Changelog

Changelog

What changed, and when.

Product changes, corrections, and the formal notices our Terms and Privacy Notice require — including the ones where we were wrong and are saying so.

removed

Opsgenie is no longer an alert channel

Atlassian stopped selling Opsgenie to new customers in June 2025 and has set its end of life for April 2027, so the channel could not be adopted by anyone signing up today. Rather than advertise a destination new customers cannot obtain, we have removed it from the product, the API and the docs. Seven channels ship: email, Slack, Microsoft Teams, Discord, webhooks, PagerDuty and SMS.

Teams that need on-call schedules and escalation policies should forward to PagerDuty; PageLantern detects and records, the paging tool decides who wakes up.

Notice

Correction: credential fields are encrypted at rest, and always have been on this plan

Our Terms, Privacy Notice and Security page all stated that monitor request headers, request bodies, environment variables and alert webhook URLs were stored without field-level encryption. That stopped being true when field-level AES-256-GCM encryption shipped for those columns, and we did not update the documents. We have corrected all three.

Only heartbeat tokens are genuinely stored unencrypted, because an inbound ping is authenticated by matching the token value, which requires the stored value to be readable. Treat a heartbeat URL as a bearer secret and rotate it if it may have been exposed.

Nothing about how we store your data changed on this date — only what we say about it. We would rather correct a statement that was wrong in our own disfavour than leave it standing.

Changed

Encryption at rest is no longer described as a paid feature

The plan comparison listed "Encrypted notification destinations" as a Starter and Team feature. It was never gated: encryption is applied at the persistence layer to every account on every plan. The row was wrong and has been replaced with an accurate one that applies to all three plans.

We do not differentiate plans on security controls, and the pricing page now says so rather than implying the opposite.

Added

Annual subscriptions now get a pre-renewal reminder

If you are on an annual plan, we email you before each renewal with the amount, the renewal date, and a link to cancel. Our Terms and Refund Policy have described this since August 3; it now exists.

Monthly plans do not get one. No rule asks for a reminder on a term shorter than a year, and a monthly reminder is the kind of mail that trains people to filter us.

Added

Checkout now asks EU and UK customers to confirm immediate start

Before payment, checkout asks you to confirm that your subscription should start immediately and to acknowledge that the 14-day right of withdrawal is lost once the service has been fully performed. This is what the EU Consumer Rights Directive requires of a digital service that begins inside the cooling-off period, and our Refund Policy already described it.

The acknowledgment is recorded against the checkout session, so if a charge is ever disputed we can show what was agreed rather than asserting it.

Added

Documentation: eleven new guides, an API reference, and code you can copy

The documentation covered about a third of the product. It now covers SSL and domain monitoring, DNS and TCP checks, browser checks, every alert channel, webhook payloads and signature verification, incidents and postmortems, status-page customisation, teams and roles, API keys, billing, and the operational states you see in the product.

There is also a full API reference, and — for the first time — snippets you can copy, including the cron heartbeat example the pricing page has been advertising.

Changed

We stopped under-selling our own alert channels

The pricing table and the getting-started guide both listed four alert channels. Seven ship: email, Slack, Microsoft Teams, Discord, webhooks, PagerDuty and SMS. Every surface now renders the list from one place, and a test fails the build if they disagree again.

Changed

Consumers are excluded from arbitration

We market PageLantern to people running personal sites and side projects as well as to businesses. Asking those customers to give up their day in court was inconsistent with that, and in the EU and UK such clauses are unenforceable against consumers anyway.

If you use PageLantern as a consumer, the arbitration agreement, the class-action waiver and the jury-trial waiver in Terms §27 do not apply to you at all. We also removed the clause restricting you from publishing benchmarks and comparisons, and added an intellectual-property indemnity in your favour.