Privacy Policy — outage.me
Operator: Smart Signals LLC, a Wyoming limited liability company. Contact: privacy@outage.me. Effective: 3 October 2026.
outage.me shows the live status of online services, using each provider's own public status page. We collect as little as we can. This policy lists everything we do collect.
Public site (outage.me, outage.me/br)
- No analytics, no ad trackers, no tracking cookies. We don't record your IP address or browser details in any database.
- Usage counts. When you view a page, click a service card or open search, we record which page and card it was (for example "github card clicked"), a timestamp and the referring website's domain. We don't record who you are, your IP address or any text you type. These records are deleted after 30 days.
- Search box. If you type something that looks like a web address, it's sent to our server to check whether that service has an official status page we could track. It isn't linked to you.
- Speed test (optional). The test runs against Cloudflare (speed.cloudflare.com). We only receive results if you tick the consent box. Then we store your download and upload speed, latency, jitter, and your internet provider's network number and name. No IP address or location. Results are deleted after 30 days and appear only as per-provider averages.
- User reports (optional, where a service page offers them). If you click a problem on a service's page (for example "Mobile data"), we count it: the service, the problem type, a 15-minute time slot, your approximate location (country, state and city, as estimated by our content-delivery network from your connection; no GPS and no browser location request) and your internet provider's network number. We don't store your IP address or browser details with any report. To count each person once per service every 30 minutes, we keep a one-way code derived from your IP address and browser; its key changes every day, and the code is deleted after 30 minutes. Report counts are deleted after 35 days. We publish only totals: a place is shown only once it has at least 5 reports, and network numbers are never shown. Legal basis: our legitimate interest in showing whether a service is failing for other people too (GDPR Art. 6(1)(f); LGPD Art. 7, IX).
- Email alerts (optional). We store your email address and the services you picked, and send alerts from alerts@outage.me through Amazon SES. Nothing is sent until you click the link in our confirmation email; if you never do, your address is deleted after 7 days. Every alert has a one-click unsubscribe link, and unsubscribing deletes your address. We also keep a one-way hash of your email for 24 hours, to stop repeat sign-ups. Subscriptions made before 3 October 2026 were moved from Amazon SNS to this list.
- Stored in your browser, never sent to us: the services you pinned, the cards you dismissed, and your last-used tab.
Pro app (app.outage.me)
- Account. Sign-in uses Amazon Cognito, with email, Google or Apple. We keep your email address. From Google or Apple we receive only your email and whether it's verified; if you choose Apple's "Hide My Email", we get the relay address.
- Your settings. Your watchlist (providers, regions, network numbers, vendors, alert threshold) and any alert channels you add (email, a Slack or webhook URL, a PagerDuty routing key). We use these only to send the alerts you asked for, to the destinations you configured. An email channel gets the same confirmation email and one-click unsubscribe as email alerts above, and removing the channel deletes the address from our alert list.
- Ask. Your questions go to Amazon Bedrock (AWS) to generate answers. Each question and answer is stored for 1 hour, only so follow-up questions work, then deleted automatically. A daily question counter is kept for 2 days.
- API keys. We store only a one-way hash of each key, its label, its last 4 characters, and when it was created and last used.
- Usage counts. Page views, tab switches and settings changes are recorded with your account ID, for 30 days. Your question text is never recorded.
- Cookies. Sign-in cookies (strictly necessary) last 12 hours:
CloudFront-Policy,CloudFront-Signature,CloudFront-Key-Pair-Id,tarantula_principalandtarantula_tier. A 10-minute cookie (tarantula_oauth_state) protects the sign-in step, and a 10-minute cookie (__Host-oauth_csrf) protects the "Allow" button when you connect an app. - Connected apps (MCP). If you connect an AI app (for example Claude or ChatGPT) to your account, we store which app you approved, when, and when it last used access. The app receives tokens that are stored only as one-way hashes on our side. They expire (access after 1 hour; renewal after 30 days, or after 7 days unused). Disconnect any app, or all of them, under Connected apps in the Pro app. Questions an app sends through the
answertool are handled exactly like Ask above. - Contributing outage observations (optional, off by default). If your organization turns on Contribute outage observations, your software (an AI app, a hook, or an OpenTelemetry collector) can tell us that calls to a public service failed. We store your organization's account ID, the public hostname (only hosts on our published list), the type of failure (for example a timeout or a 5xx error), a 15-minute time slot, call and failure counts, and, if your software sends it, the cloud region it runs in. We never receive or store URLs, paths, request or response content, error messages, or your own internal hostnames. We use this to confirm outages across organizations, to credit your organization with extra questions when a report is confirmed, and to keep a per-organization trust score. Records are deleted after 35 days at most. We publish only totals across at least 3 organizations, never which organizations reported, and a region only once at least 5 organizations reported from it. Turn it off at any time on the Keys page. Legal basis: our legitimate interest in detecting outages, and the contribution you choose to make (GDPR Art. 6(1)(f); LGPD Art. 7, IX).
Third parties
- Amazon Web Services: hosting, sign-in, email delivery and the AI model.
- Google and Apple: only if you sign in with them.
- Cloudflare: the speed test, only if you run it.
- Google Fonts: the pages load fonts from Google, which receives your IP address the way any web request does.
- Slack, PagerDuty or your own webhook: only if you configure them as alert channels.
- We don't sell or share personal data for advertising.
Security and server logs
Our edge firewall rate-limits requests by IP address, and AWS keeps a small sample of blocked requests. Our servers log errors, but not IP addresses, email addresses or anything you type. Server logs are deleted after 30 days.
Your rights
You can ask for access to your data, a correction, or deletion of your account and data by writing to privacy@outage.me. We answer within 30 days. If you are in the EU, the UK or Brazil, you also have the rights your local law gives you (GDPR, UK GDPR, LGPD), including the right to complain to your data-protection authority; send those requests to the same address.