gavelLegal Documentation

Privacy Policy

VERSION: 2.4.0-STABLELAST UPDATED: MARCH 27, 2026

01. Introduction

At Upwatch ("Upwatch", "we", "our"), we respect your privacy and are committed to protecting it through our compliance with this policy. This policy describes the types of information we may collect from you or that you may provide when you use our monitoring platform and our practices for collecting, using, maintaining, protecting, and disclosing that information.

This policy applies to information we collect through the Upwatch dashboard, in email and other electronic messages between you and Upwatch, and through our monitoring APIs.

02. Data Collection

What We Collect

  • _Account Information: Email address, name, and hashed password.
  • _Monitor Configuration: URLs, check intervals, HTTP methods, custom headers, and tags you configure.
  • _Check Results: HTTP status codes, response latency, TLS certificate expiry dates, and error messages from your monitored endpoints.
  • _Incident Records: Timestamps, causes, and resolution data for detected outages.

We collect this information directly from you when you provide it (account registration, monitor setup) and automatically through our check engine when it performs HTTP requests to your configured endpoints.

03. How We Use Your Data

monitor_heart

Service Delivery

Executing HTTP checks, computing uptime statistics, detecting incidents, and delivering webhook alerts.

security

Security

Authenticating sessions with JWT tokens, protecting against SSRF attacks, and enforcing per-user data isolation.

public

Public Status Pages

Displaying monitor names and status on your public status page. URLs, headers, and configuration are never exposed publicly.

trending_up

Service Improvement

Aggregate, anonymized usage patterns to improve check reliability, dashboard performance, and alerting accuracy.

04. Data Retention

Check results are automatically purged after the retention period configured for your account (default: 90 days) using database TTL indexes. Incident records are retained indefinitely for historical reporting unless you delete your account.

When you delete a monitor, checks stop immediately. Historical check data is retained per the retention policy. When you delete your account, all associated data (monitors, checks, incidents, alerts) is permanently removed.

05. Security

We implement industry-standard safeguards to protect your data from unauthorized access.

Password Storagebcrypt hashed
AuthenticationJWT (15min access / 7d refresh)
SSRF ProtectionPrivate IP blocking
Data IsolationPer-user tenant scoping

06. Cookies & Local Storage

Upwatch uses browser localStorage to persist your JWT session tokens. We do not use advertising cookies, third-party tracking pixels, or analytics scripts. The only data stored client-side is your authentication token, which is required for the dashboard to function.

07. Your Rights

You have the right to:

  • check_circleAccess all data we hold about you via the API
  • check_circleExport your monitor data and check history
  • check_circleDelete your account and all associated data
  • check_circleRequest information about how your data is processed

To exercise any of these rights, contact us at [email protected].

Questions about our privacy practices?

Our team is ready to answer questions about data handling, security, and compliance.

mail Contact Privacy Team