PRIVACY
What we collect, which is almost nothing.
This describes what the service actually does, not what a template says it might do. Last updated 2026-09-06.
THE SHORT VERSION
- No cookies. None at all, so there is no consent banner and nothing stored in your browser.
- The metadata you check is not kept. It is fetched, parsed in memory, shown to you, and gone.
- One thing is stored: your email, and only if you type it into the waitlist form.
- No accounts, no profiles, no advertising. We do not sell or share personal information, in the CCPA sense or any other.
Who is responsible
[YOUR LEGAL NAME OR COMPANY], [STREET, CITY, POSTCODE, SLOVAKIA], [IČO / COMPANY NUMBER, once registered], is the data controller. For anything on this page, write toprivacy@notafter.dev.
The free checker
You give it a URL or paste a document. We fetch it, decode the certificates and render the result. That is the whole lifecycle: nothing from a check is written to a database, and the URL you submitted is not retained.
We only fetch publicly published SAML metadata and OpenID discovery documents, over http or https on ports 80 and 443, and we refuse any address that resolves inside a private network. We never send credentials, and we have none to send.
The waitlist
| What | Your email address, which page you signed up from, and the time. |
| Why | To email you once monitoring opens. Nothing else. |
| Legal basis | Your consent, given by submitting the form (GDPR Art. 6(1)(a)). |
| How long | Until we have contacted you about launch, until you ask us to delete it, or 24 months — whichever comes first. |
| Who sees it | Us, plus the database and email providers listed below. |
Ask us to delete it at any time and we will, without asking why. Withdrawing consent does not affect anything done before you withdrew it.
Analytics
We count how the checker is used, with a cookieless analytics service. No identifier is stored on your device and visitors are not tracked between sessions or across sites. Each event carries a fixed, whitelisted set of values and nothing else:
- — that a check finished, whether it was SAML or OIDC, and whether the result was healthy or not
- — that a check failed
- — that someone joined the waitlist, and roughly which page from
The URL you checked, the document, its certificates, your email address and any error text are never included. Query strings, URL fragments and the referring page are stripped before an event is sent. If your browser sends a Do Not Track signal, no analytics are loaded at all.
Legal basis: our legitimate interest in knowing whether the tool is used (GDPR Art. 6(1)(f)). Because the data is aggregate and cookieless, this needs no consent banner.
Server logs
Our host records ordinary web server logs, including IP addresses, for delivering the site, spotting abuse and debugging. Retention is controlled by the host, not by us, so we do not state a period we cannot keep. Your IP is also held in memory for about a minute for rate limiting, and is not written anywhere.
Legal basis: legitimate interest in operating and defending the service (GDPR Art. 6(1)(f)).
Who else processes this
| Provider | What for | Where |
|---|---|---|
| Vercel | Hosting and request logs | United States, served from the EU region |
| Supabase | The waitlist database | European Union (Frankfurt) |
| Resend | Sends us the notification when you join the waitlist | United States |
| Umami Cloud | Aggregate, cookieless analytics | See umami.is for its current hosting region |
Where a provider is outside the EEA, transfers rely on the European Commission’s Standard Contractual Clauses under that provider’s data processing agreement.
Your rights
Under the GDPR and UK GDPR you can ask for a copy of your data, correct it, have it deleted, restrict or object to how it is used, and receive it in a portable form. In practice we hold one thing about you — an email address you typed in — so most requests are answered in a sentence.
Write to privacy@notafter.dev. We answer within 30 days. If you are not satisfied you can complain to your local supervisory authority; in Slovakia that is the Úrad na ochranu osobných údajov Slovenskej republiky.
Children
This is a tool for people running SSO integrations at work. It is not directed at children.
Changes
If what we collect changes, this page changes with it and the date at the top moves. Material changes affecting anyone on the waitlist will be emailed rather than quietly published.