Owl Watch

Last updated 2 August 2026

Privacy Policy

Owl Watch is a monitoring service. To do its job it has to keep two things: enough about you to let you back into your account, and a record of what the sites you asked it to watch were doing. This page says what those are, how long they are kept, and what Owl Watch deliberately does not collect.

No analytics and no tracking

There are no analytics, no tracking pixels, no advertising, and no third-party scripts of any kind on this site or in the application. Nothing you do here is profiled, and nothing about you is sold, rented or shared for marketing.

The only cookies set are the ones that make a signed-in session work: a session cookie and a CSRF token, plus a "remember me" cookie if you ask for one. They are strictly necessary, which is why you are not asked to consent to them. Your light or dark theme preference and your chosen language are stored in your browser and on your account.

What is stored about you

  • Your account. Your name, your email address, a one-way hash of your password, and your language preference.
  • Sign-in security. If you turn them on, your two-factor secret, your recovery codes, and any passkeys you register. Secrets are stored encrypted.
  • What you asked to be watched. The hostnames, URLs, ports and mail servers you add, along with their schedules and check settings.
  • Where you asked to be told. Webhook addresses and their signing secrets, which are stored encrypted.

What is recorded about the sites you watch

  • Check results. Whether each check answered, how long it took, and the response code or error. These are kept for 35 days and then deleted; a daily summary of uptime and average response time is kept beyond that so the long history bars survive.
  • Public facts about your domains. Certificate details, domain registration and registrar data, nameservers, DNS records, mail authentication records, and the security-relevant headers your site returns. All of it is read from your own site or from public registries.
  • Changes. A check that finds the same thing as yesterday records nothing. Only changes are written down.

Owl Watch does not store the body of your pages. It reads a response to answer the question you set — a status code, or whether a keyword you chose is present — and keeps the answer, not the page.

Requests made on your behalf

When you add something to be watched, Owl Watch makes requests to it on the schedule you set, identifying itself in the User-Agent header as OwlKeeper/1.0 (+https://owlkeeper.com). Those requests appear in your own server logs. It also queries public sources to answer questions your site cannot: domain registry (RDAP) lookups, and DNS lookups made over Google's public DNS-over-HTTPS resolver. Only the hostname being checked is sent.

Email

Your email address is used to verify your account, to let you reset your password, and to send the alerts you have configured. There is no marketing email and no newsletter. Alerts are sent through a third-party email provider, which necessarily sees the address and the contents of the message.

Public status pages

If you publish a status page, anyone holding the link can see what is on it: the hostname, whether services are answering, uptime figures, recent incidents, and when the certificate and registration renew. It never shows monitor names, addresses, or anything from the security checks. The link is unguessable and the page asks search engines not to index it, but it is not protected by a password — treat it as public. You can withdraw it or issue a new link at any time, which stops the old one working immediately.

Who else can see it

Everything you add belongs to your team, and is visible to the members of that team. Beyond that, your data is not shared with anyone. It is processed by the infrastructure providers that host the application, its database and its outbound email — they act on instructions and do not use it for their own purposes.

Deleting your account

You can delete your account from your profile settings. Doing so removes your account and the monitoring data belonging to it. Some records may persist briefly in encrypted infrastructure backups before those are rotated out.

Your rights

You can see and correct your account details in the application at any time, export or request a copy of what is held about you, and delete it. If you are in the UK or the European Economic Area you also have the right to object to processing and to complain to your national data protection authority.

Changes

If this policy changes in a way that materially affects what is collected or who can see it, the date at the top of this page will change and you will be told by email before it takes effect.