Skip to main content

Privacy Policy

Pingara is committed to protecting your privacy. This policy explains what we collect, why we collect it, who we share it with, where it is processed, and how you can have it removed.

Last updated: August 25, 2026

Information We Collect

If you have an account, we collect only what we need to run the monitoring service you signed up for. (There are two things we collect from visitors who have no account — the certificate checker and the site scan on our home page. They get their own section below.)

  • Account details. Your email address, your name if you provide one, and a hashed version of your password. We never store your password in plain text.
  • Sign-in and device information. For each device signed in to your account we record the IP address, your browser’s user agent and a device label derived from it (for example “Chrome on macOS”), an approximate city and country, and when the session was last active. This powers the Active Sessions list in your settings so you can see where your account is signed in and sign out a device you do not recognise. The session identifier itself is stored only as a hash.
  • Security credentials. If you enable two-factor authentication, we store your TOTP secret encrypted and your single-use backup codes as hashes. If you create API keys, we store only a hash and a short prefix so we can show you which key is which.
  • Monitor configuration. The URLs, hostnames, and ports you ask us to monitor, along with the check intervals, regions, timeouts, and alert settings you choose.
  • Monitoring results. Uptime logs and performance metrics produced by our probes, including response times, DNS and TLS timings, status codes, error messages, SSL expiry dates, and the incidents derived from them.
  • Organization and team data. Your organization name, the members you invite, their roles, and their notification preferences.
  • Billing identifiers. If you subscribe to a paid plan, we store the customer and subscription identifiers issued by Stripe. We never see or store your card number.
  • Status page subscribers. If you enable email subscriptions on a public status page, we store the email addresses of the people who subscribe so we can notify them of incidents.

The Certificate Checker and Site Scan (No Account Needed)

Our home page has two tools you can use without an account: a box that checks a domain’s security certificate, and a full site scan that checks a domain across ten areas and gives you a shareable report. You do not need an account for either, so these are the only parts of Pingara that collect something from people who are not customers. Here is exactly what happens. Some points below apply to one tool and say so; the last one — the note of domains we keep indefinitely — applies to both.

  • You give us a domain name, and that is all we keep from it. Type a domain, or paste a full web address if that is easier — we throw away everything except the domain before doing anything else. The path, the query string, any sign-in details in the address, and anything else in the link never reach our records.
  • The certificate checker never requests a page. From our own servers, not from your browser, we complete the encrypted handshake, read the certificate the site presents, and disconnect. We never request a page, so we do not see or store any content from it.
  • The site scan requests your home page and robots.txt — and follows where the site itself redirects. We send a plain GET request to the home page of the domain you name, and to its robots.txt file, both from our own servers. No cookies, no sign-in details, and no custom headers go out with either request, and we never follow a link we find on the page — the scan only ever touches the address you gave us, never anything the page links to. If a site sends its own visitors elsewhere (for example from the bare domain to “www”), we follow that redirect too, up to four times, checking each new address against the same safety rules before we go there. We identify these requests with a name and a link back to this page, so a site owner can always tell it was us.
  • We read what we fetch, but we do not keep it. We read up to 512 KB of the home page (less for robots.txt and the registration lookup below) and turn what we find into counts, yes/no answers, and pass/fail results — for example how many images are missing alt text, whether a security header is present, or how a certificate’s expiry compares to today. Two things are the exception: the page’s title, which we keep because the report shows it, capped at 120 characters, and a short supporting note on some results, capped at 200 characters. Neither the page itself, its headers, nor any error message is ever stored.
  • Some things we deliberately never store, from either tool: the IP addresses a domain resolves to, response headers as sent, and raw DNS text records. From the site scan’s domain registration lookup, we also never store any registrant name, address, phone number, or email address.
  • The registration check asks the domain’s registry, not the domain itself. To show when a domain was registered and when it expires, we ask the public registry responsible for that domain ending — a lookup called RDAP, the modern replacement for WHOIS. That request tells the registry which domain you asked about. We keep only the dates, the registrar’s name, and a few status flags from the answer, never the registrant contact details described above.
  • Your IP address is scrambled before it is stored. We need to recognise repeat requests so neither tool can be abused, but we do not need to know who you are, so we store a one-way fingerprint of the address rather than the address itself. These abuse-prevention records are deleted within 30 minutes of being written.
  • A site scan report gets its own link, and that link is the only way to see it. The link contains 32 random bytes that we generate, so it cannot be guessed, and we mark the report page so search engines never list it. Anyone who has the link can view the report, so treat it the way you would treat any other link you are willing to share. We keep a report for 24 hours and delete it automatically within 24 hours and 20 minutes of when you started the scan.
  • We keep a note of which domains have been checked or scanned, and we keep it indefinitely. This one applies to both tools. Separately from any report, and outliving it, we keep the domain you asked about — with any leading “www.” removed, so that www.example.com and example.com are recorded as one entry — how many times its certificate has been checked, how many times it has been scanned, and when it was first and most recently seen by either tool. We do not shorten it any further: if you check shop.example.com, shop.example.com is what we keep. The certificate checker only adds to this note once the site has answered and presented a certificate, so a domain we could not reach, and anything that was never a valid domain name, is not recorded at all. Beyond those counts and timestamps, the only other thing that can go in this note is a contact email address and a short note, and only when someone on our team enters one, in order to contact that domain’s operator about monitoring it. Nothing here is about you or the device you used, so none of it — not any report, not its link, not any of the results — can be traced back to the person who ran the check. We use the note to understand which kinds of site people are checking, and, when we hold a contact address, sometimes to email it about monitoring the domain. Every outreach email we send carries a one-click link that stops all further contact about that domain, permanently. Deleting a report does not delete this note. If you would rather we did not keep it, email us at support@pingara.io and we will remove it — contact address, note and all.

