Skip to content
How it worksPricingAbout
Sign inStart seven-day trial

Privacy notice

Who is responsible for what, what is held and why, where it sits, how long it stays, and how to ask for it to be corrected or deleted.

Effective from 2026-09-12

1. Who is responsible

stillworks.watch is operated by Tomáš Pilař, a sole trader (self-employed natural person) registered in the Czech Republic, identification number (IČO) 88527069, with registered business address at Škroupova 564, 537 01 Chrudim – Chrudim III, Czech Republic (the Operator).

Register
Czech Trade Licensing Register (živnostenský rejstřík); competent trade licensing authority: Městský úřad Chrudim
Privacy requests
privacy@stillworks.watch
Data protection officer
No data protection officer is appointed. The Operator is a sole trader whose core activities do not consist of large-scale, regular and systematic observation of individuals or large-scale processing of special categories of data, so Article 37 GDPR does not require one
Supervisory authority
Úřad pro ochranu osobních údajů (the Czech Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic

The privacy address is the one to use for access, export, correction, deletion and any other question about personal data. Support handles product questions and is not the channel for privacy requests, although a request sent there is passed on.

2. Two roles, kept apart

The Operator is the controller for the personal data of its own customers and of the people it deals with directly: account and customer identity, authentication, billing and account administration, abuse, fraud and rate-limit protection, the Service's operational and security logs, communications with you, and compliance with the Operator's own legal obligations. Section 3 describes that processing.

For data contained in or derived from your application while the Service performs the checks you asked for, you are the controller and the Operator is your processor, acting on your documented instructions. That covers page content collected to propose checks, screenshots, recordings, network traces, page content used by the visual fallback, the credentials you configure, visitor-error events from the optional snippet, and inbound email data for email steps. Section 4 lists it; the data processing agreement governs it.

The Service is offered to businesses, but the GDPR protects individuals regardless of who the customer is. A sole trader's account data, the name of the person acting for a company, and the users of your application are all personal data and are treated as such.

3. What the Operator holds as controller

WhatDetailHow long
Account and sign-inYour email address, how you signed in, and, if you chose GitHub, the name, avatar and connection tokens GitHub sends. Sessions deliberately do not store your IP address or browser identification.While the account exists
Your projects and recipientsThe addresses of the applications you asked the Operator to watch, the checks on them, their schedule, and the recipients you verified for alerts.While the account exists
BillingYour email address, the identifiers of your Stripe customer record and subscription, and the plan and payment status Stripe reports. Card details are entered on Stripe's own pages and never reach the Service.While the account exists, then as the law on accounting evidence requires
Rate-limit and abuse protectionA keyed hash of the visitor's IP address for a run started from the landing page without an account, and a keyed hash of the email address and client address used to request a sign-in link. The addresses themselves are never stored.30 minutes for anonymous runs, at most 48 hours for sign-in link limits
Run history and operational logsWhich check ran, what it did, whether it passed, how long it took, and the Operator's own operational and security logs. Sign-in, alert and deploy tokens are stripped from the access log before it is written.Run history by plan; operational logs for a bounded period
CommunicationsEmails you exchange with the Operator, alerts and summaries sent to you, and the record of which recipient confirmed what and when.While the account exists, then as needed to evidence consent
A published snapshot of a websiteWhen a visitor publishes the result of a run they started from the landing page, the Operator holds the address of that website, what the one look at it found, and the icon the site publishes for itself. No page, no path and no content of the site is kept. Anybody with the link can open the page; it is kept out of search engines.Two weeks of findings, then a record without them for 90 days
Recorder connection qualityWhile you record a check, a bounded summary of how well the Operator's own connection to your browser held up: how long the first picture took to arrive, how steady it stayed, and whether it reached you directly or through a relay. No address, no page content, nothing you typed and no picture of your screen. It is attached to your account, so it is treated as personal data rather than described as anonymous.30 days from when it arrives

Legal bases. Account, project, recipient and billing data are processed to perform the contract with you (Article 6(1)(b) GDPR). Rate-limit hashes, security logs and abuse handling rest on the Operator's legitimate interest in keeping the Service secure and preventing it from being used against third parties (Article 6(1)(f)); the hashes are keyed so that the Operator cannot read an address back out of them. The quality of the Operator's own connection to your browser while you record a check rests on the same kind of interest, here in keeping the recorder working (Article 6(1)(f)). Accounting records are kept because the law requires it (Article 6(1)(c)). Nothing is processed for advertising, profiling or sale, and nothing is used to train an AI model.

