Legal

Privacy Policy

Last updated: 12 August 2026

This Privacy Policy explains how UptimeHunt handles personal data. UptimeHunt is a distributed uptime, website, and service monitoring platform.

1. Who we are and how to contact us

UptimeHunt is operated by OpenHades Cloud Services Konrad Mosoń — Konrad Mosoń, an individual entrepreneur (jednoosobowa działalność gospodarcza) registered in the Polish CEIDG and based in Kraków, Poland (EU), NIP 8681952845, REGON 387960680. For the personal data described in this policy, OpenHades Cloud Services Konrad Mosoń is the data controller.

Reach us about anything in this policy — privacy questions, data-subject requests, support — at support@uptimehunt.io.

Our services run across these domains:

  • uptimehunt.io — marketing site
  • app.uptimehunt.io — dashboard and REST API
  • docs.uptimehunt.io — documentation
  • mcp.uptimehunt.io — MCP server (for AI clients)
  • auth.uptimehunt.io — OAuth 2.1 authorization server

UptimeHunt is currently free and in beta, provided "as is". No paid plans are purchasable yet.

2. The personal data we collect

We collect two broad categories of data: personal data about you (the account holder), and the monitoring data you supply to run your checks.

2.1 Data about your account

  • Account data: your email address, your password (stored only as a salted hash — we never store the plaintext), and an optional name. We use this to create and operate your account, authenticate you, and contact you.
  • Authentication artifacts: JWT access and refresh tokens, which are held client-side in your browser's localStorage (these are not third-party advertising cookies); and OAuth 2.1 authorization data — consent records, your list of "connected apps", and opaque access tokens — used by the MCP server and AI clients you connect.
  • API tokens: long-lived, uh_-prefixed tokens for automation. We store only a hash of each token; the secret is shown to you once at creation, is scoped, and is revocable.
  • Technical and usage data: IP address, browser/user-agent, request and server logs, and timestamps. We collect this to secure and operate the service, prevent abuse, and debug.
  • Website and dashboard analytics: page URL and referring URL, browser, operating system, device type, screen size, browser language, page-load performance timings, and an approximate location (country, region, city) derived from your IP address. On the public website and the documentation site we also record where clicks land and how far the page was scrolled, to build heatmaps — no session recording. This is collected by Umami, which we run on our own servers. Inside the signed-in dashboard your numeric account id and the organization you are working within are attached to these records, and the dashboard is not heatmapped; on the public website these records carry only an identifier we cannot resolve to a person. See Section 12.
  • Communications: emails we send you (account and security notices, password resets, and alert notifications) delivered over SMTP; and any correspondence you send to support@uptimehunt.io.
  • Billing/payment data: none. We do not collect or store payment or card data — no payment processor is connected to the Service.

Providing your account data (at least an email address and password) is necessary to create and operate an account. If you do not provide it, we cannot create an account for you or provide the service.

2.2 Monitoring data you supply

To provide monitoring, we process the data you configure. Some of this may relate to systems or services that belong to third parties you choose to monitor, and some may include credentials you enter.

  • Monitoring configuration: target URLs, hostnames, IP addresses, ports, request method and headers, optional HTTP basic/bearer credentials you enter for authenticated checks, custom DNS nameservers, check intervals, assertions/expectations, projects, and chosen probe locations (the geographically distributed servers — "probes" — that run your checks; see Section 6). The targets you enter may belong to third parties you have chosen to monitor.
  • Check results: response times and phase breakdowns (DNS/TCP/TLS/first-byte), HTTP status codes, TLS certificate chains and expiry, DNS records (A/AAAA/MX/TXT/NS/SOA/CNAME) and TTLs, SMTP banners and EHLO capabilities, SSH identification banners/version/host-key fingerprints, ping round-trip time and packet loss, and game-server status (Quake3/Source/A2S/GoldSource/Minecraft — map, game type, player counts and roster).
  • Incidents and incident history; alert rules; and an audit log of account actions.
  • Integrations: the credentials and configuration you supply for each notification destination — outbound webhook URLs, bot tokens, API keys, routing keys, and channel or chat identifiers. Alerts are delivered to the destinations you choose, which are third-party services governed by their own terms and privacy policies. Which destinations are available is listed on our pricing page and in the documentation, not here.
  • Kubernetes auto-discovery (optional): if you run the UptimeHunt operator in your own cluster, it reads cluster Ingress hostnames and paths and mirrors them into HTTP checks using a long-lived API token. This is add/update-only.

