Privacy Policy

Pingara is committed to protecting your privacy. This policy explains what we collect, why we collect it, who we share it with, where it is processed, and how you can have it removed.

Last updated: July 26, 2026

Information We Collect

We collect only what we need to run the monitoring service you signed up for:

  • Account details. Your email address, your name if you provide one, and a hashed version of your password. We never store your password in plain text.
  • Sign-in and device information. For each device signed in to your account we record the IP address, your browser’s user agent and a device label derived from it (for example “Chrome on macOS”), an approximate city and country, and when the session was last active. This powers the Active Sessions list in your settings so you can see where your account is signed in and sign out a device you do not recognise. The session identifier itself is stored only as a hash.
  • Security credentials. If you enable two-factor authentication, we store your TOTP secret encrypted and your single-use backup codes as hashes. If you create API keys, we store only a hash and a short prefix so we can show you which key is which.
  • Monitor configuration. The URLs, hostnames, and ports you ask us to monitor, along with the check intervals, regions, timeouts, and alert settings you choose.
  • Monitoring results. Uptime logs and performance metrics produced by our probes, including response times, DNS and TLS timings, status codes, error messages, SSL expiry dates, and the incidents derived from them.
  • Organization and team data. Your organization name, the members you invite, their roles, and their notification preferences.
  • Billing identifiers. If you subscribe to a paid plan, we store the customer and subscription identifiers issued by Stripe. We never see or store your card number.
  • Status page subscribers. If you enable email subscriptions on a public status page, we store the email addresses of the people who subscribe so we can notify them of incidents.

How We Use Your Information

Your data is used to operate the service, and for nothing else:

  • Running the checks you configure and detecting outages and degraded performance.
  • Populating your dashboard, charts, uptime and Apdex figures, SLA reports, and incident history.
  • Sending the alerts and weekly reports you have opted into, through the channels you configure.
  • Showing you where your account is currently signed in, and letting you revoke a device or sign out everywhere.
  • Managing your account, plan limits, and billing, and answering your support requests.
  • Keeping the service secure, including detecting abuse and enforcing rate limits.

We Never Sell Your Data

We do not sell, rent, or trade your personal information to third parties, and we do not share it with advertisers. The only parties who receive your data are the service providers listed below, who process it strictly on our behalf so that Pingara can function.

Third-Party Services

Pingara relies on a small number of established providers. Each receives only the data required for its role:

  • Convex hosts our database and backend, and therefore stores your account, monitor, and monitoring result data.
  • Amazon Web Services hosts the Pingara web application and runs the monitoring probes that perform your checks.
  • Stripe processes payments and manages subscriptions. Card details are entered on Stripe’s own systems and never pass through ours.
  • Resend delivers transactional email such as alerts, verification messages, and weekly reports, and receives the recipient address and message content.
  • ipapi.co turns the IP address of a sign-in session into an approximate city and country for your Active Sessions list. We only call it when you open that list — never during sign-in — and we cache the result so a repeat address is not sent again.
  • Google (Gemini) powers our AI root cause hints. When you request an analysis, the timing and error details of the relevant check are sent to the model.
  • Google Analytics measures how our website is used. It runs only if you accept analytics cookies.
  • Alert destinations you configure — such as Slack, Microsoft Teams, Discord, PagerDuty, or your own webhook endpoint — receive the incident details we send on your behalf.

Cookies & Analytics

We use a session cookie to keep you signed in. This cookie is essential to the service and cannot be turned off while you are logged in.

Analytics cookies are optional. We ask for your consent before any analytics script runs, and analytics stay disabled until you accept. You may decline, and you can clear your choice at any time by clearing your browser storage for this site.

When you mark a knowledge base article helpful or unhelpful, we record that rating against a random identifier stored in your browser, so the same article is not counted twice. It is not linked to your account, and you do not need one to read the knowledge base.

Where We Process Your Data

Pingara is operated from the United States, and our monitoring probes run in several regions so we can check your services from more than one place — currently US East (N. Virginia), US West (Oregon), Europe (Ireland), and Asia Pacific (Singapore). Your monitor configuration and check results are therefore processed in the regions you select, and your account data may be processed in a country other than the one you live in.

Data Retention

Individual check results are high-volume time-series data and are kept for a short period. We aggregate them into hourly, daily, weekly, and monthly rollups, which we retain longer so that your uptime history and SLA reporting remain available. Account, organization, and monitor configuration data is kept for as long as your account is active.

How far back your monitoring history goes depends on your plan — see our pricing page for the current retention windows. If your organization moves to the Free plan, history beyond the shorter Free plan window is no longer available, as described in our Terms of Service.

Our cache of resolved IP locations is purged automatically after 30 days. Session records are removed when you sign the device out, and when your account is deleted.

Security

All communication with Pingara is encrypted in transit using HTTPS. Passwords are stored only as salted hashes, and credentials for the integrations you configure are handled as secrets. If you enable two-factor authentication, your TOTP secret is encrypted at rest and your backup codes are stored as hashes, so neither can be read back out of our database.

Pingara is multi-tenant by design: every monitor, incident, and report belongs to a single organization, and access is checked against your membership on every request. No security measure is perfect, but we treat the protection of your data as a core part of building the product.

Children’s Privacy

Pingara is not intended for children. As set out in our Terms of Service, you must be at least 13 years old to use the service, and we do not knowingly collect information from anyone younger. If you believe a child has given us their information, contact us and we will remove it.

Your Rights & Data Deletion

You may contact us at any time to request a copy of the data we hold about you, to correct it, or to have it deleted. You can also remove your data yourself, in this order:

  • Delete your organization. This is what removes your monitoring data — monitors, check results, rollups, incidents, alert rules, and status page entries are all deleted with it. Only an owner can do this, the organization must be on the Free plan, and any other members must be removed first.
  • Delete your account. Once you no longer belong to any organization, deleting your account removes your user record along with your saved sessions and any outstanding password reset or email verification tokens. Account deletion is blocked while you are still a member of an organization.

To make a request, or to ask anything about this policy, email us at support@pingara.io. If you subscribed to a public status page, every notification we send includes an unsubscribe link.

Changes to This Policy

This policy may change as the service evolves. When we make material changes, we will update the date above. Your continued use of Pingara after a change means you accept the updated policy. See also our Terms of Service.

Contact Us

Questions about this policy, or about the data we hold on you? Email us at support@pingara.io and we will get back to you.