Privacy
This notice covers zerolog Monitoring at zerolog.ch/monitoring, the landing page zerolog.ch/monitors and the API under /monitoring/api. It supplements the zerolog.ch privacy policy. Where the two differ, this notice governs the monitoring service. The German version is the authoritative one; this English text is a translation.
Version 1.0 · 23 September 2026
Controller
Gian-Luca Luongo, Dorfstrasse 77, 5430 Wettingen, Switzerland
Email: info@zerolog.ch
The controller is a natural person, not a company. There is no data protection officer; the controller answers requests personally. Further details are in the zerolog.ch legal notice.
In short
- You do not need an account. We set no cookies and store nothing in your browser.
- We do not store your IP address. For abuse protection we derive a daily pseudonym from it that changes every day.
- You give an email address only if you want to. It is never published.
- The whole service runs on Cloudflare, Inc. (USA) as our processor.
- You can delete your monitor yourself at any time with your management link.
Principles
We process personal data only for the purposes stated here, only as much as needed and only for as long as needed. What we do not need, we do not collect: no name, no phone number, no account, no audience measurement, no advertising.
When you open a page
When you open a page or call the API, Cloudflare, as the platform operator, necessarily processes your IP address, the requested address, date and time, browser and operating system details and connection data. No page can be delivered without them.
Our application reads your IP address in memory only. It does not reach our database or our own log lines.
Cloudflare writes a log entry for every request containing the requested address, the response and technical metadata. These logs serve troubleshooting and protection of the service. Cloudflare deletes them after 7 days.
Cookies and browser storage
We set no cookies and use neither local storage nor session storage. Pages load fonts, scripts and map data only from our own server. You choose the language through the address or your browser setting.
The forms are the one exception (see Turnstile): there, a Cloudflare script reads signals from your browser for bot detection.
Abuse protection with a daily pseudonym
To stop anyone from flooding the service with automated entries, we limit the forms, for example to at most 5 new monitors per day and sender. For this we derive a pseudonym from your IP address: a keyed hash (HMAC-SHA-256) using a secret key and the current calendar day.
- Without the secret key, the IP address cannot be recovered from the pseudonym.
- Because the day is part of the calculation, the same IP address yields a different pseudonym every day. Entries from different days cannot be linked.
- We, the controller, hold the key. For us the pseudonym therefore remains personal data, and we treat it as such.
Where the pseudonym is stored and for how long is set out under Retention.
Turnstile (form protection)
The forms "Add a website", "Report a region", "Request a country", "Report abuse" and voting on the request board are protected by Cloudflare Turnstile. Only on these pages does your browser load a script from challenges.cloudflare.com. Turnstile processes your IP address, a technical fingerprint of the encrypted connection, your browser identifier (user agent) and the page address. When you submit, our server checks the result with Cloudflare and passes on your IP address.
For bot detection on our pages Cloudflare acts as our processor. According to Cloudflare, it additionally uses these signals under its own responsibility to improve bot detection. The Cloudflare Turnstile privacy addendum applies to that.
Without Turnstile you cannot submit the forms. All read-only pages work without it.
Website monitoring
When you add a website we store:
- the website address (required), optionally a keyword that must appear on the page, and a display name;
- optionally alert channels: a webhook address (generic, Discord or Slack) and an ntfy topic;
- the daily pseudonym of your IP address and the creation time;
- the time the status page was last viewed;
- a verification code for confirming the domain;
- a hash of your management key. We do not store the key itself.
Purpose: check the website every 5 minutes, show a status page and notify you when its state changes.
Your management link is the only access to your monitor. Anyone who has it can change and delete the monitor. Keep it like a password and do not share it. We cannot recover lost management links.
Status page. Every monitor gets a status page with availability, response time and history. Only websites with a confirmed domain and public services pre-listed by us are listed publicly (search, sitemap). Unconfirmed status pages are reachable only through their link, blocked for search engines, and show the domain as plain text without a link. Alert channels, the daily pseudonym and the management key never appear on the status page.
Alerts. On a state change we send a message with the website's name, address and state to the channels you entered. Discord, Slack, ntfy or your own webhook receiver get this message on your instruction; their own terms apply to processing there. Each monitor also has a public Atom feed that contains state changes only.
Email alerts are currently not available, and the form does not ask for an email address. If we introduce them: sign-up only with a confirmation link (double opt-in), an unsubscribe link in every email, and we delete the address after you unsubscribe. We will update this notice beforehand.
Third-party websites. You do not have to own a website to add it. Our check requests the page like a browser and reads at most 256 KB. We keep only reachability, HTTP code, response time, certificate expiry and whether the keyword appears, no page content. Operators of a listed website can have the entry blocked through "Report abuse" or by email.
Requests and board
With "Report a region" and "Request a country" you report missing sources, false alarms or missed outages. We store:
- region or country, type of report and topic;
- optionally a note and a source address;
- optionally your email address for a reply;
- the daily pseudonym of your IP address and the timestamps.
The public board and the API show region or country, type, topic, your note, status, vote count and date, and whether a source was given. So please do not put details about yourself or other people in the note. Source address, email address and pseudonym stay internal. The operator reviews suggested sources by hand; nothing is adopted automatically.
The email address is optional. We use it only to reply about that one request, for example when it is done or rejected or when we have a question. No newsletter, no advertising, no disclosure.
For votes ("+1") we store the daily pseudonym per request so the same connection counts only once per day.
Reporting abuse
Every status page lets you report a monitor. We store the monitor ID, the reason, optionally your note, the daily pseudonym and the time. The operator reviews the report and blocks the monitor if needed. Please do not put details about yourself in the note that the review does not need.
