This policy explains what personal data A.Rahman Abdulla Mufarreh Abdulla Mufarrah, an individual based in Manama, Kingdom of Bahrain ("we"), the operator of ExpiryOwl, processes, why, and who helps us. We are a small team and we try to collect as little as possible.
What we process
| Data | Why | Kept for |
|---|---|---|
| Account email address and name | To run your account, sign you in, and send alerts and reports you set up. | Until you delete the account |
| Monitored hostnames, client names and contact emails you add | To run the checks and send reports. | Until you delete them or the account |
| Check results (certificate details, registration data, DNS records, response times) | To show history, detect changes and alert you. | While the host is monitored, then up to 90 days |
| Alert channel settings (webhook URLs, chat IDs) | To deliver alerts. Secrets are stored encrypted. | Until you remove the channel |
| IP address and browser user-agent | Security, rate limits on sign-in and the free tools, and an audit log of account changes. | Up to 90 days (audit entries up to 1 year) |
| Product usage events (for example "tool used", "monitor added") | To understand which features help. First-party only, no third-party trackers or ad cookies. | Up to 2 years, aggregated after that |
| Billing details | Handled by Paddle. We see your plan, country and invoice status, never your card number. | As required for tax records |
Hostnames typed into a free tool are checked and not stored with your identity. We keep an anonymous count of tool uses and, for rate limiting, your IP address for up to one hour.
Cookies
We set one session cookie when you sign in, and remember your light or dark theme choice in your browser. There are no advertising or cross-site tracking cookies.
The first time you open a page on our site we also set one first-party cookie, eo_attr, for 30 days. It holds where the visit came from: the campaign tags in the link (utm_source, utm_medium, utm_campaign), the name of the referring website (only its domain, never the full address) and the path of the first page you opened. It contains nothing about you personally. If you create an account, we copy these values onto your organisation so we can see which channels bring customers. No third-party scripts read it.
Sub-processors
| Provider | What for | Data involved |
|---|---|---|
| Paddle | Payments, invoicing, sales tax (merchant of record) | Name, email, billing country, payment details |
| Resend | Sending sign-in links, alerts and reports | Recipient email addresses, email content |
| Google (Gemini API) | Writing the short summary in monthly client reports | Hostnames and check results for that report; no account passwords or payment data |
| Hostinger | Server hosting | All service data (stored on our server) |
| Cloudflare | Network and TLS in front of the server | Request metadata such as IP addresses |
If report summaries can't be written by Gemini, we fall back to a model running on our own server or a plain template, so the report never depends on it.
Your rights
You can see, export, correct and delete your data from the dashboard, or ask us at [email protected]. Depending on where you live you may also have the right to object to or restrict processing and to complain to a data protection authority. We answer requests within 30 days.
Changes
If we change this policy in a way that matters, we'll email account holders before it takes effect. The date at the top shows the latest version.