A published snapshot of a website. Anybody can ask the Service to look once at a public address, and can then publish what it saw as a page others can open. The address of a small site can say who runs it, so publishing it rests on the Operator's legitimate interest in showing the person behind that site what is visible about it from outside, and in being found by them (Article 6(1)(f) GDPR). Only what one look at a public page shows is published: the address of the site, sentences about whether it answered, and the icon it publishes for itself. No page, no path and no content of the site is ever part of it, and the page is kept out of search engines. If a page like that is about your site, section 10 says how to have it taken down, and publishing a file at /.well-known/stillworks-optout on your domain stops the Service from looking at it at all.

Stripe. Payments are handled by Stripe. For the payment itself, fraud prevention, anti-money-laundering checks and its own regulatory duties, Stripe acts as an independent controller under its own privacy policy; for the subscription records it keeps for the Operator it acts as a processor. Deleting your stillworks.watch account does not erase the records Stripe must keep under its own legal obligations.

Network traces are never offered to you for download: they can contain tokens and the personal data of third parties, and they exist only for the Operator's own debugging.

4. What the Operator processes on your behalf

Each of the following may contain personal data of your users, staff, customers or correspondents. Not every run contains all of it; this is the possible scope, and what actually appears depends on what your application displays and on the checks you configure.

Page content used to propose checks
Server-rendered HTML of your home page and the links on it, collected once when a project is created so that checks can be proposed.
Screenshots, recordings and network traces
Pictures and video of the moment a check broke, and a network trace kept for the Operator's own debugging. These are images of your application and can show your users' names, email addresses and whatever was on the screen.
Page content used by the visual fallback
The screenshot and accessibility structure of a page, sent to the AI fallback only after every deterministic way of finding an element has failed, and never for a run that carries a credential.
Credentials you configure
Sign-in values for your application that you configure for a check, encrypted at rest and opened only inside the isolated runtime that needs them.
Visitor-error events
Error messages, stack traces, URL paths and viewport category from the optional one-line snippet you install. No cookie, no visitor identifier, no storage, no form values, no query string or fragment, no IP address and no full User-Agent.
Inbound email data
For a check that waits for an email from your application: the sender address, its domain and the link extracted from the message. The body, subject and attachments are never stored.
Recorder sessions
The addresses of the pages you open while recording a check, and a crop of each element you click, so that the recorded step can be reviewed. No live frame, keystroke or full-page image is kept.

An alert is an email, and it carries the screenshot of the moment your check broke as an attachment, because a link would have expired before you opened it. That screenshot is a picture of your application and can contain the personal data of your users: names in an admin list, email addresses in an order, whatever a half-filled form had in it. It goes through the Operator's mail provider and only to recipients who confirmed they want the messages. The picture travels with every email alert; an alert you send to Slack, Discord or your own webhook carries the text only. Nominate email recipients accordingly.

The visitor-error snippet is deliberately minimal: it sets no cookie, creates no visitor identifier, reads no storage, collects no form values, removes the query string and fragment from every URL before sending, and the Service stores neither the visitor's IP address nor the full User-Agent. It is still not true that a visitor error can never contain personal data: an error message, a stack trace or a URL path can contain whatever your application put there, and the Service cannot tell a token in a path from an ordinary segment. Raw events are deleted after two weeks.

The Service is not designed for the intentional or targeted processing of special categories of personal data, such as health data. Incidental capture can still occur where a screen of your application displays such information at the moment a screenshot or recording is taken, and the Operator does not claim it is technically impossible. The terms and the data processing agreement set out what you and the Operator each owe in that case.

5. Where the infrastructure is

Core infrastructure is hosted in the European Union. The servers, the database, the object storage holding screenshots and recordings, and the encrypted backups are with Hetzner in Germany; email is sent through Seznam.cz in the Czech Republic; the external availability check of the Service itself is with UptimeRobot in Slovakia. That is a fact about how the Service is deployed, not a preference.