Data from other sources
Outage indicators are based on public sources: grid and network operator notices, news metadata (from publisher feeds and GDELT), network measurements from IODA, and place data from GeoNames and Natural Earth. From news we take only title, publisher, link and time, no article text and no images. Personal data is not what we are after. If a title names a person, the name appears only as part of that title with a link to the source. We delete such entries after 90 days. All sources are listed on the methodology page.
The daily blocklist of harmful websites contains host names only, no personal data.
Recipients
- Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA, as processor for hosting, database, cache, queues, logs and Turnstile, under the Cloudflare Customer Data Processing Addendum.
- The recipients of your alerts that you enter yourself (Discord, Slack, ntfy or your webhook server).
- The operator (Gian-Luca Luongo). There are no other recipients. We do not sell data or pass it on for advertising.
Transfers abroad
USA. Cloudflare, Inc. is based in the USA. Under Annex 1 of the Swiss Data Protection Ordinance, the USA counts as providing adequate protection only for organisations certified under the Swiss-U.S. Data Privacy Framework. Cloudflare, Inc. is listed there (record 5666, Swiss-US certification, checked on 23 September 2026: active, re-certification under review). The transfer therefore rests on Art. 16 para. 1 of the Swiss Federal Act on Data Protection (FADP). We have not concluded separate standard contractual clauses. If the certification lapses, we will update this notice.
Locations. Your connection is handled by the Cloudflare location nearest to you; from Switzerland normally Zurich or Geneva, otherwise a location in the country or region you connect from. The database runs with the location hint Western Europe. Cloudflare states that the hint does not guarantee the location, so we cannot name a single country for it. Cached overview data without personal reference is distributed worldwide by Cloudflare.
Alert channels. Where an alert goes is determined by the address you enter. The message contains only details about the monitored website.
Retention and deletion
- Monitor (address, name, keyword, alert channels): until you delete it with the management link. Monitors whose status page has not been viewed for 60 days and that have no alert channel are paused. If a paused monitor stays untouched for another 12 months, we delete it.
- Daily pseudonym on monitors, requests and abuse reports: removed 30 days after creation.
- Abuse-protection counters: until the end of their time window, deleted in the next daily run, so after 2 days at most.
- Votes on the board (with daily pseudonym): 90 days.
- Email address on requests: until 90 days after the request is done or rejected. Immediately on request.
- Abuse reports: 12 months after they are handled.
- Website check measurements: single checks 7 days, hourly values 90 days. They contain no personal data.
- Logs at Cloudflare: 7 days.
- Backups: Cloudflare can restore the database to any point in the last 30 days. Deleted data therefore remains in this backup for up to 30 days. We restore only to fix a fault and then delete again whatever you had asked us to delete.
When you delete a monitor, we remove it and its alert channels immediately. The website's check history goes with it unless someone else monitors the same address.
A daily maintenance run applies these periods. Where it does not yet do so automatically, the operator deletes by hand.
Security
- All connections are encrypted (HTTPS).
- Pages load third-party code only for Turnstile and only on the form pages. A Content Security Policy blocks all other third-party sources.
- We store the management key only as a hash and compare it in constant time.
- We store IP addresses only as a daily pseudonym with a secret key.
- Inputs have fixed maximum lengths, for example 2048 characters for addresses and 1000 characters for notes. We reject addresses in internal networks.
- Only the operator has access to the database and the logs.
Your rights
You can ask what personal data we process about you (Art. 25 FADP). Access is free of charge, and we answer within 30 days. You can also ask us to correct inaccurate data or delete your data, object to processing, and ask for your data in a common electronic format (Art. 28 FADP).
Do it yourself. With your management link you can view, change and delete your monitor at any time.
By email. Write to info@zerolog.ch. Because there are no accounts, we can only match you through something you show us: a monitor's management link, a request number together with the email address given there, or the ID of a reported monitor. We can recompute a daily pseudonym only from the IP address and calendar day you give us. Without such proof we do not hand out data, because otherwise whoever asks first would get it.
Complaints
You can contact the Swiss Federal Data Protection and Information Commissioner (FDPIC), www.edoeb.admin.ch. The FDPIC can open an investigation (Art. 49 FADP).
For people in the EU and EEA
The service is also aimed at people in Europe outside Switzerland. Where the General Data Protection Regulation (GDPR) applies, the following also holds:
- Legal bases. Delivering pages, logs, the daily pseudonym and Turnstile: legitimate interest in a secure service free of abuse (Art. 6(1)(f) GDPR). Monitor, status page and alerts: providing the service you requested (Art. 6(1)(b) GDPR). Optional email address on requests: your consent (Art. 6(1)(a) GDPR), which you can withdraw by email at any time.
- Transfer to the USA. Cloudflare, Inc. is also certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR).
- Your rights under Art. 15 to 22 GDPR: access, rectification, erasure, restriction, data portability and objection. We make no automated decisions about you.
- Complaints can be lodged with the data protection authority of the state where you live or work.
Disclaimer
zerolog Monitoring is not an official warning service. Its indicators are based on automatically evaluated public sources and fixed rules. They can be incomplete, late or wrong. We give no warranty for accuracy, completeness or availability, neither for the outage indicators nor for website monitoring and its alerts.
Do not rely on this site in an emergency. In an emergency, contact the official authorities: 112 across Europe; in Switzerland also police 117, fire 118, ambulance 144; 911 in North America. For power or network outages, your grid operator or provider and the authorities give binding information.
Operators of linked third-party sites are responsible for their content.
Changes
We update this notice when the service or the law changes. The version published here applies. Version 1.0 of 23 September 2026.