Legal
Privacy Policy
Last updated: 2026-07-09
LastRun is operated by Eastbase Studio. This policy explains what we collect, why, who processes it for us, and the choices you have. We keep data collection to what LastRun needs to work, and we don't sell personal data. Questions or requests: support@eastbase.studio.
01Who we are & scope
Eastbase Studio is the operator of LastRun and the controller of the personal data described here. This policy covers the LastRun website, dashboard, and ping API. Third-party services you connect (like Slack or your email provider) handle data under their own policies.
02Account, organization & team data
When you sign up we store your name, email, and a password hash (or, if you use social sign-in, the basic profile your provider returns). Each account has a workspace (organization); if you invite teammates we store their membership, role, and invitation status. We use this to run your account, apply permissions, and contact you about the service.
03Monitor configuration
We store the monitors you create — names, schedules, timezones, grace periods, maximum runtimes, ping and badge keys, alert-channel attachments, and status-page settings. This is the configuration LastRun needs to know what to watch and how to alert you.
04Ping & run data
Each time your job pings us we record the event: the monitor it's for, the type (start, success, or fail), timestamps, computed durations, and the resulting run and incident history. This is the core record of whether your jobs ran.
05Request body & run output
If your job sends a request body with a ping, we truncate it to about 10KB and store it as run output so you can review it. Because this is free-form text you send us, please keep it non-sensitive: do not include secrets, credentials, API keys, access tokens, database URLs, raw customer data, sensitive personal data, payment card data, confidential business data, or full logs or stack traces that may contain environment variables. Send a short summary or a redacted message instead. We can't filter this content for you — you control what's in it.
06Source IP & request metadata
Like any web service, our servers receive technical metadata with requests — including the source IP address, timestamps, and basic request details. We use this to ingest pings, operate the service, apply rate limits, and protect against abuse. We don't use it to build advertising profiles.
07Alert channels & integrations
To deliver alerts we store the channel details you provide — alert email addresses, and the webhook URLs or integration configuration for Slack, Discord, Telegram, or a custom webhook. When an alert fires, a copy of that alert (monitor name, status, and any captured output) is sent to the provider you connected so it can notify you. Those providers process the message under their own terms.
08Public status pages & badges
If you publish a status page or badge, the information on it is intentionally public: it can be viewed without signing in and may be cached, indexed by search engines, copied, or screenshotted by third parties. Only publish what you're comfortable making public, and avoid confidential details in monitor names or page titles.
10Legal bases
Where data-protection law (such as the GDPR) applies, we rely on:
- Contract — to create your account and provide the monitoring, alerts, and features you sign up for.
- Legitimate interests — to operate, secure, and improve the service (including error diagnostics, abuse prevention, and rate limiting), balanced against your rights.
- Consent — for optional analytics cookies and similar storage, which you can give or withdraw at any time.
- Legal obligation — to keep billing, tax, and accounting records where the law requires it.
11Processors & sub-processors
We share data only with the service providers that help us run LastRun, under agreements that limit them to that purpose:
- Vercel — website and dashboard hosting, plus Vercel Analytics (analytics — only after consent).
- Railway — hosting for the monitoring engine that ingests pings and sends alerts.
- Neon (US-East) — the primary database.
- Better Auth — authentication; Google or GitHub sign-in only if you choose to use it (optional).
- Lemon Squeezy — payments, as merchant of record; we never receive your card details.
- Resend — sending alert and account emails.
- Slack, Discord, Telegram, or a custom webhook — only when you connect one as an alert channel, and only to deliver your alerts.
- PostHog — product analytics (only after consent, optional).
- Sentry — error and performance monitoring.
12International processing
Eastbase Studio is a small studio and our infrastructure is primarily hosted in the United States (for example, our database region is US-East), and some processors above operate in the US and elsewhere. If you're outside those regions, your data may be transferred and processed there. We use reputable providers and rely on their data-transfer safeguards where required.
13Retention & deletion
Ping and run history is retained by plan — 7 days on Free, 90 days on Pro — and then deleted automatically. Deleting a monitor deletes its pings and incidents immediately.
When you delete your account, we aim to delete or anonymize your workspace data from active systems within about 30 days. Residual copies may persist in encrypted backups, logs, and diagnostics for up to about 90 days before they roll off. We may keep limited billing, tax, and accounting records longer where the law requires it.
14Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can manage or delete your account and data from Settings, or email support@eastbase.studio and we'll help. You can also withdraw analytics consent any time from Cookie preferences in the footer.
15Security
Authentication is handled by Better Auth; passwords are stored hashed, never in plain text. Data is encrypted in transit, access is limited to what's needed to run the service, and the ping and API tokens that protect your monitors are treated as credentials. No system is perfectly secure, so please keep your own credentials and ping tokens safe (see the Terms).
16Children
LastRun is a developer tool for adults and isn't directed to children. We don't knowingly collect personal data from children; if you believe a child has given us data, contact us and we'll remove it.
17Changes
We may update this policy as the product evolves. If we make a material change, we'll update the date above and, where appropriate, notify account holders by email.
18Contact
For any privacy question or request, email support@eastbase.studio. LastRun is operated by Eastbase Studio.