Last updated: September 28, 2026
Checkmate is an open-source, self-hosted monitoring tool built and maintained by Bluewave Labs, based in Canada. This policy explains what personal information we handle, and just as importantly what we don't, across everything that carries the Checkmate name:
The short version: Checkmate is self-hosted software. Your monitoring data lives on servers you control, and we never see it. There is no hosted Checkmate service, no account with us, and no billing relationship.
When you deploy Checkmate, it runs entirely within your own infrastructure. Everything it stores — monitor configurations, uptime and response-time history, server metrics, incident records, status pages, the accounts of your team members, and the credentials for any notification channels you connect — lives in your own database, on hardware you choose.
For data-protection purposes, whoever operates a Checkmate deployment is the data controller for the data inside it. If you are a team member of an organization running Checkmate and want your data corrected or deleted, contact the operator of that deployment — we could not help even if asked, because we hold none of it.
The Checkmate mobile app is a client for your own Checkmate server. It collects no data for us.
Bluewave Labs receives nothing from the app: no identifiers, no usage data, no diagnostics. App stores (Google Play, the App Store) may show us aggregate install statistics they collect under their own privacy policies.
checkmate.so is a static marketing and documentation site. There is no sign-up, no login, and no contact form.
We measure traffic with cookieless, aggregate web analytics: page views, referrers, and coarse device and country breakdowns. No cookies are set, no personal identifiers are stored, and visitors are not tracked across sites or over time. We publish these numbers openly on our analytics page.
Like any website, our hosting infrastructure processes IP addresses and request metadata to serve pages and protect against abuse. These operational logs are kept briefly by our hosting provider and are not used to identify or profile visitors.
A few settings, such as your theme choice on the analytics page, are kept in your browser's local storage. They never leave your browser.
demo.checkmate.so is a shared demonstration instance with publicly posted credentials. Anything entered there is visible to other visitors and is wiped periodically. Don't put real personal data, real credentials, or production configuration into the demo.
The only personal data Bluewave Labs holds in connection with Checkmate is what you send us directly:
Where we process the limited data above, we rely on our legitimate interest in operating the project and responding to people who contact us. Depending on where you live — including under the GDPR in the EU/EEA and UK, PIPEDA in Canada, and the CCPA in California — you may have the right to access, correct, export, or delete personal data we hold about you, and to object to its processing. Email us and we'll honour it. You also have the right to complain to your local data-protection authority.
For data held inside a self-hosted Checkmate deployment, direct these requests to the operator of that deployment (see section 2).
Bluewave Labs is based in Canada, and our website infrastructure may process requests in other countries, including the United States. Given how little the website collects — aggregate analytics and short-lived operational logs — this is the extent of any cross-border processing on our side. Your self-hosted data stays wherever you deploy it.
The website is served over HTTPS, and the mobile app connects to your server over the connection you configure — use HTTPS for any server reachable from the internet. Security of a self-hosted deployment is in the operator's hands; the documentation covers recommended practice, and we publish security fixes through our release notes. If you believe you've found a vulnerability, please report it to us at the address below.
Checkmate is infrastructure software for a general audience. It is not directed at children, and we do not knowingly collect personal information from anyone under 13.
If our practices change — for example, if we ever add crash reporting to the mobile app — we will update this page, change the date at the top, and describe what changed in our changelog. Material changes to the app's data practices will also be reflected in its store listings before they take effect.
Bluewave Labs
Email: hello@bluewavelabs.ca
You can also reach the team through our contact page.