Privacy Policy
Last updated 22 September 2026
The short version. We collect the email address you sign in with, the monitors you create, and the destinations you tell us to send alerts to. We do not sell anything to anyone, we do not run advertising, and we do not track you across other sites. You can delete your account and everything in it at any time.
Who we are
UptimeMonke is an uptime monitoring service operated from Singapore. This policy covers the website at uptimemonke.com, the API at api.uptimemonke.com, and the UptimeMonke mobile apps for Android and iOS.
What we collect, and why
Account information
When you create an account we receive, from you or from the identity provider you choose to sign in with (Google, GitHub or Apple):
- Your email address — to identify your account, to send you the confirmation link, and to reach you about your workspace.
- Your display name and profile picture, where the provider supplies them — shown to you in the app. These are optional and you can change the name.
- An account identifier issued by Firebase Authentication.
We never receive your password. Authentication is handled by Firebase Authentication; if you sign in with Google, GitHub or Apple, your password is never sent to us at all.
What you put into the service
- Monitors — the name, the address being checked, and any settings for that check type, such as a keyword to look for, a port, or a DNS record.
- Alert contacts — the channel and the destination you enter: an email address, a Slack or Discord webhook URL, a chat identifier, or your own webhook endpoint.
- Your workspace name.
What the service produces
- Check results — whether each check succeeded, how long it took, and the error text when it failed.
- Incidents — when a monitor went down, when it recovered, and the cause reported by the check.
Mobile app
- A push notification token, if you allow notifications. It identifies your device to Firebase Cloud Messaging so an alert can reach it. It is deleted when you sign out or disable notifications.
Usage analytics
We use Google Analytics, through Firebase, to understand which features get used and where people get stuck. Events record the action — that a monitor was created, that a sign-in failed — together with an opaque workspace identifier and whether the workspace is on the free tier.
Analytics never receives your email address, your monitor addresses, or your alert destinations. That is a deliberate constraint in the code, not a policy promise: those values are not passed to the analytics layer.
Anti-abuse
Sign-up and sign-in are protected by Google reCAPTCHA, which analyses the request to distinguish a person from automated abuse. Google's handling of that is governed by its own privacy policy.
Donations
Donations are processed by Stripe. Card details never reach our servers — they are entered on Stripe's own checkout. We receive confirmation that a payment succeeded and the amount, which is what we use to raise your check allowance.
What we do not do
- We do not sell or rent personal information to anyone.
- We do not show advertising, and we do not share data with ad networks.
- We do not track you across other websites.
- We do not read the content of the sites you monitor beyond what the check itself needs — a status code, a response time, and a keyword match where you configured one.
Public status pages
A monitor appears on your public status page only if you tick that option on the monitor itself. Absence means private — a monitor created before that setting existed does not become public by default.
A published status page shows the monitor's name and its health. It never shows the address being checked, the keyword being matched, your alert contacts, or the text of an error.
How long we keep it
- Account and monitor configuration — for as long as your account exists.
- Individual check results — about 35 days, after which they are compacted into daily summaries.
- Daily uptime summaries — retained to draw the longer history windows on your charts and status page.
- Incidents — about a year.
- Push notification tokens — until you sign out or turn notifications off.
Your choices
- See and correct it. Your account details, monitors and alert contacts are all visible and editable in the app.
- Delete it. Deleting your account removes your workspace, its monitors, their history and your alert contacts. Email us at the address below and we will action it.
- Turn off push notifications in your device settings, or from the app, which removes the device token.
- Export it. Ask and we will send you what we hold in a machine- readable form.
If you are in the UK, EU or another region with equivalent law, you also have the right to object to processing, to restrict it, and to complain to your data protection authority.
Security
Traffic to the site and API is encrypted in transit. Authentication is handled by Firebase, so we never hold your password. Alert contacts must be confirmed before they can receive anything, so a channel cannot be pointed at someone who did not agree to it.
No service can promise perfect security, and we are not going to. If we discover a breach affecting your data, we will tell you.
Children
UptimeMonke is a tool for people running websites and services, and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has given us information, email us and we will delete it.
Changes to this policy
When our data practices change, this page changes with them and the date at the top is updated. If a change materially affects how we handle your information, we will tell you by email before it takes effect.
Contact
Questions about this policy, or a request about your data: privacy@uptimemonke.com