Privacy Policy

Last updated: June 2026

What we collect

MrCron collects your email address when you sign in via magic link. We store the projects, checks, and integration configurations you create. When integrations are connected, we store encrypted API credentials and periodically fetch metric snapshots from the connected services.

How we use it

Your data is used solely to provide the MrCron service — displaying metrics, evaluating alert rules, and sending alert notifications to your configured channels. We do not sell or share your data with third parties for marketing or analytics.

Integration credentials

API tokens and secrets you provide are encrypted at rest using AES-256-GCM before being stored in our database. They are only decrypted in memory during scheduled sync jobs. We use read-only API scopes wherever the connected service supports them. Disconnecting an integration permanently deletes the stored credentials.

Third-party services

We use Resend to deliver email notifications. Your email address is transmitted to Resend solely to deliver transactional alerts you have configured. We do not use any advertising or tracking pixels in emails.

Data retention

Raw metric snapshots are kept for 7 days. Aggregated rollups are kept longer. Alert firing records are kept for audit purposes. If you delete your account, all associated data including encrypted credentials, projects, checks, and metric history is permanently deleted.

Cookies and local storage

MrCron sets one first-party session cookie (authjs.session-token) to keep you signed in. It is httpOnly, Secure, and SameSite=Lax — it cannot be read by JavaScript and is never shared with third parties. We also store your theme preference (light / dark) in localStorage. No advertising or tracking cookies are used.

Contact

Questions about this policy? Email privacy@mrcron.com.