Two things can leave the EU and are named rather than averaged into the sentence above. If you choose to sign in with GitHub, your email address, name and avatar reach GitHub in the United States; signing in with a link instead avoids that entirely. And AI requests are routed as section 6 describes. Every processor, with its legal entity and location, is listed on subprocessors.

The speed of your application is measured on the same machines that already run your checks, in the European Union. It is the Operator's own browser doing the measuring, on the Operator's own hardware, while it replays a check you configured: nothing is added to your application for it, nothing new runs in your visitors' browsers, and no visitor of yours takes part. What is kept from it is whole numbers and counts — how long a page took to answer and to draw, how many requests it made and how many bytes those were, how long each step of your check took — together with a short list of fixed words, such as whether a request went to your own site or to another one, which step of your check it belongs to, and which build of the Operator's browser did the measuring. Never kept: any address, path, query or fragment; any header, cookie or sign-in value; the body of any request or reply; anything written to the browser console; the title or the text of a page; the name or the value of any field; and the network address of the machine your application runs on. No new company receives any of it.

6. How AI requests are routed

This is a separate question from the one above and it has a separate answer. A model is asked exactly two things: to propose checks when you add a project, and to find an element again after every ordinary way of finding it has failed. Nothing else in the Service asks a model anything, and a model never decides whether your application is broken.

Requests are routed through OpenRouter, Inc., a United States company, to the inference provider pinned in the Operator's configuration. The pinned provider is Azure in the EU, so inference happens in the EU, but because the routing layer is a United States company the Operator does not describe the complete AI path as EU-only. Every request carries an instruction to the provider not to retain the content and not to use it for training, and a request is refused rather than handed to a provider outside the pinned list.

Right now every pinned provider is an EU regional endpoint, so inference for those two calls happens inside the EU. Pin a provider elsewhere and it stops doing so, and this paragraph will say that instead, because it is read from the same configuration that routes the request.

azure/eu
Microsoft Azure, Azure (EU) regional endpoint operated by Microsoft — EU region

The full chain, the maker of the model, the router and the party running the model, is on subprocessors, and security says what is sent in each of the two calls.

7. Recipients and international transfers

Personal data is shared only with the processors listed on subprocessors, with Stripe in its role as described in section 3, with recipients you nominate and verify, and with a public authority where the law requires it. It is not sold and it is not shared for advertising.

Where a transfer to a country outside the European Economic Area takes place, today the United States for OpenRouter's routing layer and, if you choose it, GitHub, it rests on the European Commission's standard contractual clauses or another transfer mechanism under Chapter V GDPR, together with the request-level retention and training restrictions described above. You can obtain details of the mechanism in use by writing to the privacy address.

8. Your browser

There is no analytics script on this site, no advertising, and nothing that follows you between pages, and none of that changes because of what comes next. While you record a check, the Operator measures the quality of its own connection to your browser: how long the first picture took to arrive, how steady it stayed afterwards, and whether it reached you directly or through a relay. That describes the Operator's own service rather than you. It carries no address, no page content, nothing you typed and no picture of your screen; it is attached to your account rather than to an identifier that follows you between sites; and the Operator deletes it 30 days after it arrives, or sooner if you delete your account.

There is also not nothing, and saying otherwise would be easier than it is true.

One cookie. A sign-in session, set when you sign in, valid for seven days and refreshed while you use the product. Signing out removes it. It is strictly necessary for the Service and needs no consent.

One key in local storage, named stillworks.scan. If you run a check from the landing page without an account, it holds the identifier of that one run and a token for reading its result, so the result survives the trip through a sign-in link into a new account. It says nothing about you, it works for that one run only, and it is discarded within 30 minutes. Nothing else on this site writes to your browser.

