Last updated: March 2026
This Privacy Policy explains how postmortem.so ("we", "us", or "our") collects, uses, and protects your personal data when you use our service at postmortem.so.
We are committed to protecting your privacy and complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
postmortem.so is an AI-powered incident monitoring and post-mortem generation service. For the purposes of GDPR, we are the data controller for personal data collected through our service.
Contact: support@postmortem.so
We use your data to:
When an incident is detected, we send check history data to Anthropic's Claude API to generate post-mortem reports. This data includes endpoint paths, status codes, latency values, and timestamps. We do not send personally identifiable information to the Claude API.
Anthropic's privacy policy applies to data processed by their API: anthropic.com/privacy
We share your data only with the following third-party service providers, solely to operate the service:
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Clerk | Authentication | clerk.com/privacy |
| Neon | Database hosting | neon.tech/privacy |
| Vercel | Application hosting | vercel.com/legal/privacy-policy |
| Stripe | Payment processing | stripe.com/privacy |
| Resend | Transactional email | resend.com/privacy |
| Anthropic | AI post-mortem generation | anthropic.com/privacy |
| Upstash | Job scheduling (QStash) | upstash.com/privacy |
We do not sell your personal data to third parties. We do not share your data for advertising purposes.
We only use essential cookies required for authentication and session management (set by Clerk). We do not use advertising or analytics cookies.
If you are located in the European Economic Area, you have the following rights:
To exercise any of these rights, contact us at support@postmortem.so. We will respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority.
We implement appropriate technical and organisational measures to protect your personal data, including:
Our service providers may process data outside the European Economic Area. Where this occurs, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses).
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or by posting a notice on our website. The date at the top of this policy indicates when it was last updated.
For privacy-related questions or to exercise your rights: