Privacy Policy
This explains what we collect, what we do with it, and what you can ask us to do about it. It covers both the website and the monitoring service. The company responsible for your data — the controller, in GDPR terms — is UptimeTwin LLC, 351 San Felipe Road, Ste 101 #1018, Hollister, CA 95023, USA.
Last updated: September 9, 2026
1. What We Collect
Account details
Your email address, and your password stored as a bcrypt hash. We never keep the password itself. If you sign in with Google or GitHub instead, we get your email address and name from them, plus an identifier for your account there — never your password for that service. Microsoft sign-in is built but switched off, so nothing goes to Microsoft today. If you turn on two-factor login, we store the shared secret your authenticator app needs. We never store the six-digit codes.
Monitor setup
The URLs, hostnames, ports and check intervals you configure, plus your alert preferences — thresholds, quiet hours and which channels to use.
Check results
The outcome of every check: up, down or degraded, how long it took, when it ran, and whatever the check itself returned, such as SSL certificate details or DNS records. This is what your dashboard, reports and status pages are built from.
People you add
If you add someone else as an alert recipient, or they subscribe to one of your status pages, we hold the email address or phone number you or they gave us, so we can send what you set up. When you use UptimeTwin for a business, that information is yours rather than ours: you decide what happens to it and we act only on your instructions. Section 9 of our Terms of Use sets out that arrangement in full. If you are one of those people and you want your details removed, ask whoever runs the monitoring, or contact us and we will put you in touch.
Payment details
Paid plans are handled entirely by Stripe. Your card number, CVV and billing address never reach us. All we get back is a customer ID and a subscription status, which is what we need to know which plan you are on.
Support messages
If you contact support or send feedback, we keep your name or email, the category you picked and your message. We use it to reply to you and nothing else.
SMS alerts
Add a mobile number as an alert channel and we store the number, the time you ticked the consent box, and the exact wording you agreed to. We text you a six-digit code first and only start sending alerts once you enter it, so nobody can sign up a phone they do not hold.
Your mobile number, and the fact that you opted in, will not be shared or sold to third parties for marketing purposes. Your number goes to our SMS delivery provider, ClickSend, so it can deliver the alerts you asked for. That is the only place it goes.
How often you hear from us is entirely down to your own monitors: you get a text when one goes down or comes back, or when it reports another change you monitor for, such as a slow response or a certificate or domain about to expire — so the volume varies. Message and data rates may apply. Reply STOP to any message to end them, or HELP for help. Stopping texts leaves the rest of your account alone — your monitors keep running and your other alert channels keep working. The full SMS terms are in section 16 of our Terms of Use.
Mobile app
If you use our mobile app, we store a push token for each device you sign in on, along with the device's platform and name, so alerts can reach it. Each device appears as its own alert channel under Settings → Notifications, where you can remove it at any time.
Free tools
The free tools at /tools need no account, and most of them keep nothing at all. Two can email you: the SSL-expiry reminder and the weekly site report. If you ask for either, we store the email address you gave, the domain you asked about, and when we last wrote to you. That is all of it, and there is no account behind it. Nothing is ever sent to an address until it has confirmed by clicking through from the first message, and every message carries an unsubscribe link. Because there is no account to sign in to, section 7 does not apply to these: use the unsubscribe link, or contact us and we will remove the address.
Server logs
Basic request logs: IP address, browser or app user agent, and a timestamp. We use them for security and debugging. They sit in the logging systems our hosting and edge providers run, and age out on those providers' own schedules — usually within about a month. We do not copy them anywhere else or build any profile from them.
2. What We Do With It
- Run the monitoring service
- Send the alerts and notifications you have set up
- Answer your support and feedback messages
- Take subscription payments through Stripe
- Generate AI diagnostics and assistant replies, on paid plans
- Spot and investigate abuse and security incidents
- Keep an internal audit trail of administrative actions on accounts
We do not sell or share your personal data for advertising. There are no advertising or cross-site tracking companies in the service, and no analytics company builds a profile of you or follows you between sites. The only measurement that could be present at all is Cloudflare's own page counting at the edge of the site it already protects: aggregate page views, no cookie, nothing tied to your account, and nothing used for advertising. Nothing here makes an automated decision that has a legal or similarly significant effect on you — the AI features suggest, they do not decide.
3. Legal Basis (GDPR)
If you are in the EU, UK or EEA, here is what we rely on:
- Contract — your account, your monitors, your checks, your billing, and the AI features on paid plans. We cannot provide the service you signed up for without processing these.
- Legitimate interest — security logging, abuse and fraud prevention, and the admin audit trail.
- Consent — anything you specifically opted into, such as SMS alerts.
We never rely on consent for tracking or advertising, because we do neither.
4. Who Else Sees Your Data
Only these providers and services, and only as far as each one needs. The list is meant to be complete: it names the companies that handle data for us, the systems we run ourselves that hold a copy of it away from the main application, and the public registries a check has to ask a question of.
- Cloudflare — sits in front of every request to our site and API. It sees your IP address and request headers, shields us from attacks, and runs the Turnstile check on our sign-up and contact forms. Where Cloudflare's own Web Analytics is switched on for our site, your browser also loads a small counting script from Cloudflare and it counts the page view; that count is aggregate, sets no cookie, and is not linked to your account. See Cloudflare's Privacy Policy.
