Legal

Privacy Policy

We believe privacy is a right, not a feature. This policy explains exactly what data we collect, why we collect it, and how we protect it — in plain language.

Effective: January 1, 2025
Last updated: January 1, 2025
Questions? hello@podpapa.com

Overview

The short version: We collect only what we need to run the service. We never sell your data. We never share it with advertisers. Your monitoring data stays on our infrastructure and is never used for any purpose other than delivering the service to you.

Monitor by PodPapa ("Monitor", "we", "us", or "our") is a managed uptime monitoring service operated by PodPapa. This Privacy Policy describes how we collect, use, store, and protect information when you use our website at monitor.podpapa.com and related services.

By using Monitor, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the service.

Data We Collect

We collect information in the following categories:

Account Information

  • Email address (used to create your account and send notifications)
  • Password (stored as a bcrypt hash — we never store your password in plain text)
  • Name (optional, used to personalize your dashboard)

Monitor Configuration Data

  • URLs, IP addresses, hostnames, and ports you add to be monitored
  • Custom HTTP headers and authentication credentials you optionally provide for authenticated endpoint monitoring
  • Notification channel configurations (e.g., Telegram bot tokens, Slack webhook URLs, email addresses)
  • Monitor settings such as check intervals, alert thresholds, and tags

Monitoring Activity Data

  • Response time and status code results from each check performed on your monitors
  • SSL certificate details retrieved during certificate monitoring
  • Incident logs including timestamps, duration, and cause of detected downtime events

Technical & Usage Data

  • IP address of your browser when you log into the dashboard
  • Browser type and operating system (from standard HTTP headers)
  • Pages visited within the dashboard and features used
  • Error logs and diagnostic data used to maintain service reliability

How We Use Your Data

We use the data we collect exclusively to operate and improve the Monitor service. Specifically:

  • To deliver the monitoring service — performing checks on your configured monitors at your specified intervals, detecting downtime, and recording results
  • To send alerts — delivering notifications to your configured channels when a monitor changes state (down, recovered, SSL expiring, etc.)
  • To display your dashboard — showing uptime history, response time charts, and incident logs within the Monitor interface
  • To maintain and improve reliability — using technical logs and error data to diagnose and fix issues with the service
  • To communicate with you — sending service-related emails such as account confirmation, password reset, billing receipts, and important service announcements
  • To enforce our Terms of Service — detecting abuse, fraudulent activity, or violations of our acceptable use policy

We do not use your data to train machine learning models, serve advertising, build behavioral profiles, or sell to data brokers.

Data Storage & Security

All Monitor data is stored on PodPapa-managed infrastructure. We implement industry-standard security measures to protect your data:

  • All data is transmitted over encrypted HTTPS/TLS connections
  • Passwords are hashed using bcrypt before storage
  • Sensitive credentials (such as notification tokens) are encrypted at rest
  • Access to production systems is restricted to authorized personnel only, with access logs maintained
  • Automated daily backups are performed and stored separately from production data
  • Our infrastructure is regularly updated with security patches

While we take security seriously and implement reasonable measures, no system is 100% immune to breaches. In the event of a data breach that affects your personal data, we will notify affected users as required by applicable law.

Third-Party Sharing

We do not sell your personal data. We do not share your data with advertisers, marketing companies, or data brokers — ever.

We may share data with third parties only in the following limited circumstances:

  • Service providers — we use a small number of trusted providers to operate the service (e.g., payment processing for billing). These providers are contractually bound to process your data only for the purpose of delivering their service to us and may not use it for any other purpose.
  • Notification delivery — when you configure a notification channel (Telegram, Slack, email, etc.), alert data is transmitted to those services to deliver your notifications. This transmission is initiated by you through your own credentials and accounts.
  • Legal compliance — we may disclose your data if required by applicable law, regulation, valid legal process, or to protect the rights and safety of PodPapa, our users, or the public.
  • Business transfers — in the event of a merger, acquisition, or sale of all or a portion of our assets, user data may be transferred as part of that transaction. We will notify affected users before any such transfer.

Cookies & Local Storage

Monitor uses a minimal set of cookies and browser storage strictly necessary to operate the service:

  • Session cookie — keeps you logged into the dashboard. Expires when you log out or after an inactivity period.
  • Theme preference — stores your chosen light/dark mode preference in localStorage so it persists across visits.

We do not use advertising cookies, tracking pixels, or third-party analytics that profile your behavior across other websites. We do not use Google Analytics or similar cross-site tracking tools.

Your Rights

You have the following rights regarding your personal data, regardless of your location:

  • Access — you can request a copy of all personal data we hold about you at any time
  • Correction — you can update your account information directly from the dashboard settings, or request corrections by email
  • Deletion — you can delete your account and all associated data from the dashboard settings. Deletion is permanent and irreversible. We will remove all your data within 30 days.
  • Export — you can export your monitor configuration and historical data from the dashboard at any time
  • Objection — you can object to processing of your data in cases where we rely on legitimate interests as a legal basis
  • Portability — you can request your data in a machine-readable format for transfer to another service

To exercise any of these rights, contact us at hello@podpapa.com. We will respond within 30 days.

Data Retention

We retain your data for as long as your account is active. Specifically:

  • Account data — retained until you delete your account
  • Monitor history and incident logs — retained for the duration of your subscription and up to 90 days after account cancellation
  • Billing records — retained for 7 years as required by applicable accounting and tax laws
  • Server access logs — retained for 90 days for security and debugging purposes, then automatically deleted

When you delete your account, all personal data and monitor data are permanently deleted from our production systems within 30 days. Billing records are retained only as required by law.

Children's Privacy

Monitor is a professional infrastructure monitoring service intended for use by businesses and individuals aged 16 and older. We do not knowingly collect personal data from children under the age of 16.

If you believe we have inadvertently collected data from a person under 16, please contact us immediately at hello@podpapa.com and we will delete the data promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

  • Update the "Last updated" date at the top of this page
  • Send a notification email to all registered users at least 14 days before the changes take effect
  • Display a notice in the dashboard for a period after the change

Continued use of Monitor after the effective date of a revised policy constitutes your acceptance of the changes. If you disagree with any changes, you may delete your account before the effective date.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please reach out — we aim to respond within 2 business days.

Privacy & Data Requests

For privacy questions, data access requests, or account deletion.

hello@podpapa.com