SSLup.io
Sign in Start free

Privacy

SSLup.io is operated by JAMD Technologies Inc. This page says what we collect, why we collect it, who else sees it, and what you can tell us to do with it. Last updated 10 August 2026.

The short version

Who we are

JAMD Technologies Inc (“we”, “us”) operates SSLup.io and is the controller of the personal data described here.

We are registered in Arizona, United States. For anything on this page — access, correction, deletion, or a question about how something works — write to privacy@sslup.io. It reaches a person, not a queue nobody reads, and we will give you a postal address on request.

What we collect, and why

Your account

An email address, and either a password we store only as a hash or an identifier from the sign-in provider you chose (Google, Microsoft or Apple). We never receive your password from those providers. Your organization is given a name based on your email address, which you can change.

We need this to give you an account and to send you the alerts you asked for. Legal basis: performance of a contract.

What you ask us to monitor

The hostnames, ports and protocols you enter, the groups you sort them into, and the results of checking them: certificate issuer, validity dates, key and signature details, the names on the certificate, TLS grade, whether the endpoint answered, and how long it took.

We also look up the registration of the domains you watch. We read the expiry date, status, registrar and nameservers. We do not read or store registrant contact data — not the name, address, phone number or email of whoever registered the domain — even when a registry publishes it.

Legal basis: performance of a contract.

People you tell us to alert

The names and email addresses of the contacts you add, and any Telegram chat IDs or webhook URLs you configure for Slack, Discord, Teams or your own endpoint. You are responsible for having a basis to give us a colleague’s address; we use it only to send the alerts and reports you set up.

Records of what happened

When you signed in and by which method, a log of changes made inside your organization, and — for actions taken by our own operators on your account — an audit record including the operator’s IP address. We record the IP address of failed invite-code attempts and of sales enquiries, to stop automated abuse of those two forms. Legal basis for those two: our legitimate interest in keeping the service usable.

Payment

Stripe processes payments. We store the Stripe customer and subscription identifiers, which plan you are on, whether you pay monthly or yearly, the status of the subscription, and when the current period ends. Card details are entered on Stripe’s own checkout page and never touch our servers.

Website analytics

Google Analytics 4 and Clicky, and only after you accept them in the banner. Until you do, consent is denied by default and no analytics script is loaded. Advertising storage is never granted at all.

Inside the application we trim the reported address to the site and path before sending it, so tokens from password-reset links, invite codes and any hostname you look up are never transmitted to an analytics provider. On the marketing site the query string is kept, because that is where campaign tags such as utm_source live.

Referral links are counted against a salted hash rather than an IP address.

AI reports

If you switch on AI analysis, we send your monitoring data — hostnames, ports, issuers, expiry dates, check results and certificate counts — to Anthropic‘s API to produce the written report. Your contacts’ names and email addresses are not included. The feature is off unless you enable it, and turning it off stops all such transfers.

Cookies

You can change your mind at any time by clearing the site’s cookies, which brings the banner back.

Who else sees your data

We use these processors, and no others:

Separately, we query public sources about the domains you watch: Certificate Transparency logs and the registries’ RDAP service. Those are lookups of public records about a domain name, not transfers of your personal data.

We will also disclose data if the law requires it. We will tell you when we are permitted to.

Where your data is held

Our servers are in the United States. If you are in the United Kingdom or the European Economic Area, using SSLup.io means your data is transferred there. Our processors listed above rely on the standard contractual clauses or an equivalent transfer mechanism.

How long we keep it

When you close your account, we delete your data from the live service.

Your rights

Wherever you are, you can email privacy@sslup.io and ask us to show you your data, correct it, export it, or delete it. We answer within 30 days and we do not charge for it.

If the UK GDPR or EU GDPR applies to you, you have the rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent for anything you consented to — analytics, in practice — without affecting what was done before you withdrew it. You may also complain to your supervisory authority; in the UK that is the Information Commissioner’s Office.

If you are a California resident, you have the right to know what we collect and why, to have it deleted, to have it corrected, and not to be treated differently for exercising any of those rights. We do not sell personal information, and we do not share it for cross-context behavioural advertising, so there is no opt-out for you to exercise — but if that ever changes this page will say so before it does.

Security

Traffic to the site is HTTPS only. Passwords are stored hashed, never in a form we can read. Each organization’s data is separated in the database and the application checks that boundary on every page that reads it. Configuration and credentials live outside the web root and are not reachable over the web.

No system is perfect. If you find a security problem, please write to privacy@sslup.io and we will treat it seriously.

Children

SSLup.io is a tool for people who run websites. It is not directed at children and we do not knowingly collect data from anyone under 16.

Changes

If we change this page in a way that affects you, we will say so here and, for anything material, by email before it takes effect. The date at the top is the last time it changed.