Targets and credentials are processed only to run the checks you configured: a hostname is sent to a probe so it can connect and measure the result, and credentials you enter are used to authenticate against that target.

2.3 Personal data about third parties that you supply

The monitoring configuration and check results you enter can include personal data about third parties that we did not collect directly from those individuals. Examples include hostnames and IP addresses belonging to other people or organisations, credentials you enter for authenticated checks, and game-server data such as player counts and rosters.

For this third-party personal data:

  • the categories of data are those listed in Section 2.2 (e.g. hostnames/IPs, credentials you enter, and check results such as game-server rosters);
  • the source is you, the account holder, who configured the check; and
  • we process it only to provide the monitoring service to you, on your instructions.

You are responsible for ensuring you have a valid legal basis and any necessary authorisation to monitor the targets you configure and to enter any credentials and third-party data, and for your use of the results. Please only configure checks against systems you own or are authorised to monitor.

3. How and why we use your data

We use the data above to:

  • create, operate, and secure your account, and authenticate you;
  • run the monitoring checks you configure and return their results to you;
  • generate incidents, evaluate alert rules, and deliver alert notifications to your chosen destinations;
  • send you account, security, and service emails;
  • maintain an audit log and diagnose problems;
  • protect the service against abuse, overload, and misuse, and protect our infrastructure and other users;
  • improve and maintain the service; and
  • comply with our legal obligations.

We do not use third-party advertising or analytics trackers, and we do not sell your personal data. The analytics we do run are self-hosted on our own infrastructure and are described in Section 12; no analytics data leaves our servers.

4. Legal bases (GDPR Article 6)

We rely on the following legal bases under Article 6 of the GDPR, mapped to the purposes in Section 3:

  • Performance of a contract (Art. 6(1)(b)) — to create, operate, and secure your account and authenticate you; to run the monitoring checks you configure and return their results; to generate incidents, evaluate your alert rules, and deliver alert notifications to your chosen destinations; and to send you account, security, and service emails. This is the basis for providing the service you have signed up for.
  • Legitimate interests (Art. 6(1)(f)) — for the following purposes, where we have a legitimate interest that we balance against your rights and interests:
    • keeping the platform and your account secure and protecting our infrastructure and other users (our interest: information security and fraud/abuse prevention);
    • preventing abuse, overload, and misuse of the service (our interest: maintaining service integrity and availability);
    • diagnosing problems and maintaining an audit log (our interest: operating, troubleshooting, and ensuring accountability of the service);
    • improving and maintaining the service (our interest: developing and improving our product).
  • Consent (Art. 6(1)(a)) — where we specifically ask for it, for example optional features that require consent. You can withdraw consent at any time, without affecting processing already carried out before withdrawal.
  • Legal obligation (Art. 6(1)(c)) — where we must retain or disclose data to comply with applicable law.

5. Data retention

We keep personal data only as long as needed for the purposes above or as required by law.

Raw probe results (the per-check results we store):

PlanRetention
Free30 days
Pro90 days
Team180 days
Scale365 days
Enterprisecustom

Incident history:

PlanRetention
Free30 days
Pro90 days
Team180 days
Scale365 days
Enterprisecustom

Free is the only live tier today. The other rows apply when those plans launch.

Account data is retained for the life of your account and is deleted when you close your account, subject to any retention we are legally required to perform. To close your account or request deletion, email support@uptimehunt.io (see Section 9, Your GDPR rights).

Other data categories:

  • Technical and usage data (IP address, user-agent, request and server logs, timestamps): retained for a limited period for security, abuse prevention, and debugging, and then deleted or aggregated; where it forms part of the audit log it follows the audit-log rule below.
  • Analytics data (Section 12): retained for as long as we run the service, so that usage can be compared year on year. Public-website analytics carry no identifier that outlives the month they were recorded in — the visitor hash is re-salted monthly. Signed-in dashboard analytics carry your account id and your organization and are deleted when you close your account, or earlier on request.
  • Audit log of account actions: retained for the life of your account (and deleted on account closure), subject to any legally required retention.
  • Support and other correspondence you send to us: retained for as long as needed to handle your request and for a reasonable period afterwards for our records, then deleted.
  • Authentication and OAuth artifacts (JWT tokens, OAuth consent records, connected-apps entries, opaque access tokens, API token hashes): retained while they remain valid or while the relevant connection or token exists, and removed when you revoke them, disconnect the app, or close your account.

