SteadyMonitor

Privacy policy

Last updated 29 August 2026

1. Who we are

SteadyMonitor is operated by Steady Circuit Ltd, trading as SteadyCircuit, registered in England & Wales under company number 16471673, with its registered office at 66 Paul Street, London, EC2A 4NA. For anything in this policy, or to exercise any of the rights in section 9, contact hello@steadycircuit.com.

Where we host SteadyMonitor for you, we are the data controller for the information described below. SteadyMonitor can also be installed on your own servers; in that case the organisation running the installation is the controller, we hold none of the data, and this policy describes only what the software itself stores on their behalf.

2. What we hold

SteadyMonitor is an uptime monitor. Most of what it stores is about your systems rather than about people, but some of it can identify someone, and all of it is listed here.

3. Cookies and browser storage

SteadyMonitor sets no cookies and does no advertising, analytics or tracking of any kind. Your browser stores three things locally, none of which leaves your device except to authenticate you: your session token, your light or dark theme preference, and — only while a sign-in is in progress — the state of that sign-in. Signing out removes the session token.

4. Why we hold it, and on what basis

Account and configuration data is processed to perform our contract with you: without it there is no service. Monitoring results are processed for the same reason — they are the service. Security and operational data is processed under our legitimate interest in keeping the service available and defending it from abuse. We do not sell personal data, and we do not use it to profile or advertise to anyone.

5. Who else sees it

We will also disclose data where the law requires it. Nobody else receives it.

6. Where it is held

Your data is stored on Hetzner Cloud infrastructure in Helsinki, Finland — inside the European Economic Area. The third parties in section 5 may process data outside that region under their own terms; the only data that reaches them is what is needed to sign you in or to deliver an alert you asked for.

7. How long we keep it

8. How it is protected

Traffic is encrypted in transit with TLS. Each workspace's data is separated in the database at the row level, so one workspace's queries cannot read another's. Agent tokens are stored only as hashes, and alerting credentials are encrypted before storage. Requests pass through a web application firewall and per-address rate limits before they reach the application. No system is perfectly secure, and we do not claim otherwise.

9. Your rights

Under the UK GDPR and the EU GDPR you can ask us for a copy of your personal data, ask us to correct or delete it, ask us to restrict or object to how we use it, and ask for it in a portable form. Much of this you can do yourself from the dashboard, which lets you edit and delete anything you have configured and export your data. For anything else, write to hello@steadycircuit.com and we will respond within one month.

If you think we have handled your data badly, you can complain to the supervisory authority in your country — in the UK, the Information Commissioner's Office at ico.org.uk. We would rather you told us first.

10. Changes

If we change this policy we will update the date at the top, and we will tell you before any change that materially affects you takes effect.