Legal

Privacy policy

Last updated 2026-09-26

This policy explains what personal data A.Rahman Abdulla Mufarreh Abdulla Mufarrah, an individual based in Manama, Kingdom of Bahrain ("we"), the operator of ExpiryOwl, processes, why, and who helps us. We are a small team and we try to collect as little as possible.

What we process

DataWhyKept for
Account email address and nameTo run your account, sign you in, and send alerts and reports you set up.Until you delete the account
Monitored hostnames, client names and contact emails you addTo run the checks and send reports.Until you delete them or the account
Check results (certificate details, registration data, DNS records, response times)To show history, detect changes and alert you.While the host is monitored, then up to 90 days
Alert channel settings (webhook URLs, chat IDs)To deliver alerts. Secrets are stored encrypted.Until you remove the channel
IP address and browser user-agentSecurity, rate limits on sign-in and the free tools, and an audit log of account changes.Up to 90 days (audit entries up to 1 year)
Product usage events (for example "tool used", "monitor added")To understand which features help. First-party only, no third-party trackers or ad cookies.Up to 2 years, aggregated after that
Billing detailsHandled by Paddle. We see your plan, country and invoice status, never your card number.As required for tax records

Hostnames typed into a free tool are checked and not stored with your identity. We keep an anonymous count of tool uses and, for rate limiting, your IP address for up to one hour.

Cookies

We set one session cookie when you sign in, and remember your light or dark theme choice in your browser. There are no advertising or cross-site tracking cookies.

The first time you open a page on our site we also set one first-party cookie, eo_attr, for 30 days. It holds where the visit came from: the campaign tags in the link (utm_source, utm_medium, utm_campaign), the name of the referring website (only its domain, never the full address) and the path of the first page you opened. It contains nothing about you personally. If you create an account, we copy these values onto your organisation so we can see which channels bring customers. No third-party scripts read it.

Sub-processors

ProviderWhat forData involved
PaddlePayments, invoicing, sales tax (merchant of record)Name, email, billing country, payment details
ResendSending sign-in links, alerts and reportsRecipient email addresses, email content
Google (Gemini API)Writing the short summary in monthly client reportsHostnames and check results for that report; no account passwords or payment data
HostingerServer hostingAll service data (stored on our server)
CloudflareNetwork and TLS in front of the serverRequest metadata such as IP addresses

If report summaries can't be written by Gemini, we fall back to a model running on our own server or a plain template, so the report never depends on it.

Your rights

You can see, export, correct and delete your data from the dashboard, or ask us at [email protected]. Depending on where you live you may also have the right to object to or restrict processing and to complain to a data protection authority. We answer requests within 30 days.

Changes

If we change this policy in a way that matters, we'll email account holders before it takes effect. The date at the top shows the latest version.