Where we are under a legal obligation to retain certain data for longer (for example record-keeping requirements), we keep it for the period required and then delete it.

6. Sharing, recipients, subprocessors, and infrastructure

We do not sell your data and we do not share it for advertising. The categories of recipients of personal data are:

  • Infrastructure providers / subprocessors (listed below), who process data on our behalf to run the service;
  • Third-party alert destinations you choose — when an alert fires, we transmit the alert content (which may include monitoring details) to the integration destinations you have configured (e.g. your webhook endpoints, and, when available, chat platforms). These are third-party services governed by their own terms and privacy policies; you choose them; and
  • Competent courts, regulators, and public authorities, where we are legally required to disclose data, or where disclosure is necessary to enforce our terms or to protect the rights, safety, and security of UptimeHunt, our users, or the public.

We process data using the following infrastructure and providers:

  • Core platform: runs on the operator's own self-managed Kubernetes cluster.
  • Distributed probe nodes: run on third-party VPS providers in multiple countries. These probes execute your checks from their locations and return the results to the core platform. The providers and countries change over time. Current providers include RackNerd and Mikr.us, among others; for the full current list, ask at support@uptimehunt.io.
  • Data stores: application data and probe results are held in self-hosted databases on the operator's own cluster, alongside a self-hosted message queue. No third-party data-storage processor is involved.
  • Email delivery: Amazon SES (AWS), EU region (eu-north-1, Stockholm) — sends account, security, and alert-notification emails over SMTP.
  • Advertising trackers: none. Third-party analytics: none — our analytics run on Umami, self-hosted on the operator's own cluster and collected at utr.openhades.com, so this data is never shared with an analytics vendor.
  • Payment processor: none.

7. International transfers

Our core infrastructure is operated from the EU.

By design, our probe nodes are distributed globally, including outside the European Economic Area (EEA), and run on third-party VPS providers located in multiple countries — so a non-EEA subprocessor is involved when a check runs from a non-EEA location. When a check runs from a non-EEA probe, the data processed at that location includes the monitoring configuration you entered (for example the target hostname or URL, request method and headers), any HTTP basic/bearer credentials you entered for authenticated checks, and the check results produced there.

For these transfers, we seek to rely on appropriate safeguards under Chapter V of the GDPR (for example, Standard Contractual Clauses) where they are available from the relevant provider. Where you would like more information about the safeguards in place, a copy can be requested via support@uptimehunt.io.

8. Security

We take reasonable measures to protect personal data, including:

  • passwords stored only as salted hashes;
  • API tokens stored only as hashes, and which are scoped and revocable;
  • TLS encryption for data in transit;
  • per-owner tenant isolation, so each account can only access its own data.

None of this makes a breach impossible, and we do not claim otherwise.

9. Your GDPR rights

Subject to the conditions in the GDPR, you have the right to:

  • access your personal data;
  • rectify inaccurate or incomplete data;
  • erase your data ("right to be forgotten");
  • restrict processing;
  • data portability — receive your data in a portable format;
  • object to processing based on legitimate interests;
  • withdraw consent where we relied on it; and
  • lodge a complaint with a supervisory authority.

To exercise any of these rights, email support@uptimehunt.io. We will respond within one month; for complex or numerous requests we may extend this by up to two further months and will tell you if we do.

You also have the right to complain to the Polish supervisory authority:

You may also lodge a complaint with the supervisory authority in your EU country of residence.

10. Automated decision-making

UptimeHunt does not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 of the GDPR. Our alert-rule evaluation and incident generation operate on the monitored systems and their results — not to make decisions about you as an individual.

11. Children

UptimeHunt is not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us with personal data, contact support@uptimehunt.io and we will take appropriate steps.

12. Cookies, local storage, and analytics

We do not use third-party advertising cookies. To keep you signed in, the dashboard stores JWT access and refresh tokens in your browser's localStorage. The OAuth authorization server (auth.uptimehunt.io) sets a first-party session cookie during sign-in and consent so it can remember your authenticated session through the OAuth flow, and uses the data described in Section 2.1 to manage sign-in and connected apps. These are strictly necessary for the service to function.