9. How long things are kept

WhatHow long
Run history and the speed measured during each run (metadata of each run)30 days on a trial and on Small, 90 days on Growing, 365 days on Portfolio
Recordings, screenshots and network traces30 days on every plan, without exception
Raw visitor-error eventsTwo weeks
Anonymous runs started from the landing page30 minutes
Recorder session records and element crops24 hours after the session ends
Recorder connection quality30 days from when it arrives, whatever your plan, and sooner if you delete your account
Link extracted from an inbound emailAt most 1 hour
Sign-in link rate-limit recordsAt most 48 hours
Encrypted database backups30 days
Data of a frozen, unpaid account30 days after the account was frozen
A published snapshot of a websiteTwo weeks for what the look found, then 90 days for the record of it
A deleted accountDeleted when you delete it from the product, except what the law requires the Operator to keep; a copy can remain in an encrypted backup for at most 30 days

Recordings and screenshots are deleted after 30 days on every plan, including the plan that keeps a year of history: history is the record of what happened, not the video of it. A frozen account keeps its projects and history until the deletion date shown in the product, but its recordings still fall under the 30-day cap. Backups are encrypted, retained for 30 days and then expire; a copy of deleted data can remain in a backup until its expiry, is never restored into the live Service except to recover from a disaster, and is not active service data.

10. Your rights and how to exercise them

You have the right to access the personal data the Operator holds about you, to receive a copy of it in a portable format, to have it corrected or deleted, to restrict or object to its processing, and to withdraw a consent you gave. Write to privacy@stillworks.watch from the address on your account; you will receive an answer within one month, and the Operator may ask you to confirm your identity first. A request that concerns the users of your application is answered with you, in your role as controller, as the data processing agreement sets out.

Deleting your account. You delete your whole account yourself, from Settings in the product, under Danger zone: choose Delete my account, type the email address of your account to confirm, and the deletion runs at once. It is irreversible. It removes your projects, checks, runs, recordings, screenshots, network traces, findings, incidents, visitor-error data, recorder sessions, the credentials you configured, alert recipients, sign-in sessions and the account itself, including the objects in storage. Deleting your account also ends your paid subscription, if you have one: the subscription is cancelled at Stripe first, at once rather than at the end of the period you have paid for, and only then is anything removed; if Stripe cannot be reached at that moment nothing is deleted and you can try again later. If storage cannot be emptied at that moment, the account is closed to sign-in and the deletion finishes automatically without you; it is never reported as done before it is. If you cannot sign in, write to the privacy address from the address on your account and the Operator deletes the account for you.

Two things are outside that deletion and are named rather than implied. Accounting records the Operator must keep under accounting or tax law, and the records Stripe keeps under its own legal obligations as an independent controller, have a legal basis of their own; they remain for their statutory periods and are not part of the active account. A copy of deleted data can remain in an encrypted backup until that backup expires, at most 30 days later; it is never restored except to recover the Service from a disaster and is not active service data. There is no download of your data in the product: a copy of it is provided on request to the privacy address, as the first paragraph of this section says.

A published page about your site. If somebody published a page here about a website you run, you can object to it and have it taken down. You do not need an account, you do not need to argue with whoever published it, and you are not asked to prove more than that the site is yours. Write to report@stillworks.watch and a person takes the page down within 24 hours and replies to say it is gone. The Service then no longer serves the snapshot, its findings or its old preview; the page and card say only that it was taken down. Another service or somebody who already received the link may still hold a copy or preview saved before the takedown, which the Service cannot remove from there. Reporting abuse says the same in more detail. You can also stop it without writing to anybody: publish a file at /.well-known/stillworks-optout on your domain and the Service stops looking at the domain and hides any page already published about it, usually within a day.

If you are not satisfied with the answer you can complain to Úřad pro ochranu osobních údajů (the Czech Office for Personal Data Protection), Pplk. Sochora 27, 170 00 Praha 7, Czech Republic, or to the supervisory authority of the EU member state where you live or work.

11. Changes to this notice

The Operator may update this notice, and the date at the top says which version you are reading. A change that affects how your personal data is used is notified to you by email before it takes effect.

The last thing to remember

Someone should be checking. It's me.

Know someone with more side projects than time? Send stillworks.watch their way.

You give me one URL. I keep checking it while you’re away.

stillworks.watch

A second look at the things you ship.

Product

  • How it works
  • Pricing
  • Help

Trust & support

  • About
  • Security
  • Status
  • Report abuse

Legal

  • Terms
  • Privacy
  • Data processing
  • Subprocessors