Our lawful basis for both tools is legitimate interests: running the feature you asked us to run, keeping it from being used to attack other people, and — for the note of checked and scanned domains described above, which identifies no person — understanding what people use these tools for and letting site operators know we can monitor their site. No cookie is set by either, and both work whether or not you have accepted any.

Please only check domains you own or are allowed to test — see our Terms of Service. If you operate a domain and would rather it could not be checked this way, email us at support@pingara.io and we will exclude it from both the certificate checker and the site scan.

How We Use Your Information

Your data is used to operate the service, and for nothing else:

  • Running the checks you configure and detecting outages and degraded performance.
  • Populating your dashboard, charts, uptime and Apdex figures, SLA reports, and incident history.
  • Sending the alerts and weekly reports you have opted into, through the channels you configure.
  • Showing you where your account is currently signed in, and letting you revoke a device or sign out everywhere.
  • Managing your account, plan limits, and billing, and answering your support requests.
  • Keeping the service secure, including detecting abuse and enforcing rate limits.

We Never Sell Your Data

We do not sell, rent, or trade your personal information to third parties, and we do not share it with advertisers. The only parties who receive your data are the service providers listed below, who process it strictly on our behalf so that Pingara can function.

Third-Party Services

Pingara relies on a small number of established providers. Each receives only the data required for its role:

  • Convex hosts our database and backend, and therefore stores your account, monitor, and monitoring result data.
  • Amazon Web Services hosts the Pingara web application and runs the monitoring probes that perform your checks.
  • Stripe processes payments and manages subscriptions. Card details are entered on Stripe’s own systems and never pass through ours.
  • Resend delivers transactional email such as alerts, verification messages, and weekly reports, and receives the recipient address and message content.
  • ipapi.co turns the IP address of a sign-in session into an approximate city and country for your Active Sessions list. We only call it when you open that list — never during sign-in — and we cache the result so a repeat address is not sent again.
  • A domain’s own registry receives the domain name when you run a site scan, so we can look up its public registration record. See The Certificate Checker and Site Scan section above for what we keep from the answer.
  • Google (Gemini) powers our AI root cause hints. When you request an analysis, the timing and error details of the relevant check are sent to the model.
  • Google Analytics measures how our website is used. It runs only if you accept analytics cookies.
  • Alert destinations you configure — such as Slack, Microsoft Teams, Discord, PagerDuty, or your own webhook endpoint — receive the incident details we send on your behalf.

