Privacy Policy
What Pinger collects, why, and what you can do about it.
Last updated 14 September 2026
This policy covers pinger.ai, the public tools
on it, and the Pinger application at app.pinger.ai. Pinger is
operated by Ginzamarkets, Inc.
What we collect
When you use the free tools
Nothing is stored. A check runs, the result is returned to your browser, and it is not written to a database or associated with you. Requests are rate limited by IP address, which means an address is held in memory briefly to count requests. That counter expires on its own and is not retained.
When you have an account
- Account details. Your email address, display name, and an identifier from the sign-in system. Passwords are handled by Keycloak and never reach Pinger.
- What you asked us to monitor. The domains you add, and which checks you turned on for each.
- Check results. Status codes, response times, certificate and DNS details, robots.txt contents and similar, along with the changes and incidents derived from them.
- Notification settings. The email addresses, Slack webhooks or HTTP endpoints you want alerts sent to.
- Google Analytics data, only if you connect it. An OAuth token and the metrics for the property you select.
What we do not collect
There are no advertising cookies, no analytics scripts and no third-party trackers on this site. We do not build profiles, and we do not sell or rent personal data to anyone.
Why we hold it
To run the service you asked for: checking your sites, working out when something changed, and telling you about it. Account details identify you and let us send operational email. Check history exists so that a change can be compared against what came before, which is the entire point of a monitor.
Who else sees it
A short list of providers process data on our behalf, each for a specific purpose. They are named individually on the subprocessors page, along with what each one touches. We do not share personal data with anyone else except where the law requires it.
How long we keep it
- Check results are kept as history for as long as the account is open, since comparing against the past is what makes a change detectable.
- Accounts and sites are deactivated rather than deleted when you stop using them, so history stays intact and can be restored.
- Full deletion is available on request, and that means deletion rather than deactivation.
Security
- Everything is served over TLS.
- Google OAuth tokens are encrypted at rest with application-level encryption, separately from database encryption.
- Secrets are injected from a managed secret store at deploy time and are never committed to source control.
- Database and internal services are not exposed to the public internet.
Your choices
You can ask us to show you what we hold, correct it, export it, or delete it. You can disconnect a Google account at any time from account settings, which revokes our token immediately. You can turn off any individual monitor without losing its history, or close the account entirely.
Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA, including the right to object to processing and the right to complain to a supervisory authority. We will honour those requests regardless of where you are.
Children
Pinger is a tool for people running websites and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
If this policy changes in a way that materially affects you, we will say so on this page and, for account holders, by email. The date at the top always reflects the current version.
Contact
Write to [email protected] for anything in this policy, including access and deletion requests.