Skip to content
Bionic Uptime

Privacy

What we collect, why, how long we keep it, and who else sees it. If a sentence here is vague, treat that as a bug and tell us.

What we collect about you

Your email address, because it is how you sign in and where alerts go. If you set a different address for alerts, we keep that too, and we do not use it until you have confirmed it from that inbox. Your timezone, so times read correctly. That is the whole list of things you tell us about yourself.

If you add someone else to a website's alerts, such as your client, we keep their email address. We send them one email asking them to confirm, and nothing else until they do. Every alert they get has a link that stops them at once, with no account needed, and you can see on the website's page that they stopped. Their address is removed when you remove them or the website.

If you write to us from the support page, your address and your message reach us as an email. We keep that email for as long as the conversation needs it, and it is not added to any account or list.

We do not ask for your name, your company, a phone number or a card until you upgrade, and we have no field to type any of them into.

What we collect about your websites

The addresses you ask us to watch, and the result of every check: whether it answered, the status code, how long it took, and the certificate expiry date. We record which of our two locations made each check, because that is the evidence behind any outage we report. Once a day we also read the public registration record (RDAP) for each website's domain name and keep its expiry date, so we can remind you before it runs out.

Each website can have a public status page. It is off until you turn it on. While it is on, anyone with its link can see the website's name and address, whether it is up, when it was last checked, and its confirmed outages and monitoring gaps from your history. It never shows your email address, who gets your alerts, or your other websites. Search engines are told not to list it. Turning it off, or making a new link, stops the old link working.

We do not store the content of your pages. We request the address and note what came back; nothing from the response body is kept.

If you ask us to check that a page says something — or that it never says something — we keep the phrase you typed, because it is part of what you asked us to watch. When we check, we read the page as your server sends it and look for that phrase. We record only whether it was there. The page itself is discarded the moment we have that yes or no, and it is never written down, sent anywhere or shown to anyone.

The phrase itself is not secret from you: it appears in your alert emails, in the incident record and in your CSV export, because it is the evidence for why we called something an outage. Do not use a password or a token as the phrase.

If you make a status key for our WordPress plugin, we keep a one-way hash of the key, its last four characters, and the day it was last used. We never keep the key itself. The plugin's requests name your WordPress site's address, and we use them only to answer with that one website's status.

Visits to this website

We count visits to our own public pages, first-party, with no cookies and no third-party analytics. Nothing about a visit leaves our server, except the one case described under Meta below. We store the page, the time, the referring site if there is one, and a one-way hash of the address and browser that is re-salted every day, so the same person counts once per day and cannot be recognised tomorrow or identified afterwards.

We do not count anything while you are signed in, and we do not use these counts for advertising.

How long we keep it

These are enforced by a job that runs every day, not by us remembering. Backups are kept for 14 days and age out on their own.

Who else sees it

Nobody else. We do not sell or rent your data, and there is no advertising network script, tracking pixel or session recorder on this site.

What you can do

Export everything we hold about your monitoring as a CSV from your account page, at any time, without asking us. Delete your account from the same page, which removes your websites and their history. Change the address alerts go to. If you want something we have not built a button for, email us and we will do it by hand.

Where it lives

On servers in the United States. Our two checking locations are in Chicago and New Jersey, deliberately with different providers on different networks, so one outage cannot take both out and manufacture a false alarm.

Changes and contact

If this changes we will say what changed rather than only moving the date. Questions, requests or complaints: write to us from the support page.

Last updated 22 September 2026: added what happens to a message sent from the support page.