Privacy policy
This policy describes which data we collect, why we collect it, with whom we share it and how you exercise your rights. It was written to be read, not just to be complied with.
Subprocessors and international transfer
We process your data with the support of: Supabase (database and authentication), Vercel (application hosting), Contabo (server running the check and alert workers), Stripe (payments and subscriptions), Resend (email delivery) and Cloudflare (DNS, email routing and the signup anti-abuse challenge). The full list, with purpose, region and transfer mechanism, is on the Subprocessors page.
Retention
We keep account, authentication and monitoring data for as long as the account exists. Checks, incidents and alerts are kept for 12 months; audit for 180 days; inbox/outbox/delivery for 90 days; billing for 5 years after the last transaction; primary backups with a 35-day maximum window. Incidents that are still open are not deleted by age, because they describe the current state of the hostname, and nothing is deleted while the account is under a legal hold. Once deletion is requested, data is retained for 30 days before the purge — a safety window against a mistaken request — and erasure proceeds from then on.
Your rights
You may request deletion of your data, and manage your consent, from the dashboard (Settings → Privacy). For access, correction and portability, write to privacidade@cymesh.net. Identity confirmation is performed via your own account login, except for legal exceptions.
LGPD
cymesh is the controller of account, billing and operational data. The legal bases used are documented in the data governance matrix: contract execution for account, monitoring and alerts; legal obligation for billing and fiscal retention; legitimate interest and security for auditing. We do not use your data for marketing in the MVP.