How it worksFeaturesPricingBlogFAQ
Sign inStart free trial
How it worksFeaturesPricingBlogFAQSign in
Theme
Start free trial

Privacy Policy

Last updated: 10 August 2026

RotSweep is operated by NEGLETEK, a software company based in Athens, Greece, and the data controller for the personal data described here. Customer data is stored and processed in the European Union, on infrastructure we run. For anything in this policy, contact privacy@rotsweep.com.

What we collect, and why

Account data. When you sign up we store your name and email address. Sign-in itself is handled by our authentication provider, Clerk; we never see or store your password.

Workspace and billing data. For each workspace we store its name, and — where you provide them for invoicing — a legal entity name, VAT ID, billing email address and country. Payments are processed by Stripe; your card details go directly to Stripe and never touch our servers. We keep records of the invoices Stripe issues for your workspace.

Monitoring configuration. The projects you create, the URLs you monitor with their tags and source pages, the pages or sitemaps you ask our scanner to read, and the email addresses of your alert recipients. Recipients do not need an account, so make sure you have their permission before adding them.

Sweep results. For each check of a monitored URL we record its outcome: HTTP status, the redirect chain and final destination, timing, a similarity score, and an extract of the destination page’s visible content (title, headings, main text) that we keep solely to compare future checks against your accepted baseline. This is content from the third-party pages you monitor — see “Content we fetch” below.

Correspondence. If you email us, we keep the correspondence so we can help you.

Technical logs. Our infrastructure keeps standard server logs, which can include IP addresses, used only for security and operations.

What we do not do

This website sets no cookies and runs no third-party advertising trackers or analytics. The only thing it stores in your browser is your theme preference, kept in localStorage on your device. The dashboard uses the session cookies of our authentication provider — essential for signing you in, nothing more. We do not sell personal data.

Legal bases

We process account, workspace and monitoring data to perform our contract with you (GDPR Art. 6(1)(b)); billing records to meet legal obligations such as tax law (Art. 6(1)(c)); and security logs and product safety measures under our legitimate interest in running the service reliably (Art. 6(1)(f)).

Processors we use

We share data only with the processors needed to run the service, under data processing agreements:

  • Clerk — authentication (your sign-in, name and email). Clerk is a US-headquartered provider; transfers are covered by GDPR Chapter V safeguards.
  • Stripe — payment processing, invoicing and VAT handling.
  • Mailgun — transactional email, configured to Mailgun’s EU region.
  • Hetzner — EU data centres (Germany) where our own database and infrastructure run.

Content we fetch from monitored pages

RotSweep’s job is to fetch publicly accessible URLs that our customers configure. Our crawler identifies itself honestly in its user agent as RotSweep by default, paces its requests per domain, and never fetches more than it needs to compare a page against its baseline. We store extracts and fingerprints of the fetched pages for that comparison only; we do not republish them. If you operate a website and have questions about our crawler, contact support@rotsweep.com.

Retention

Account and workspace data is kept while your account or workspace exists. Check history is available to you for your plan’s retention window (30 days on Daily Sweep, 12 months on Deep Sweep, 24 months on Full Sweep). When a trial expires, the workspace becomes read-only and its data is preserved so you can pick up where you left off. When you delete a workspace, permanent deletion is scheduled 30 days out — a grace period against mistakes — after which the workspace’s data is removed. Scanner job records are pruned after 30 days. Invoice records are kept for as long as tax law requires. You can request earlier deletion of your personal data at any time.

Your rights

Under the GDPR you can request access to, correction of, deletion of, or a portable copy of your personal data, restrict or object to processing, and withdraw any consent. Write to privacy@rotsweep.com and we will respond within a month. You also have the right to lodge a complaint with a supervisory authority — for us that is the Hellenic Data Protection Authority in Athens.

Security

All traffic is encrypted in transit. Our systems run on EU infrastructure with access limited to the people who operate the service, and credentials are kept in a managed secrets store. No method of storage is perfectly secure; if we ever become aware of a breach affecting your personal data we will notify you and the supervisory authority as the GDPR requires.

Changes

When this policy changes we will update it here and revise the date at the top. Material changes will be announced to account holders by email. See also our Terms of Service and Data Processing Agreement.

Know what broke. Know what changed.
Built in Athens, hosted in the EU.
Product
How it worksFeaturesPricingBlogFAQ
Company
AboutContactsupport@rotsweep.com
Legal
PrivacyTermsDPA
Created by NEGLETEK — © 2026 · All rights reservedAll prices exclude VAT