Last updated 12 August 2026
Privacy Policy
Owl Keeper is a monitoring service. To do its job it has to keep two things: enough about you to let you back into your account, and a record of what the sites you asked it to watch were doing. This page says what those are, how long they are kept, and what Owl Keeper deliberately does not collect.
Analytics
Owl Keeper measures how this site and the application are used, so that the parts people struggle with can be found and fixed. Two things do that, and they work differently enough to be worth separating.
Product analytics, recorded on the server. Actions taken inside the application — a site added, a monitor created or checked by hand, a status page published — are recorded against your account, along with a few plain facts about the action such as the type of check. This runs through PostHog, which also loads a small script in your browser to record which pages you visit and which site sent you here. That script sets its own cookies, and it does so whatever you answer to the cookie banner — the banner controls Google Analytics only. It never records the contents of the pages you watch.
Google Analytics, which runs in your browser. This site and the application load Google Analytics 4. It is a script from Google that sets its own cookies and records which pages you visit, which site sent you here, roughly where in the world you are, and what kind of device and browser you are using. It is used to understand which pages bring people here and where they give up.
Neither is used for advertising. Nothing about you is sold or rented, and nothing is shared for marketing.
Public status pages carry neither. A link you send a client loads no analytics at all — not ours, not Google's. Those are your client's visitors, not ours, and they are not measured.
Cookies
The cookies that make a signed-in session work — a session cookie, a CSRF token, and a "remember me" cookie if you ask for one — are strictly necessary, which is why you are not asked to consent to those. Your light or dark theme preference and your chosen language are stored in your browser and on your account.
Google Analytics sets cookies of its own, and those are not strictly necessary, which is why you are asked before any of them are set. Until you say yes, Google's tag is held in a consent-denied state and writes nothing to your browser. Saying no changes nothing about how any of this works.
You can change your mind at any time with the Cookies link in the footer of this page, which brings the question back. Withdrawing is the same single click as agreeing was.
What is stored about you
- Your account. Your name, your email address, a one-way hash of your password, and your language preference.
- Sign-in security. If you turn them on, your two-factor secret, your recovery codes, and any passkeys you register. Secrets are stored encrypted.
- What you asked to be watched. The hostnames, URLs, ports and mail servers you add, along with their schedules and check settings.
- Where you asked to be told. Webhook addresses and their signing secrets, which are stored encrypted.
What is recorded about the sites you watch
- Check results. Whether each check answered, how long it took, and the response code or error. These are kept for 35 days and then deleted; a daily summary of uptime and average response time is kept beyond that so the long history bars survive.
- Public facts about your domains. Certificate details, domain registration and registrar data, nameservers, DNS records, mail authentication records, and the security-relevant headers your site returns. All of it is read from your own site or from public registries.
- Changes. A check that finds the same thing as yesterday records nothing. Only changes are written down.
Owl Keeper does not store the body of your pages. It reads a response to answer the question you set — a status code, or whether a keyword you chose is present — and keeps the answer, not the page.
Requests made on your behalf
When you add something to be watched, Owl Keeper makes requests to it on the schedule you set, identifying itself in the User-Agent header as OwlKeeper/1.0 (+https://owlkeeper.com). Those requests appear in your own server logs. It also queries public sources to answer questions your site cannot: domain registry (RDAP) lookups, and DNS lookups made over Google's public DNS-over-HTTPS resolver. Only the hostname being checked is sent.
Your email address is used to verify your account, to let you reset your password, and to send the alerts you have configured. There is no marketing email and no newsletter. Alerts are sent through a third-party email provider, which necessarily sees the address and the contents of the message.
Public status pages
If you publish a status page, anyone holding the link can see what is on it: the hostname, whether services are answering, uptime figures, recent incidents, and when the certificate and registration renew. It never shows monitor names, addresses, or anything from the security checks. The link is unguessable and the page asks search engines not to index it, but it is not protected by a password — treat it as public. You can withdraw it or issue a new link at any time, which stops the old one working immediately.
Who else can see it
Everything you add belongs to your team, and is visible to the members of that team. Beyond that, your monitoring data is not shared with anyone. It is processed by the infrastructure providers that host the application, its database and its outbound email — they act on instructions and do not use it for their own purposes.
The two analytics tools described above are the exception worth naming, because they are the only places where anything about you leaves this application for a company that is not simply running it. PostHog receives the in-app actions listed there. Google receives what its script collects in your browser; Google is a large advertising company and, while this property is not used for advertising, what Google does with data it collects is governed by its own terms rather than by this page.
Deleting your account
You can delete your account from your profile settings. Doing so removes your account and the monitoring data belonging to it. Some records may persist briefly in encrypted infrastructure backups before those are rotated out.
Your rights
You can see and correct your account details in the application at any time, export or request a copy of what is held about you, and delete it. If you are in the UK or the European Economic Area you also have the right to object to processing and to complain to your national data protection authority.
Changes
If this policy changes in a way that materially affects what is collected or who can see it, the date at the top of this page will change and you will be told by email before it takes effect.