Legal
Privacy policy
What AxoWatch collects when you use the site, the app and the Chrome extension, why, who else sees it, and how long we keep it.
AxoWatch watches websites for their owners: it checks that pages answer, measures how fast they load, replays key paths such as sign-up or checkout in a real browser, and collects errors from the site's own application. This policy explains what data that takes and what we do with it. It covers the website at axowatch.com, the AxoWatch app and the AxoWatch Chrome extension.
AxoWatch is run by Sybrik Development, a business in Ontario, Canada ("we", "us"). We are responsible for the personal data described here. Using AxoWatch is also governed by our terms of service.
If something here is unclear, write to privacy@axowatch.com.
The short version
- We collect what the service needs to work. Data from your account and your sites is never used for advertising.
- Analytics and advertising cookies on our website are switched on only if you press Accept in the cookie banner. Until then they are not loaded at all, and you can change your mind at any time under Cookie settings at the bottom of the page.
- We do not sell data, and we share it only with the services listed below that help us run AxoWatch.
- The Chrome extension records only when you press Record, only on the site you allow, and sends the result only to your AxoWatch account.
- You can ask us for a copy of your data or to delete it at any time.
What we collect
Your account
When an account is created we store your name, email address and password. The password is stored only as a salted scrypt hash — we cannot read it. If you sign in with Google, we keep only your name and email address from your Google account — not your photo or contacts, and we get no access to your Google data.
We also store your account settings: time zone, language, the sites (projects) you add and how you want to be alerted.
The sites you monitor
To monitor a site we store its address and the checks you set up. Running those checks produces data that we store in your account:
- Uptime checks: whether the page answered, the status code, how long it took and, when it failed, why.
- Speed checks: the score and measurements of each run, and the full report of the measurement.
- User flows: the steps of the flow, and for each run its result, a screenshot after every step, the page address and title, short pieces of text that appeared on the page, and the error if a step failed.
These screenshots and texts are of your own site, as a visitor would see it. If your flow signs in to the site, the page after sign-in may show data of that test account — which is why we ask you to use a test account for flows.
Errors from your application
If you connect error tracking, your application sends us error reports: the error message, the stack trace, the page or request where it happened, and the steps that led to it. Before a report is saved to your project we remove passwords, tokens, cookies, session identifiers and anything that looks like a card number. Until then the report waits in a processing queue for at most 24 hours. If your application identifies the signed-in user in the report (for example with an id or email), that identification is stored as sent.
To count how many people an error affected without keeping their addresses, we turn the visitor's IP address and browser into a one-way code that changes every day. The IP address itself is not stored.
The people whose errors appear in these reports are visitors of your site, not of ours. For this data you decide what is sent, and we process it on your behalf — see "Data about your visitors" below.
The Chrome extension
The extension records a path through your site so AxoWatch can replay it. What it does:
- It does nothing until you connect it to your AxoWatch account with a one-time code from the app. After that it keeps a connection token, your name, the account name and the project you picked, in the extension's storage on your computer. On our side we keep a fingerprint (hash) of that token, the browser's name (for example "Chrome on macOS") and when it was last used.
- It records only after you press Record, and only on the site you allow in Chrome's permission dialog. It does not read other tabs or other sites, and it stops when you press Stop or close the tab.
- While recording it notes what you click, point at and type, and where: the page address, which element you used (its tag, label, placeholder or a short piece of its text) and the value you typed into a field, cut to 80 characters. Values of password fields are not recorded — you add those yourself in the app. If a site turns a password field into plain text (a "show password" button) and does not mark it as a password field, what you type there is recorded like any other text — one more reason to use a test password. The extension does not take screenshots and does not record anything you do not do on that page.
- The recording stays in the browser's memory until you press Stop. It is not written to disk and is cleared when the browser closes.
- When you press Stop, the extension turns the recording into the steps of a flow on your computer and sends those steps to your AxoWatch account. The raw recording is not sent. If sending fails, you can save the recording as a file instead.
