms and privacy policies.
Retention
Active monitor data is retained while monitoring is enabled. When a monitor is disabled, its monitor record and associated check history are automatically deleted after 30 days. Operational metrics use hashes for domains and browser sessions rather than storing those identifiers in raw form. Email-provider logs may be retained by Resend under its own policies.
Security and network data
Cloudflare may process ordinary network metadata such as IP addresses to deliver and protect the service. This application does not store raw visitor IP addresses in D1. Requests are rate limited and arbitrary URL fetching is not supported.
Contact
For privacy questions, data-related requests, or support, email support@mail.signalnest.works.
MVP status
This is an early MVP and the service, limits, and operating practices may evolve as the product is validated.