Legal

Privacy policy

Last updated: September 28, 2026

1. Who we are and what this covers

Checkmate is an open-source, self-hosted monitoring tool built and maintained by Bluewave Labs, based in Canada. This policy explains what personal information we handle, and just as importantly what we don't, across everything that carries the Checkmate name:

  • The Checkmate software you install and run on your own infrastructure
  • The Checkmate mobile app for Android and iOS
  • This website (checkmate.so), including the documentation and the public demo at demo.checkmate.so

The short version: Checkmate is self-hosted software. Your monitoring data lives on servers you control, and we never see it. There is no hosted Checkmate service, no account with us, and no billing relationship.

2. The self-hosted software

When you deploy Checkmate, it runs entirely within your own infrastructure. Everything it stores — monitor configurations, uptime and response-time history, server metrics, incident records, status pages, the accounts of your team members, and the credentials for any notification channels you connect — lives in your own database, on hardware you choose.

  • Checkmate sends no telemetry, usage analytics, or crash reports to Bluewave Labs. There is no phone-home mechanism.
  • We have no access to your deployment, your monitoring data, or the personal data of your team members.
  • If your deployment sends notifications through third-party channels you configure (for example email, Slack, Discord, or webhooks), that traffic flows directly between your server and those services under your own accounts and their privacy policies.

For data-protection purposes, whoever operates a Checkmate deployment is the data controller for the data inside it. If you are a team member of an organization running Checkmate and want your data corrected or deleted, contact the operator of that deployment — we could not help even if asked, because we hold none of it.

3. The mobile app

The Checkmate mobile app is a client for your own Checkmate server. It collects no data for us.

  • Connections: the app talks only to the Checkmate server whose address you enter. It makes no other network connections.
  • Stored on your device: the server address you configure, your sign-in session for that server, and your app preferences. This stays on the device and is removed when you sign out or uninstall the app.
  • What you see in the app — monitors, uptime history, incidents — is fetched from your server and belongs to your deployment, as described in section 2.
  • No third-party SDKs: the app contains no analytics, no crash-reporting service, no advertising, and no tracking of any kind.
  • Notifications: if you enable them, they are generated on your device from your own server's data.

Bluewave Labs receives nothing from the app: no identifiers, no usage data, no diagnostics. App stores (Google Play, the App Store) may show us aggregate install statistics they collect under their own privacy policies.

4. This website

checkmate.so is a static marketing and documentation site. There is no sign-up, no login, and no contact form.

Analytics

We measure traffic with cookieless, aggregate web analytics: page views, referrers, and coarse device and country breakdowns. No cookies are set, no personal identifiers are stored, and visitors are not tracked across sites or over time. We publish these numbers openly on our analytics page.

Hosting logs

Like any website, our hosting infrastructure processes IP addresses and request metadata to serve pages and protect against abuse. These operational logs are kept briefly by our hosting provider and are not used to identify or profile visitors.

Local preferences

A few settings, such as your theme choice on the analytics page, are kept in your browser's local storage. They never leave your browser.

The public demo

demo.checkmate.so is a shared demonstration instance with publicly posted credentials. Anything entered there is visible to other visitors and is wiped periodically. Don't put real personal data, real credentials, or production configuration into the demo.

5. What we never do

  • We do not sell or rent personal information — to anyone, ever.
  • We do not run advertising or share data with ad networks.
  • We do not use tracking cookies or build visitor profiles.
  • We do not send marketing email, because we hold no mailing list.

6. Data we may hold about you

The only personal data Bluewave Labs holds in connection with Checkmate is what you send us directly:

  • Email: if you write to us, we keep the correspondence for as long as it takes to help you, and delete it on request.
  • GitHub and Discord: issues, pull requests, and community messages are hosted by those platforms under their own privacy policies, and are public by their nature.

7. Legal bases and your rights

Where we process the limited data above, we rely on our legitimate interest in operating the project and responding to people who contact us. Depending on where you live — including under the GDPR in the EU/EEA and UK, PIPEDA in Canada, and the CCPA in California — you may have the right to access, correct, export, or delete personal data we hold about you, and to object to its processing. Email us and we'll honour it. You also have the right to complain to your local data-protection authority.

For data held inside a self-hosted Checkmate deployment, direct these requests to the operator of that deployment (see section 2).

8. International transfers

Bluewave Labs is based in Canada, and our website infrastructure may process requests in other countries, including the United States. Given how little the website collects — aggregate analytics and short-lived operational logs — this is the extent of any cross-border processing on our side. Your self-hosted data stays wherever you deploy it.

9. Security

The website is served over HTTPS, and the mobile app connects to your server over the connection you configure — use HTTPS for any server reachable from the internet. Security of a self-hosted deployment is in the operator's hands; the documentation covers recommended practice, and we publish security fixes through our release notes. If you believe you've found a vulnerability, please report it to us at the address below.

10. Children

Checkmate is infrastructure software for a general audience. It is not directed at children, and we do not knowingly collect personal information from anyone under 13.

11. Changes to this policy

If our practices change — for example, if we ever add crash reporting to the mobile app — we will update this page, change the date at the top, and describe what changed in our changelog. Material changes to the app's data practices will also be reflected in its store listings before they take effect.

12. Contact

Bluewave Labs
Email: hello@bluewavelabs.ca

You can also reach the team through our contact page.