- Stripe — payments. See Stripe's Privacy Policy.
- Postmark and SMTP2GO — send our transactional email: alerts, password resets and replies from support.
- ClickSend — SMS delivery to a number you have verified. They get the number and the text of the alert. Nothing else about your account. See ClickSend's Privacy Policy.
- Google (Firebase Cloud Messaging) — mobile push notifications, if you use our app. Google receives the device token and the alert text. See Firebase's privacy information.
- Google and GitHub — only if you choose to sign in with one of them. We receive your email address, name and an account identifier from the one you pick. Microsoft sign-in is wired up but switched off, so no data reaches Microsoft; if we turn it on, this page will say so first.
- AI model providers — Google, OpenAI and Groq — on paid plans, the AI diagnostics and the AI assistant send the relevant monitor's address and its recent check results, and for the assistant the messages you type, to one of these providers to generate a response. Your password and payment details are never part of that.
- Fly.io, Railway and Supabase — application and database hosting. The databases are in the United States.
- DigitalOcean — runs a second, complete copy of the website and of the API alongside Fly.io and Railway, and takes roughly half of every request to the service, so anything the service handles can pass through it. Those servers hold the credentials they need to reach our databases. DigitalOcean also hosts part of the fleet that runs your checks, which sees the addresses it is told to check and the results that come back.
- GitHub — our own service-status site at status.uptimetwin.com is published as static pages by GitHub, deliberately outside our own infrastructure so that it keeps working when we do not. GitHub serves that page, so it sees the IP address and request headers of anyone who opens it, and because our sign-in cookie is scoped to uptimetwin.com and its subdomains, a signed-in browser sends that cookie with the request as well. GitHub is separately one of the sign-in options above.
- Domain and address registries — a domain check has to ask the registry itself, so the domain being checked goes to IANA's public registry directory and to the RDAP server for that domain ending, with rdap.org as a fallback. The AI diagnostics also ask RIPE NCC (stat.ripe.net) and rdap.org whether the address you monitor is still announced to the internet and which network it belongs to. These lookups carry the domain or address being checked and nothing that says whose account it is.
- Our own security log system — not another company, but listed here because it holds your data away from the application: a separate system we run ourselves collects the security record described in section 6 — sign-ins, failed sign-ins, administrative actions and account deletions, each with the email address, IP address and browser involved. It reads that record straight out of the database and holds the lasting copy under its own retention schedule; the application keeps only a 90-day spool.
- Our mail hosts — email you send to support is received and stored on mail servers operated for us, so that we can read and answer it.
- ipwho.is and ipapi.co — turn the IP address of a sign-in into an approximate city and country, so your login history and our unfamiliar-sign-in warnings can tell you where a sign-in came from. The same services are used for a second purpose: when the AI diagnostics investigate one of your monitors, they look up where the address you monitor is hosted and which network it sits on, so the report can say whose infrastructure a fault is on. In both cases they receive one IP address on its own: no name, no email address, nothing that says whose account it is. If the first two are unreachable we make the same single lookup against ip-api.com instead.
- Google Fonts — our pages use two typefaces served by Google, so your browser fetches them from Google and Google sees your IP address when it does. Nothing about your account is sent, and it is not used for analytics or advertising.
We may also disclose data where the law requires it, or to protect the safety and rights of our users or others.
We use no advertising or cross-site tracking companies, and no analytics company beyond the aggregate page counting Cloudflare can do at the edge, described above.
5. Where Your Data Goes
Our databases are in the United States. The servers that run your checks are in the United States, the Netherlands, Singapore and Japan, and they send their results back to the US. If you use the service from the EU, UK or anywhere else outside the US, your data is transferred to and processed in the US. Our providers each maintain their own transfer safeguards, and if you need standard contractual clauses in place with us for your own compliance, ask and we will sort it out.
6. How Long We Keep It
- Account data — for as long as your account exists.
- Individual check results — the full record of every check, on a rolling window set by your plan: 30 days on Free, 60 on Pro, and 90 on Business and MSP. Older records are deleted. Dashboard graphs may show a shorter span than your plan actually retains.
- Aggregated history — when individual results age out we keep only summaries, with no individual check kept, and at two grains. Per-hour totals are held 60 days on Free and 180 days on Pro, Business and MSP. Per-day totals — uptime, downtime, incidents and response-time figures — are held 60 days on Free, 180 on Pro, 365 on Business and 395 on MSP. Both are then deleted, and nothing is kept beyond 425 days on any plan.
- If you change plan — moving to a plan with a shorter window does not delete your history that day. We keep the longer window for 30 days first, so a lapsed payment or a brief step down does not destroy records you may still want.
- Alert history — 90 days.
- AI assistant conversations — kept only while the chat can still be resumed, and deleted once it has been idle for 24 hours.
- AI request logs — 90 days.
- Security record — sign-ins, failed sign-ins, administrative actions and account deletions, each with the email address, IP address and browser involved: 90 days in the application database. Our own security log system holds the lasting copy of the same record, under that system's own retention schedule.
