Privacy Policy
Last updated: July 19, 2026
This page explains how Kotori (kotori.page) handles personal data.
1. What we collect
We collect the following information as you use the Service:
- At signup: your email address, password (hashed by our authentication provider — we never store or see the plaintext), and display name
- When you sign in with Google: your Google account email address
- When you register a site: the monitored site's URL and display name, and the report recipient's name and email address
- When you subscribe to a paid plan: payment information (your card details are processed directly by Stripe and never touch our servers)
2. How we use it
We use the information we collect only to provide the Service (monitoring, notifications, and generating and sending monthly reports), to bill you, and to contact you about the Service. We never use it for any other purpose, such as selling it to third parties or adding it to advertising lists.
3. Where it's stored / processors
Application data is stored on Cloudflare's services (D1, R2); authentication data is stored on Supabase's auth platform. Payment processing is handled by Stripe, and email delivery by Resend — both receive the information needed to do their jobs. As part of our daily automated checks, we also send your monitored sites' URLs to Google's Safe Browsing API (malware/phishing detection) and PageSpeed Insights API (performance measurement).
4. Analytics
This Site uses Umami, a self-hosted, cookie-free analytics tool, to track aggregate traffic without identifying individual visitors.
5. Retention
We keep your registered information until you delete your account or ask us to delete it.
6. Access and deletion
To request access to, correction of, or deletion of your data, contact us using the details below. You can also delete your own account, and cancel any active subscription, from the dashboard settings page at any time.
7. Contact
Questions about this policy can be sent to [email protected].