Privacy

What HookPulse keeps about the people who use it, for how long, which infrastructure it shares, and how to request access or deletion.

Who processes the data

HookPulse is run by the same house as the other products listed in the footer. Requests about personal data go to contato@hookpulse.net and are answered by e-mail.

What this product keeps

  • Each monitor stores its name, interval, the alert e-mail and webhook URL you set, and its check-in link.
  • Each ping stores the method, the recorded status, latency, content type, a 500-character preview of the body with tokens and secrets redacted, and four request headers: user-agent, content-type, the sender's IP address (cf-connecting-ip) and x-request-id.
  • Without an account, a guest token in your browser owns the monitors; with an e-mail sign-in, the e-mail, the sign-in codes (short-lived, hashed) and the session.
  • A miss sends an e-mail (Amazon SES) to the alert address or a POST to the alert URL.
  • Pay-per-call payments (x402) settle on the Base network, which is public by design; here we keep the transaction reference and the amount for reconciliation and accounting.
  • Prepaid credit: the token is stored only as a SHA-256 hash with its balance and movements; whoever holds the token holds the credit, and it cannot be recovered by e-mail.
  • Contact: your message, the e-mail you give and the reply go through Amazon SES to the product mailbox.

For how long

  • Each monitor keeps only its last ~100 pings; older ones are pruned as new ones arrive. Deleting a monitor deletes its pings.
  • Sign-in codes expire within minutes.
  • Per-network rate-limit counters (guest, contact, sign-in code) expire on their own within minutes or hours.
  • Payment and credit records stay as long as accounting requires.

Infrastructure and third parties

  • Cloudflare hosts the Worker, the database (D1), files (R2) and DNS; traffic passes through its edge, which keeps operational logs for a limited time and cookieless Web Analytics.
  • Cloudflare Turnstile confirms a form was sent by a person; it does not identify who.
  • Amazon Web Services (SES) sends transactional e-mail on behalf of the product.
  • jsDelivr serves interface libraries (Bootstrap) from its CDN.
  • Google Analytics 4 measures pages and events only after the first interaction (tap, click or key), with ad storage denied and no sale or sharing for advertising.
  • PayAI (x402 facilitator) verifies and settles payments on the Base network; the paying wallet is yours, and its address is public on-chain.

Cookies and browser storage

  • When you sign in with e-mail, the session lives in a cookie; without an account, a guest token stays in your browser and identifies what you created.
  • Screen preferences (theme, filters) stay in the browser's local storage and never leave it.
  • There is no advertising cookie and no cross-site tracking.

IP address

To limit abuse, the IP address goes into a hash with a secret salt and the country comes from the Cloudflare edge; the raw IP is not stored, except where this page says otherwise.

Your rights

You can request access, correction or deletion of what exists about you by writing to contato@hookpulse.net. We answer within the terms of the Brazilian data protection law (LGPD) and, where it applies, the GDPR. Data from public sources (official registries) stays at the source; only the copy here is removed.

Last updated: 5 September 2026.