Who we are
Corehost Pulse is a free uptime-monitoring service operated by Corehost (corehost.io). Contact us at support@corehost.io.
What we collect
- Account data. Your email address and a hashed password (managed by AWS Cognito). We never see your plaintext password.
- Monitor configuration. The targets you ask us to check (URLs, hostnames, ports, DNS records), intervals, regions, keywords, and alert settings. This is data you enter.
- Check results. Status and latency measurements our probes record for your monitors.
- Alert channel config. The webhook URLs and tokens you add for Discord, Slack, email, and the rest. Secrets are stored encrypted and shown redacted in the UI.
- Push device tokens (if you turn on push notifications). An opaque push token to deliver notifications. No device identifiers beyond that token.
- Operational logs. Request metadata and error logs (retained roughly 14 days) to run the service. Probe source IPs are recorded for rate limiting on public tools.
What we do NOT do
- No advertising, no ad trackers, no selling or sharing of personal data.
- One analytics tool, nothing else: Google Analytics for page views (see Analytics below). No ad trackers ride along with it.
- We do not read the content of the sites you monitor beyond the assertion you configure (a status code, a keyword, a DNS answer, a TLS expiry).
Analytics
We use Google Analytics 4 (measurement ID G-DC703RH7TC) to understand which pages matter: page views and basic aggregate context such as browser, rough region, and referrer. We do not use it for advertising, do not connect it to your account, and do not pass data to anyone beyond Google's processing of it. How Google handles that data is covered by the Google Privacy Policy.
To opt out, use Google's browser opt-out add-on or any standard content blocker; the site works identically without it.
How we use it
To run the monitoring you asked for: schedule checks, store results and history, evaluate alert conditions, and deliver alerts to the channels and devices you configured. Email is used for account verification, password reset, and alerts you opt into.
Public tools
The looking glass and MTR/traceroute tools run from our network against a public host you type in. We rate-limit by source IP and do not associate those one-off requests with your account unless you are signed in.
Sub-processors
- Amazon Web Services (compute, database, email via SES, auth via Cognito), region ap-southeast-2 primary.
- SpeedyPage (the VPS provider hosting the Pulse probe network).
- netcup (Germany, EU), the VPS provider hosting
ch1.corehost.io. That machine holds the long-term check history database, and it is also the edge that terminates TLS and proxies traffic for status pages on a customer's own domain, so visitors to those pages connect to it first. - Let's Encrypt issues the certificate for a status page on your own domain; the hostname you connect is sent to them and appears in public certificate transparency logs.
- Your browser vendor's Web Push service (Google, Mozilla or Apple, depending on the browser) carries the notification to your device, only if you enable push.
- Your chosen alert channel providers (Discord, Slack, PagerDuty, and so on) receive the alert content you direct to them.
Data retention and deletion
Check history rolls up and ages out over time. Account data persists while your account is active. There is no delete button in the panel yet: email support@corehost.io from the address on the account and we remove your account, its monitors and its history. Operational logs age out on their own retention.
Security
Passwords hashed by Cognito; optional TOTP MFA. Data encrypted in transit (TLS) and at rest (AWS-managed encryption on DynamoDB and S3). Alert-channel secrets encrypted; API tokens stored only as SHA-256 hashes.
Your rights
You can read back and correct your monitors, channels and status pages yourself in the panel, over the REST API, or with the pulsectl CLI. For a full copy of your data, or to delete the account, email support@corehost.io from the address on the account and we do it by hand; there is no one-click export or delete in the panel yet. If you are in a jurisdiction with specific data rights (GDPR, CCPA, Australian Privacy Act), those requests are honoured.
Children
Not directed at children under 16; we do not knowingly collect their data.
Changes
We will update this page and the "last updated" date for material changes.