Because typed values become part of the flow, walk the flow with test data — a test account, a test email, a test card — not with real personal or payment details.
Visitors of our website
Cookies our website and app need to work are always on:
| Cookie | What it is for | How long |
|---|---|---|
aat_session | Keeps you signed in | 30 days |
aat_google_state, aat_google_next, aat_google_signup | Protect and complete sign-in with Google | 10 minutes |
aat_slack_state | Protects connecting Slack | 10 minutes |
aat_project | Remembers which of your sites you are looking at | 1 year |
aat_locale, aat_theme, aat_sidebar, aat_speed_device | Remember your language, theme and layout choices | 1 year |
aat_consent | Remembers whether you accepted analytics and advertising cookies | 1 year |
When AxoWatch staff open an account to help its owner, aat_admin_return brings them back to their own account; it lasts as long as that session.
Analytics and advertising — only if you agree
When you first visit our website, a banner asks whether you accept analytics and advertising cookies. Until you press Accept, the scripts below are not loaded and these cookies are not set. If you press Reject, or your browser sends a Global Privacy Control signal, they stay off. You can change your choice at any time under Cookie settings at the bottom of every page.
If you accept, we use:
- Google Analytics to understand how people find and use our website: which pages they open, where they came from, their device, browser and approximate location (country and city, worked out from the IP address), and steps such as signing up or buying a plan.
- Meta Pixel (Facebook and Instagram) to measure which of our ads lead to sign-ups and purchases, and to show our ads to people who visited our website. Meta receives the pages you open, your browser details, your IP address and the same steps; if you are signed in to Facebook or Instagram, Meta can link this to your account there.
When you sign up or buy a plan, we tell these services that it happened, and for a purchase, the plan and the amount. We do not send them your name, email address or anything from the sites you monitor.
| Cookie | Set by | What it is for | How long |
|---|---|---|---|
_ga, _ga_* | Google Analytics | Tells visits of one browser apart | 2 years |
_fbp, _fbc | Meta | Links visits and ad clicks to sign-ups and purchases | 90 days |
How Google and Meta use this data is described in the Google privacy policy and the Meta privacy policy.
How we use it
We use the data above to provide AxoWatch: to run your checks and flows, show you the results, alert you when something breaks, help you fix it, take payments, keep your account secure, and answer you when you write to us. If you accepted analytics and advertising cookies, we also use what they collect to improve our website and to measure and show our ads.
We do not use data from your account or your sites for advertising, we do not sell personal information, we do not build profiles of your visitors, and we do not use it to decide anyone's creditworthiness or for lending. People at AxoWatch do not read your data unless you ask us to help, it is needed for security, or the law requires it.
Who else sees it
We use a small number of services to run AxoWatch. Each gets only what its job needs:
| Service | What it does for us | What it receives |
|---|---|---|
| DigitalOcean | Hosts our servers and database | Everything stored in AxoWatch, encrypted in transit |
| Cloudflare | Delivers our website and protects it from attacks | Every request to AxoWatch, including your IP address and browser details |
| Stripe | Takes payments for paid plans | Your name, email address, billing address and card details — the card goes to Stripe directly, we never see its full number |
| Resend | Delivers our emails | Your email address and the text of the email: confirmations, alerts, invitations |
| Anthropic (Claude) | AI that builds, explains and repairs flows and prepares fix tasks | Names and steps of your flows — including the values entered in them — page addresses and short texts from your pages, messages you write in the flow chat and, when a broken step is being repaired, screenshots of your page. Under Anthropic's commercial terms this data is not used to train its models. |
| Telegram, Slack, Microsoft Teams | Deliver alerts, if you connect them | The alert text and the chat or channel you chose |
| Sign-in with Google, if you use it; Google Analytics, if you accept cookies | Your sign-in request; what Google Analytics collects (see above) | |
| Meta | Meta Pixel, if you accept cookies | What Meta Pixel collects (see above) |
If you connect an AI agent of your own (for example through our MCP connection), that agent can read the data of your account that you allowed it to — that sharing is your choice, and you can disconnect it in the app.
