Privacy Policy #
Last updated: July 02, 2026
This Privacy Policy explains how WatchThatSite ("WatchThatSite", "we", "us", or "our") collects, uses, discloses, and safeguards your personal data when you use our website, applications, and related services (together, the "Service").
WatchThatSite is operated by an individual sole proprietor based in India (referred to as the "data controller" or "data fiduciary" where those terms apply). We are committed to protecting your privacy and handling your data transparently and in accordance with applicable data protection laws, including the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), and India's Digital Personal Data Protection Act, 2023 (DPDP Act).
By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.
1. Who We Are #
- Operator / Controller: Samya Brata Maji, an individual (sole proprietor).
- Location: India.
- Privacy contact: support@watchthat.site (see Contact & Grievances).
2. Scope #
This Privacy Policy applies to personal data we process when you:
- Visit our marketing website or documentation.
- Create and use a WatchThatSite account.
- Configure monitors, notification channels, and AI-assisted diffing.
- Subscribe to a paid plan.
- Contact us for support.
It does not cover third-party websites you choose to monitor, or third-party services you connect (such as Slack, Discord, Telegram, or your own AI provider), which are governed by their own privacy policies.
3. Personal Data We Collect #
3.1 Account Data #
When you register — directly or by signing in with Google — we collect:
- Your name.
- Your email address.
- A hashed password (only for email/password sign-up; we never store passwords in plain text).
- For Google sign-in: your name, email address, profile picture, and Google account identifier, as provided by Google. We do not receive your Google password.
Authentication is handled by Better Auth.
3.2 Monitor Configuration Data #
To operate the Service, we store the configuration you create, including:
- The URLs and web pages you choose to monitor.
- Check frequency, selectors, filters, and other monitor settings.
- Your notification preferences and connected notification channels.
3.3 Monitored Page Content (Snapshots & Diffs) #
To detect changes, we capture and store snapshots of the web pages you configure us to monitor, and we compute differences ("diffs") between snapshots. This content originates from third-party websites that you select. You are responsible for ensuring you have the right to monitor those pages and that they do not contain data you are not permitted to process.
3.4 AI Provider Keys (BYOK) #
WatchThatSite offers optional AI-assisted diffing on a "bring your own key" (BYOK) basis. If you enable it:
- You provide your own API key for a supported AI provider.
- We store that key encrypted within our self-hosted LLM gateway (Bifrost), which runs on our own infrastructure.
- Monitored page content processed for AI-assisted diffing is sent to the AI provider you configured, using your key. The routing gateway is self-hosted, so this content is not sent to any AI sub-processor of ours; the AI provider you choose processes it under its own terms.
3.5 Notification Channel Data #
To deliver alerts, we store the destination details for the channels you connect, which may include your email address and Slack, Discord, or Telegram channel/webhook identifiers.
3.6 Billing Data #
The Service is currently offered free of charge. If we introduce paid plans, payments and subscriptions will be processed by Polar.sh, which acts as our merchant of record. Polar would handle your payment card details directly — we never receive or store your full card number. We would receive only limited billing information from Polar, such as your name, billing country, plan, and payment status, to manage your account.
3.7 Usage & Device Data #
When you use the Service we automatically collect usage and diagnostic data through server logs, including your IP address, browser type and version, device information, referring pages, pages visited, and timestamps. We use this for security, debugging, and to operate the Service.
3.8 Support Data #
If you contact us, we keep the content of your message and your contact details so we can respond.
4. How We Use Your Data #
We use personal data to:
- Provide, operate, and maintain the Service, including running your monitors and delivering notifications.
- Create and manage your account and authenticate you.
- Process subscriptions and payments, if you purchase a paid plan (via Polar.sh).
- Provide AI-assisted diffing when you enable it.
- Respond to your support requests.
- Monitor, secure, debug, and improve the Service and prevent fraud and abuse.
- Send you service-related communications (for example, security or account notices).
- Send product or marketing communications where you have opted in, from which you can opt out at any time.
- Comply with legal obligations and enforce our terms.
Legal Bases (GDPR) #
Where the GDPR applies, we rely on the following legal bases:
- Performance of a contract — to provide the Service you have signed up for.
- Consent — for optional marketing communications; you may withdraw consent at any time.
- Legitimate interests — to secure, maintain, and improve the Service, and to prevent abuse, balanced against your rights.
- Legal obligation — where we must retain or disclose data to comply with law.