- Administrative audit trail — what an administrator did to an account, and when. Kept indefinitely: nothing deletes it today, and where an entry concerns an account it holds that account's email address as text.
- Support — a support ticket raised in the app lasts as long as your account and is deleted with it. Email you send to support sits in our mailbox until we delete it; ask us and we will remove your correspondence.
- Free-tool subscriptions — the address you gave the SSL-expiry reminder or the weekly site report is kept for as long as you stay subscribed. If it is never confirmed, the record is deleted after 30 days. When you unsubscribe we replace the address straight away with a one-way value that we can still match a re-subscription against but cannot read or send to, and that record is deleted after 12 months.
- Server logs — see above; they age out on our providers' schedules.
- After deletion — see below.
7. Deleting Your Account
You can do this yourself, from Settings → Account. It asks for your password, and for a two-factor code if you have one set up. Deletion is scheduled 48 hours out, and signing back in during that window cancels it. Any active subscription is cancelled straight away.
After the 48 hours the account and the data behind it are removed: your monitors, your check results and history, your alert history, your status pages and their subscribers, your support tickets and your AI conversations. If you would rather we handled it, contact us and we will complete the deletion within 30 days.
Four things deliberately outlive the account. Only the first is something the law obliges us to keep, and we would rather say so than let "your data is removed" stand as if it covered everything:
- Billing and tax records — for as long as tax and accounting law requires.
- The security record of the deletion itself — that the account was deleted, when, and the email address it belonged to, so the entry still says which account it was. Ninety days in the application database, and on our own security log system under that system's retention schedule.
- The administrative audit trail, if an administrator ever acted on your account. The entry keeps your email address in its text and, as section 6 says, nothing deletes it today.
- The leaving survey, if you filled one in. We clear the fields that identify you — the account id, the email address, the payment reference and the invite token — but we deliberately keep the free-text answers you typed, because they are the substance of the answer; a reference that no longer names you stays, so several answers from one account remain connected. Ask us and we will delete the free text too.
8. Security
What we actually do:
- Passwords are hashed with bcrypt at cost factor 12 before they are stored
- Two-factor login (TOTP) is available to every account, and administrator accounts cannot be used without it
- Sessions use short-lived signed JWTs, and the session cookie is httpOnly, so page scripts cannot read it
- Everything is served over HTTPS
- API endpoints are rate limited
- Some of the servers that run your checks connect to the database with a restricted role, limited to the handful of tables and columns they need, so they cannot read password hashes or two-factor secrets. The rest of the fleet, and the tier that serves the website and the API, still connect with a broader database account — narrowing that one is work we have not finished
- Row-level security is switched on for every table, so our database host's own web API returns nothing to a caller we have not explicitly granted
None of that makes any system perfectly secure. Please use a strong, unique password, and turn on two-factor login — it is the single biggest difference you can make to your own account.
If a breach ever puts your personal data at risk, we will tell you and the relevant regulator as quickly as the law requires.
9. Your Rights
Depending on where you live, you can ask us to:
- Show you the personal data we hold about you
- Correct anything that is wrong
- Delete your data
- Restrict or stop certain processing
- Object to processing we base on our legitimate interests
- Export your data in a portable format
- Withdraw consent, where consent is what we relied on — SMS alerts, for instance. Withdrawing does not undo processing that was lawful at the time.
In the EU, UK or EEA you can also complain to your local data protection authority.
California residents (CCPA/CPRA): you can ask what we collect, have it corrected or deleted, and opt out of it being sold or shared. We do not sell or share personal information, so there is nothing to opt out of — but you are welcome to check that with us. We do not collect sensitive personal information as the CPRA defines it, and we will never give you a worse service for exercising any of these rights.
To exercise any of this, use our contact page or email [email protected]. We aim to reply within 5 working days and to finish the job within 30.
10. Cookies
Two cookies. Both are strictly necessary, and both are only set once you are signed in:
- Session cookie — keeps you signed in. It lasts 24 hours, and is reissued as you keep working, so an active session does not drop you out mid-task. Signing out clears it.
- Trusted-device cookie — saves you re-entering a two-factor code on a device you have already verified. Expires after 30 days, or the moment you revoke it in your trusted-devices settings.
We also keep a couple of small preferences in your browser's local storage, such as light or dark theme. Those are not cookies and never reach our servers.
Because none of this is analytics, advertising or tracking, no consent banner is required under the ePrivacy Directive or similar laws. We would rather just tell you what the cookies do.
11. Children
UptimeTwin is not aimed at children and is not for anyone under 16. We do not knowingly collect data from children. If you think a child has given us personal information, contact us and we will delete it.
12. Changes to This Policy
We will update this policy as the service changes. If a change materially affects how we handle your data, we will email you before it takes effect. For anything smaller we will update the "Last updated" date at the top.
13. Contact
Questions about this policy or your data? Email [email protected], use our contact page, or write to UptimeTwin LLC, 351 San Felipe Road, Ste 101 #1018, Hollister, CA 95023, USA. Our business phone number is 1-833-878-4634. We aim to reply within 5 working days.