Privacy Policy
Last updated: 27 August 2026
GDPR contact: support@sslert.com. Product: SSLert at https://sslert.com.
What we store
- Account email (Supabase Auth).
- Monitored hostnames and ports you add.
- Check results (validity, issuer, serial, expiry timestamps, optional certificate PEM when the serial changes).
- Alert channel configuration (email address, webhook URL, Telegram/Slack/ntfy settings).
- Stripe customer and subscription identifiers, plan, and period end.
We do not sell personal data. We do not use it for advertising.
Processors
- Supabase — authentication and Postgres hosting.
- Stripe — payment processing. Card data stays with Stripe.
- Resend — delivers expiry alerts from alerts@sslert.com and account mail from info@sslert.com.
- PostHog (EU) — product analytics: page views, referrer/UTM, CTA clicks. After you sign in we send account id and email so a visitor can be matched to a user. We do not sell this or use it for ads.
Legal basis
We process this data to provide the Service (contract) and, where required, to meet legal obligations around billing. You may request access, correction, export, or deletion of your account data by emailing support@sslert.com.
Retention
Check history older than 90 days may be deleted, except the latest result per domain. Alert records may be pruned after 365 days. Account data is kept while the account exists and deleted on request, subject to billing records we must keep.
Cookies and logs
The app stores a session in the browser via Supabase Auth. We keep ordinary server logs (IP, path, time) for security and debugging, then discard them on a short rotation.
International transfers
Processors may store data in the EU and other regions they operate in. We use them only as needed to run the Service.