5. Cookies & Analytics #
We currently use only essential / authentication cookies — those required to sign you in and keep your session secure. These cannot be disabled without breaking the Service, and, being strictly necessary, they do not require consent.
We do not currently use third-party analytics, advertising, or tracking cookies. If we introduce analytics in the future, we will update this Policy and, where required, obtain your consent before any non-essential cookies are set. For details, see our Cookie Policy.
6. How We Share Your Data #
We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA.
We share personal data only with:
- Service providers / sub-processors that help us run the Service, listed below.
- Legal and safety recipients — where required by law, to respond to lawful requests by public authorities, to enforce our terms, or to protect our rights, users, or the public.
- Business transfers — if we are involved in a merger, acquisition, or asset sale, personal data may be transferred; we will notify you and any successor will remain bound by this Policy.
Sub-Processors #
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel | Frontend / website hosting | Global edge (US-based) |
| Oracle Cloud Infrastructure | Backend, database, workers, LLM gateway | Mumbai, India |
| Polar.sh | Payments (merchant of record), for future paid plans | US/EU |
| Resend | Transactional & notification email delivery | US |
| Sign-in (OAuth) | US |
Notification content is also transmitted to the channels you connect (email via Resend, Slack, Discord, Telegram) solely to deliver your alerts.
7. International Data Transfers #
Our infrastructure is primarily located in India (Mumbai), and some providers listed above are located in the United States or the EU. If you access the Service from outside these regions, your data will be transferred to and processed in them, where data protection laws may differ from those in your jurisdiction.
Where required, we rely on appropriate safeguards for such transfers, such as the European Commission's Standard Contractual Clauses or an adequacy decision, and we take reasonable steps to ensure your data is treated securely.
8. Data Retention #
We retain personal data only for as long as necessary for the purposes described in this Policy:
- Account and configuration data — for as long as your account is active.
- Monitored page snapshots and diffs — for the retention window applicable to your plan, after which they are deleted or aggregated.
- AI provider keys — until you remove them or delete your account.
- Billing records — for as long as required to meet tax, accounting, and legal obligations.
- Analytics and usage data — for a limited period for analysis and security.
When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain it to comply with legal obligations, resolve disputes, or enforce our agreements.
9. Security #
We take reasonable technical and organizational measures to protect your personal data, including encryption of AI provider keys, hashing of passwords, access controls, and secure hosting. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your Rights #
Depending on where you live, you have some or all of the following rights. To exercise them, contact us using the details in Contact & Grievances. We will verify your identity before acting and respond within the timeframes required by law. You will not be discriminated against for exercising your rights.
10.1 GDPR (EU / UK) #
- Access — obtain a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion ("right to be forgotten").
- Restriction — limit how we process your data.
- Portability — receive your data in a portable format.
- Object — object to processing based on legitimate interests or to direct marketing.
- Withdraw consent — at any time, without affecting prior processing.
- Complain — lodge a complaint with your local supervisory authority.
10.2 CCPA / CPRA (California) #
- Know / Access — the categories and specific pieces of personal data we collect, use, and disclose.
- Delete — request deletion of your personal data.
- Correct — request correction of inaccurate personal data.
- Opt out — of the "sale" or "sharing" of personal data. We do not sell or share your personal data as defined by the CCPA/CPRA.
- Limit — the use of sensitive personal information.
- Non-discrimination — for exercising your rights.
10.3 DPDP Act (India) #
- Access — a summary of the personal data we process and processing activities.
- Correction & completion — of your personal data.
- Erasure — of personal data no longer required.
- Grievance redressal — through the contact below.
- Nominate — another individual to exercise your rights in the event of death or incapacity.
11. Children's Privacy #
The Service is not directed to children. We do not knowingly collect personal data from children under the age of 16 (or the minimum age required in your jurisdiction, including the higher thresholds under the DPDP Act). If you believe a child has provided us personal data, please contact us and we will delete it.
12. Contact & Grievances #
If you have questions, requests, or complaints about this Privacy Policy or your personal data, contact us:
- Email: support@watchthat.site
- Operator: Samya Brata Maji
- Grievance / data protection contact (DPDP Act): Samya Brata Maji, support@watchthat.site
We will acknowledge and address grievances within the timeframes required by applicable law.
13. Changes to This Policy #
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above and, for material changes, provide a more prominent notice (such as email or an in-app notice). Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
