Privacy Policy

This explains what we collect, what we do with it, and what you can ask us to do about it. It covers both the website and the monitoring service. The company responsible for your data — the controller, in GDPR terms — is UptimeTwin LLC, 351 San Felipe Road, Ste 101 #1018, Hollister, CA 95023, USA.

Last updated: September 9, 2026

1. What We Collect

Account details

Your email address, and your password stored as a bcrypt hash. We never keep the password itself. If you sign in with Google or GitHub instead, we get your email address and name from them, plus an identifier for your account there — never your password for that service. Microsoft sign-in is built but switched off, so nothing goes to Microsoft today. If you turn on two-factor login, we store the shared secret your authenticator app needs. We never store the six-digit codes.

Monitor setup

The URLs, hostnames, ports and check intervals you configure, plus your alert preferences — thresholds, quiet hours and which channels to use.

Check results

The outcome of every check: up, down or degraded, how long it took, when it ran, and whatever the check itself returned, such as SSL certificate details or DNS records. This is what your dashboard, reports and status pages are built from.

People you add

If you add someone else as an alert recipient, or they subscribe to one of your status pages, we hold the email address or phone number you or they gave us, so we can send what you set up. When you use UptimeTwin for a business, that information is yours rather than ours: you decide what happens to it and we act only on your instructions. Section 9 of our Terms of Use sets out that arrangement in full. If you are one of those people and you want your details removed, ask whoever runs the monitoring, or contact us and we will put you in touch.

Payment details

Paid plans are handled entirely by Stripe. Your card number, CVV and billing address never reach us. All we get back is a customer ID and a subscription status, which is what we need to know which plan you are on.

Support messages

If you contact support or send feedback, we keep your name or email, the category you picked and your message. We use it to reply to you and nothing else.

SMS alerts

Add a mobile number as an alert channel and we store the number, the time you ticked the consent box, and the exact wording you agreed to. We text you a six-digit code first and only start sending alerts once you enter it, so nobody can sign up a phone they do not hold.

Your mobile number, and the fact that you opted in, will not be shared or sold to third parties for marketing purposes. Your number goes to our SMS delivery provider, ClickSend, so it can deliver the alerts you asked for. That is the only place it goes.

How often you hear from us is entirely down to your own monitors: you get a text when one goes down or comes back, or when it reports another change you monitor for, such as a slow response or a certificate or domain about to expire — so the volume varies. Message and data rates may apply. Reply STOP to any message to end them, or HELP for help. Stopping texts leaves the rest of your account alone — your monitors keep running and your other alert channels keep working. The full SMS terms are in section 16 of our Terms of Use.

Mobile app

If you use our mobile app, we store a push token for each device you sign in on, along with the device's platform and name, so alerts can reach it. Each device appears as its own alert channel under Settings → Notifications, where you can remove it at any time.

Free tools

The free tools at /tools need no account, and most of them keep nothing at all. Two can email you: the SSL-expiry reminder and the weekly site report. If you ask for either, we store the email address you gave, the domain you asked about, and when we last wrote to you. That is all of it, and there is no account behind it. Nothing is ever sent to an address until it has confirmed by clicking through from the first message, and every message carries an unsubscribe link. Because there is no account to sign in to, section 7 does not apply to these: use the unsubscribe link, or contact us and we will remove the address.

Server logs

Basic request logs: IP address, browser or app user agent, and a timestamp. We use them for security and debugging. They sit in the logging systems our hosting and edge providers run, and age out on those providers' own schedules — usually within about a month. We do not copy them anywhere else or build any profile from them.

2. What We Do With It

We do not sell or share your personal data for advertising. There are no advertising or cross-site tracking companies in the service, and no analytics company builds a profile of you or follows you between sites. The only measurement that could be present at all is Cloudflare's own page counting at the edge of the site it already protects: aggregate page views, no cookie, nothing tied to your account, and nothing used for advertising. Nothing here makes an automated decision that has a legal or similarly significant effect on you — the AI features suggest, they do not decide.

3. Legal Basis (GDPR)

If you are in the EU, UK or EEA, here is what we rely on:

We never rely on consent for tracking or advertising, because we do neither.

4. Who Else Sees Your Data

Only these providers and services, and only as far as each one needs. The list is meant to be complete: it names the companies that handle data for us, the systems we run ourselves that hold a copy of it away from the main application, and the public registries a check has to ask a question of.

We may also disclose data where the law requires it, or to protect the safety and rights of our users or others.

We use no advertising or cross-site tracking companies, and no analytics company beyond the aggregate page counting Cloudflare can do at the edge, described above.

5. Where Your Data Goes

Our databases are in the United States. The servers that run your checks are in the United States, the Netherlands, Singapore and Japan, and they send their results back to the US. If you use the service from the EU, UK or anywhere else outside the US, your data is transferred to and processed in the US. Our providers each maintain their own transfer safeguards, and if you need standard contractual clauses in place with us for your own compliance, ask and we will sort it out.

6. How Long We Keep It

7. Deleting Your Account

You can do this yourself, from Settings → Account. It asks for your password, and for a two-factor code if you have one set up. Deletion is scheduled 48 hours out, and signing back in during that window cancels it. Any active subscription is cancelled straight away.

After the 48 hours the account and the data behind it are removed: your monitors, your check results and history, your alert history, your status pages and their subscribers, your support tickets and your AI conversations. If you would rather we handled it, contact us and we will complete the deletion within 30 days.

Four things deliberately outlive the account. Only the first is something the law obliges us to keep, and we would rather say so than let "your data is removed" stand as if it covered everything:

8. Security

What we actually do:

None of that makes any system perfectly secure. Please use a strong, unique password, and turn on two-factor login — it is the single biggest difference you can make to your own account.

If a breach ever puts your personal data at risk, we will tell you and the relevant regulator as quickly as the law requires.

9. Your Rights

Depending on where you live, you can ask us to:

In the EU, UK or EEA you can also complain to your local data protection authority.

California residents (CCPA/CPRA): you can ask what we collect, have it corrected or deleted, and opt out of it being sold or shared. We do not sell or share personal information, so there is nothing to opt out of — but you are welcome to check that with us. We do not collect sensitive personal information as the CPRA defines it, and we will never give you a worse service for exercising any of these rights.

To exercise any of this, use our contact page or email [email protected]. We aim to reply within 5 working days and to finish the job within 30.

10. Cookies

Two cookies. Both are strictly necessary, and both are only set once you are signed in:

We also keep a couple of small preferences in your browser's local storage, such as light or dark theme. Those are not cookies and never reach our servers.

Because none of this is analytics, advertising or tracking, no consent banner is required under the ePrivacy Directive or similar laws. We would rather just tell you what the cookies do.

11. Children

UptimeTwin is not aimed at children and is not for anyone under 16. We do not knowingly collect data from children. If you think a child has given us personal information, contact us and we will delete it.

12. Changes to This Policy

We will update this policy as the service changes. If a change materially affects how we handle your data, we will email you before it takes effect. For anything smaller we will update the "Last updated" date at the top.

13. Contact

Questions about this policy or your data? Email [email protected], use our contact page, or write to UptimeTwin LLC, 351 San Felipe Road, Ste 101 #1018, Hollister, CA 95023, USA. Our business phone number is 1-833-878-4634. We aim to reply within 5 working days.