We may disclose data if the law requires it, and if AxoWatch is ever sold or merged, the data moves with it under this policy.
Some US state laws call letting an advertising service like Meta collect data on our website "sharing" or "targeted advertising". We do this only if you accept advertising cookies, and you can opt out at any time under Cookie settings or with Global Privacy Control.
Where your data is processed
We are in Canada, and the services above store and process data in the United States and other countries. Data processed there is protected by our agreements with these services, but it is subject to the laws of those countries, and their authorities may be able to access it under those laws.
How long we keep it
| Data | Kept for |
|---|---|
| Account, projects and checks | Until you delete them in the app or ask us to delete your account |
| Raw uptime results | 30 days by default — you can choose 7, 90 or 400 days |
| Error reports | 30 days, deleted in weekly batches — so at most 37 |
| Flow screenshots and page texts | The last 5 runs, failed runs of the last 14 days and the last successful run |
| Flow chat | The last 40 messages of each flow |
| Full speed reports | Until you ask us to delete them |
| Recording in the extension | Until you press Stop or close the browser |
| Extension connection | On your computer — until you press Disconnect in the extension or remove it. On our side — until you disconnect that browser in the app |
| Sign-in session | 30 days |
| Payment records and invoices | As long as tax and accounting law requires — in Canada, 6 years |
| Google Analytics data | 14 months |
| Your cookie choice | 1 year, then we ask again |
Daily summaries (uptime per day, speed scores, the list of error groups) are kept while the project exists, so you can see how the site changed over time.
Deleting a check or a project in the app removes it from the app at once. Screenshots and speed reports stored as files with it are removed when you ask us to delete your data.
How we protect it
Connections to AxoWatch are encrypted (HTTPS). Passwords are stored only as salted hashes, and sign-in, extension and API tokens are stored only as hashes, so a copy of our database would not let anyone sign in as you. Access to our servers is limited to the people who run AxoWatch.
No system is perfectly secure. If a breach affects your data, we will tell you without undue delay.
Your choices and rights
- Disconnect the extension at any time. Disconnect in the extension forgets the connection on your computer; to revoke it on our side too, disconnect that browser in the app under Integrations → Chrome extension. Removing the extension from Chrome deletes everything it stored on your computer.
- Delete flows, checks and projects in the app; to have stored screenshots and reports removed too, write to us.
- Change your cookie choice at any time under Cookie settings at the bottom of every page of our website.
- Ask us at privacy@axowatch.com for a copy of your data, to correct it, to delete your account and everything in it, or to object to how we use it. We answer within 30 days.
Canadian privacy law (PIPEDA, and Law 25 in Quebec) gives you these rights. If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada or, in Quebec, to the Commission d'accès à l'information. US state privacy laws, and the laws of the European Union, the United Kingdom and Ukraine, give similar rights to people who live there, including the right to complain to the local authority. We do not treat you differently for using any of these rights.
Data about your visitors
When you use AxoWatch on your site, some of the data we receive is about your site's visitors — mainly in error reports. For that data you are the one who decides what is collected, and we process it only to provide AxoWatch to you. You are responsible for telling your visitors about it in your own privacy policy. If you need a data processing agreement, write to us.
Children
AxoWatch is a tool for businesses and is not meant for children. We do not knowingly collect data from anyone under 16.
Changes to this policy
If we change this policy, we update the date at the top. If a change affects how we use data you have already given us, we will tell you in the app or by email before it takes effect.
Contact
Our privacy officer answers questions, requests and complaints about privacy: privacy@axowatch.com.
Sybrik Development, Ontario, Canada.





I’ll keep an eye on it.
You