Cert Monitor
Privacy Policy
How Cert Monitor collects, uses, stores, and discloses account data for the public SSL certificate monitoring service.
Last updated: June 6, 2026
Scope
This policy applies to Cert Monitor, an SSL/TLS certificate monitoring service, covering the public marketing site, account registration and sign-in, dashboard usage, and support communication.
This service is designed for certificate monitoring only. We do not provide domain ownership verification, uptime monitoring, payment processing, or team collaboration in this release.
Data we process
We process your account email address so you can register, sign in, confirm your email, reset your password, and receive service messages.
We process notification email addresses that you add to receive certificate alerts. Notification addresses must be verified before they can receive monitoring alerts.
We process monitoring targets that you submit, including domain names, host and port combinations, or HTTPS URLs that normalize into host:port certificate targets.
We process certificate check records, such as check time, certificate validity dates, issuer, subject, fingerprint, and connection or TLS errors.
We process notification records, including which monitor triggered an alert, which verified email address received it, when it was sent, and whether delivery failed.
Anonymous checker and public API
You can use the public SSL checker and /api/v1/check endpoint without creating an account. Anonymous checks do not save your check result, do not save raw certificate content, and do not store the checked domain in analytics.
We keep only the minimum short-lived operational data needed for rate limiting, abuse prevention, and service security. If we need deduplication for protection, we use short-lived hashes with a time limit rather than storing raw targets as product history.
Checker URLs may include a target query parameter so you can share or reopen the same check. That parameter is visible to anyone you share the link with, but it is not a saved monitor and does not preserve a historical result.
Our check servers perform TLS checks from the public internet and can only reach publicly accessible HTTPS endpoints. We do not store raw certificates, PEM-encoded content, public keys, moduli, or any other data that could be used to reconstruct a full certificate. We extract and store only the metadata necessary for monitoring decisions, such as validity dates, issuer, subject, and fingerprint.
How we use data
We use account and authentication data to operate the service, secure signups, prevent abuse, and support account recovery.
We use monitoring targets, check records, and notification records to run the shared certificate check queue, calculate renewal risk, and send expiry alerts to verified addresses.
We may use limited operational logs and support messages to troubleshoot failures, investigate abuse, and improve reliability.
Sharing and subprocessors
We use third-party infrastructure providers to host the application, database, authentication, bot protection, and email delivery needed to operate Cert Monitor.
We do not sell your personal data. We only disclose data to service providers or when required to comply with law, protect the service, or prevent abuse.
Retention and security
We retain account data, monitoring targets, certificate check records, and notification records for as long as reasonably necessary to operate the service, investigate incidents, and meet legal obligations.
We use reasonable technical and organizational measures to protect data. However, no internet service can guarantee absolute security.
For anonymous checks and rate-limiting protection, short-lived operational data (such as request frequency counters and deduplication hashes) expires automatically within 24 to 72 hours. This data does not convert into long-term storage and is not associated with your account.
Your choices
You can update or delete monitoring targets and notification email addresses from your account, subject to the product features currently available.
For privacy questions, access requests, or deletion requests, email support [at] certmonitor.xyz.