webhooks.sh — Privacy Policy

Last updated August 29, 2026

What webhooks.sh stores, why, and for how long. The short version: we store the webhook traffic you send us plus the minimum needed to operate and bill the service — nothing more.

What we store

What we never do

We do not sell data, run ads, fingerprint visitors, or track people across sites. We do not inspect your traffic for advertising or profiling. Stored payloads may be scanned by automated systems to detect abuse (phishing, malware), and may be reviewed by a human after an abuse report.

Who processes the data

Retention

Free bins expire after 48 hours; their stored requests are then deleted, and deletion is real deletion. Abuse reports are kept while the reported endpoint exists and for 90 days after. Account data is kept until you ask us to delete it.

Your rights

You can request access to, correction of, export of, or deletion of your personal data at any time — email abuse@webhooks.sh. If your webhook traffic contains your own users' personal data, you are its controller; deleting your endpoint's data deletes it for them too.

Security

All dashboard and viewer traffic is TLS-encrypted, view keys are stored hashed, and bin contents are readable only with the secret view URL. Report security issues to abuse@webhooks.sh.

Changes

We may update this policy as the service evolves; the "last updated" date above tracks that. Material changes will be called out on this page.

webhooks.sh · terms · privacy · abuse@webhooks.sh