Cookies & Analytics

We use a session cookie to keep you signed in. This cookie is essential to the service and cannot be turned off while you are logged in.

Analytics cookies are optional. We ask for your consent before any analytics script runs, and analytics stay disabled until you accept. You may decline, and you can clear your choice at any time by clearing your browser storage for this site.

When you mark a knowledge base article helpful or unhelpful, we record that rating against a random identifier stored in your browser, so the same article is not counted twice. It is not linked to your account, and you do not need one to read the knowledge base.

Where We Process Your Data

Pingara is operated from the United States, and our monitoring probes run in several regions so we can check your services from more than one place — currently US East (N. Virginia), US West (Oregon), Europe (Ireland), and Asia Pacific (Singapore). Your monitor configuration and check results are therefore processed in the regions you select, and your account data may be processed in a country other than the one you live in.

Data Retention

Individual check results are high-volume time-series data and are kept for a short period. We aggregate them into hourly and daily rollups, which we retain longer so that your uptime history and SLA reporting remain available. Account, organization, and monitor configuration data is kept for as long as your account is active.

How far back your monitoring history goes depends on your plan — see our pricing page for the current retention windows. If your organization moves to the Free plan, history beyond the shorter Free plan window is no longer available, as described in our Terms of Service.

Our cache of resolved IP locations is purged automatically after 30 days. The abuse-prevention records behind the certificate checker and the site scan are purged within 30 minutes of being written, and a site scan report itself — its results and the link they live at — is deleted automatically within 24 hours and 20 minutes of when the scan started. The certificate checker produces no report at all: it returns its answer to you and stores nothing about the result. One thing outlives both tools: the note of which domain was checked or scanned, how many times by each, and when we first and last saw it, described in the section on those two tools above. We keep that indefinitely, and it holds nothing that identifies you.

Signing a device out takes effect immediately, and we keep the record of that session for 14 days afterwards before deleting it. That delay is deliberate rather than housekeeping: the record is what tells us the session was revoked, so removing it too early would let an already-signed-out device be accepted again. Sessions you never sign out of are removed after 14 days of inactivity, and everything goes when your account is deleted.

Security

All communication with Pingara is encrypted in transit using HTTPS. Passwords are stored only as salted hashes, and credentials for the integrations you configure are handled as secrets. If you enable two-factor authentication, your TOTP secret is encrypted at rest and your backup codes are stored as hashes, so neither can be read back out of our database.

Pingara is multi-tenant by design: every monitor, incident, and report belongs to a single organization, and access is checked against your membership on every request. No security measure is perfect, but we treat the protection of your data as a core part of building the product.

Children’s Privacy

Pingara is not intended for children. As set out in our Terms of Service, you must be at least 13 years old to use the service, and we do not knowingly collect information from anyone younger. If you believe a child has given us their information, contact us and we will remove it.

Your Rights & Data Deletion

You may contact us at any time to request a copy of the data we hold about you, to correct it, or to have it deleted. You can also remove your data yourself, in this order:

  • Delete your organization. This is what removes your monitoring data — monitors, check results, rollups, incidents, alert rules, and status page entries are all deleted with it. Only an owner can do this, the organization must be on the Free plan, and any other members must be removed first.
  • Delete your account. Once you no longer belong to any organization, deleting your account removes your user record along with your saved sessions and any outstanding password reset or email verification tokens. Account deletion is blocked while you are still a member of an organization.

To make a request, or to ask anything about this policy, email us at support@pingara.io. If you subscribed to a public status page, every notification we send includes an unsubscribe link.

Changes to This Policy

This policy may change as the service evolves. When we make material changes, we will update the date above. Your continued use of Pingara after a change means you accept the updated policy. See also our Terms of Service.

Contact Us

Questions about this policy, or about the data we hold on you? Email us at support@pingara.io and we will get back to you.