Analytics

We run Umami on our own servers to see which pages are read and how the site and dashboard perform. It collects the data listed in Section 2.1 under "Website and dashboard analytics".

The tracker script and the endpoint it reports to are served from utr.openhades.com, which is the address to look for if you want to inspect or block the requests. Our own reporting dashboard is a separate host, umami.openhades.com, reachable only from our internal network; it receives nothing from your browser.

The analytics store nothing on your device and read nothing from it — no cookie, no local storage, no fingerprinting script. That is why this site shows you no cookie-consent banner: there is nothing to consent to under the ePrivacy rules that govern storing or reading data on your equipment.

To recognise a returning visit without storing anything, your IP address and browser string are combined into a one-way hash; your IP address is never stored in its original form. The hash is re-salted every month, so it cannot link your visits across months, and it is derived per-site, so it cannot follow you between our sites or anyone else's.

We rely on legitimate interest (GDPR Article 6(1)(f)) for this — our interest in understanding usage and performance. You can object at any time: run localStorage.setItem('umami.disabled', 1) in your browser's console on the site in question, and the tracker will send nothing for as long as that flag is set. You can also object by contacting us at support@uptimehunt.io.

Analytics inside the signed-in dashboard

On the public website (uptimehunt.io) and the documentation site (docs.uptimehunt.io) the analytics identify nobody: the records carry only the monthly hash described above, and the session identifier the heatmaps below are grouped by — neither of which we can resolve to a person.

Inside the dashboard (app.uptimehunt.io), once you are signed in, we additionally attach your numeric account id and the organization you are working within to your analytics sessions, so that we can tell how the product is actually used — which features are reached, where people get stuck — rather than only counting page views we cannot attribute to anyone. This means dashboard analytics are linked to your account and are personal data.

Those two fields are the whole of it. The account id is a number that means nothing outside our own database. The organization is recorded as its id together with its name or slug, so that reports are readable, and it is there to produce per-organization usage statistics — how a customer uses the product as a whole, not what any one person did. An organization name is your business information rather than personal data about you, but it is still your data, so we disclose it here.

We do not put your email address, your name, or anything you have configured — targets, credentials, check results — into the analytics.

The basis is again legitimate interest (Article 6(1)(f)): understanding how our own product is used by our own signed-in customers, weighed against data that reveals nothing beyond navigation within the dashboard. It is not used for advertising, is never sold or shared, and is not used to make any decision about you or your account. Your GDPR rights in Section 9 apply to it in full, including the right to object and the right to erasure — and unlike the public-website analytics, which carry no identifier we can resolve to you, these records can be located and deleted on request, because they carry your account id. Email support@uptimehunt.io.

Heatmaps on the public website and documentation

On the public marketing site and the documentation site we build heatmaps to see which parts of a page people click and how far down they read. What is recorded is where a click lands and how far the page was scrolled, together with the page and viewport dimensions needed to place those points on a picture of the page.

That is the whole of it. There is no session recording and no replay: we do not capture the page's structure, its content, any text, anything you type, or the path your pointer takes between clicks — only the coordinates of clicks that actually happened. The recorder inspects the element you clicked solely to measure the page's bounds, then discards it; no selector and no text from the page is stored.

The signed-in dashboard at app.uptimehunt.io is not heatmapped at all. Dashboard sessions carry your account id, and click coordinates attached to that would be joinable to a named customer, so the recorder does not run there.

These rows carry the same monthly-rotating identifier as the rest of the website analytics — an identifier we cannot resolve to a person, and one that stops working at the end of each month. Nothing is written to or read from your device for this, so what this section says about consent banners is unchanged, and the opt-out above switches it off along with the rest.

13. California residents (CCPA/CPRA)

We do not sell or share your personal information as those terms are used under the CCPA/CPRA. Subject to applicable law, California residents may have the right to know what personal information we collect, to delete it, to correct it, and to opt out of the sale or sharing of personal information — although the opt-out does not apply here because we do not sell or share your data. We will not discriminate against you for exercising any of these rights. To make a request, email support@uptimehunt.io.

14. Changes to this policy

We may update this Privacy Policy. Material changes update the "Last updated" date above, and we will notify you where the change warrants it.

15. Contact

For any privacy question or to exercise your rights, contact us at support@uptimehunt.io.