Privacy Policy
Last updated: July 1, 2026
This Privacy Policy (“Policy”) explains how TLS Radar (“we”, “us”, or “our”) collects, uses, stores, and protects your personal information when you access or use our monitoring platform and related services (“Service”). By using the Service, you agree to the terms of this Policy. If you do not agree, you must discontinue using the Service.
1. Information We Collect
We collect personal and technical information necessary to provide and improve the Service, including:
- Account Information: Email address, password (encrypted), optional first and last name, and social login data (Google, Microsoft, GitHub).
- Monitoring Data: Domains and IP addresses associated with your account for TLS and uptime monitoring.
- Payment Data: Stripe manages all payment information. TLS Radar stores transaction identifiers and billing details necessary to verify payments.
- Technical Data: Cookies, device information, browser type, log files, and usage analytics to enhance performance and user experience.
- Plugin & Anonymous Usage Data: When you use our Claude Code or Claude Cowork plugin, or our public tools, we may collect the domains you scan and—if you request free certificate issuance—the domain and the email address you provide, even if you do not have an account. We also generate an anonymous installation identifier to measure aggregate plugin usage; it identifies an installation, not a person, and you can opt out by deleting it locally.
We do not knowingly collect data from users under the age of 13. If we learn that we have inadvertently collected such data, it will be promptly deleted.
2. How We Use Your Data
We use the information we collect for the following purposes:
- To create, manage, and authenticate user accounts.
- To deliver monitoring, alerting, and reporting functionalities.
- To issue Let’s Encrypt certificates you request, and to send a one-time follow-up email about monitoring a certificate you issued. We send further marketing communications only if you opt in.
- To process payments, subscriptions, refunds, and account upgrades.
- To provide customer support and improve Service performance.
- To conduct usage analytics for UI/UX improvements and reliability optimization.
- To comply with legal obligations and respond to lawful requests from authorities.
We do not use your data for targeted advertising, user profiling, or selling to third parties.
3. Data Sharing and Disclosure
Your data may be shared only in the following limited circumstances:
- Payment Processing: With Stripe, for secure handling of billing and subscription transactions.
- Analytics Providers: With Google Analytics and PostHog, for usage analytics and product insights.
- Error and Performance Monitoring: With Sentry, to detect, diagnose, and resolve errors and performance issues.
- Hosting: With Hetzner, our infrastructure provider, which hosts our servers and stored data in the United States.
- Content Delivery and Security: With Cloudflare, which provides CDN, DNS, and security (DDoS and bot protection) services and processes network traffic, including IP addresses, to deliver and protect the Service.
- Certificate Issuance: With Let’s Encrypt (a third-party certificate authority) and our certificate-issuance backend, we share the domain and certificate signing request (CSR) necessary to issue a certificate you request. Certificate private keys are generated on your device and are never transmitted to us.
- Legal Compliance: In response to valid requests by public authorities or to comply with legal obligations.
We do not sell or rent personal data to third parties for marketing or commercial gain.
4. Data Storage and Retention
Your data is stored securely on servers operated by Hetzner, located in the United States (Ashburn, Virginia). We implement our own technical and organizational security measures, described in Section 6, in addition to those provided by our hosting provider. TLS Radar retains personal information for as long as necessary to provide the Service or as required by applicable laws.
If you delete your account, associated personal data will be permanently erased within thirty (30) calendar days, though residual data may persist in backups for up to one (1) year.
5. International Data Transfers
TLS Radar operates from and stores data in the United States. If you access the Service from outside the United States - including Canada or elsewhere - you acknowledge that your personal data will be transferred to and processed in the United States, which may have data-protection laws different from those in your country. We rely on our hosting provider's infrastructure and standard industry safeguards for data hosting and protection.
6. Data Security
We implement robust technical and organizational measures to safeguard your data, including:
- Encryption of passwords and sensitive user identifiers.
- Strict access controls and authentication requirements.
- Secure communications using HTTPS/TLS encryption.
- Continuous system monitoring and auditing for vulnerabilities.
Despite these measures, no system is completely secure. You acknowledge that the transmission of data over the Internet carries inherent risks, and TLS Radar cannot guarantee absolute security.
7. Cookies and Tracking Technologies
We use cookies and similar technologies to enable essential Service functionality, maintain sessions, and improve performance. Types of cookies used include:
- Necessary Cookies: Required for authentication, core platform features, and security (including cookies set by Cloudflare to protect the Service).
- Analytics Cookies: Used by Google Analytics and PostHog to collect usage metrics.
- Marketing Cookies: May be used for internal product insights and remarketing efforts.
By continuing to use our website, you consent to the use of these cookies. We do not currently provide a separate cookie consent mechanism.
8. User Rights
Users in applicable jurisdictions - including California under the CCPA/CPRA and Canada under PIPEDA - have the right to:
- Access, correct, or update their personal data.
- Request deletion of their account and associated data.
- Withdraw consent for data processing (where applicable).
You may exercise these rights directly through your account settings within the Service interface.
9. International Users and Compliance
TLS Radar is operated from the United States and primarily serves users in the United States and Canada. We honor the core data rights described in Section 8 - access, correction, and deletion - for all users regardless of location. Where the California Consumer Privacy Act (CCPA/CPRA) or Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) applies to you, we comply with the rights and obligations those laws require. We do not currently direct the Service to, or target users in, the European Economic Area; if that changes, this Policy will be updated to address the GDPR and applicable transfer mechanisms.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this Policy, and material changes will take effect no earlier than the date posted. We encourage you to review this Policy periodically. TLS Radar may, at its discretion, send optional email notifications about significant changes.
11. Contact and Inquiries
If you have any privacy-related questions, concerns, or requests, please reach out via the contact form available on our website. We do not maintain a public email for privacy inquiries.
TLS Radar LLC. is the data controller for the Service. Our registered address is:
TLS Radar LLC.30 N Gould St Ste N
Sheridan, WY 82801
United States
Thank you for trusting TLS Radar to help secure and monitor your websites.