CheckSSLExpiry
Checker Expiry Tool API MCP Blog FAQ About Contact Manage
Free Forever
🔍
SSL Checker Instant TLS & Expiration Check
⏳
Expiry Calculator Countdown & Exact Expiration Dates
📜
CAA Policy Inspector DNS RFC 8659 & Authorized CAs
🛡️
HTTPS Security TLS Protocol & Cipher Inspector
📚
Blog & Comparisons 20 Guides, Error Fixes & Tutorials
❓
Technical FAQ Answers on ACME, 45-day & Alerts
⚡
Developer REST API Free API v1, CORS & Code Snippets
🤖
MCP Server for AI Claude Desktop, Cursor & Agent Tools
🏢
About Us Mission, Architecture & Zero-Login Ethos
✉️
Contact & Support Bug Reports, Inquiries & Disclosure
⚙️
Manage Monitors Passwordless Alert Dashboard
100% Free Forever • Zero Passwords
TRANSPARENCY & DATA HYGIENE

Privacy Policy

Effective Date: February 16, 2025 • Version 2.0

1. Introduction & Core Philosophy

At CheckSSLExpiry (operated at https://checksslexpiry.com), we believe privacy is an absolute engineering requirement, not an afterthought. Our platform is architected from the ground up to operate without user accounts, passwords, or persistent tracking cookies.

This Privacy Policy explains what minimal information we collect, how it is used exclusively to deliver SSL/TLS certificate monitoring services, and how you retain 100% control over your data.

2. What We Collect and Why

We practice strict data minimization. We only collect the minimal technical data necessary to provide the service:

  • Instant Certificate Checks: When you perform a real-time check, we connect to the submitted domain on port 443. We do NOT store your query history, search terms, or client IP address in any persistent database.
  • Email Monitoring Enrollment: When you choose to receive automated expiration alerts for a domain, we store:
    • The target domain name or hostname (e.g. example.com).
    • Your verified notification email address.
    • The certificate's public metadata (SHA-256 fingerprint, issuer, expiration timestamp).
    • Notification state tracking counters (to ensure deduplication so you receive at most one alert per threshold milestone).
  • Abuse Prevention & Rate Limiting: We temporarily process client IP addresses in volatile memory and short-lived sliding-window caches (Cloudflare KV/D1) to prevent Denial-of-Service (DDoS) attacks and malicious automated scraping. These records expire automatically within minutes.

3. What We Never Collect or Access

  • No Passwords or Account Credentials: We do not have a user registration database, password fields, or account profiles.
  • No Private Keys or Server Files: We only inspect the public X.509 certificate presented during a standard TLS handshake. We never ask for, access, or store private keys, SSL certificates' private key files, SSH keys, or server credentials.
  • No Third-Party Tracking Pixels: We do not use intrusive cross-site tracking cookies, behavioral tracking scripts, or fingerprinters.

4. Cryptographic Token Security

To protect your monitoring management endpoints without passwords, we generate high-entropy 256-bit cryptographically secure random tokens (via crypto.getRandomValues).

Raw tokens are never stored on our servers. We store only the irreversible SHA-256 hash of the token in our database. When you click an access link in your email, our system hashes the token and compares it in constant-time against the stored hash.

5. Email Communications & Anti-Spam Guarantee

We only send transactional emails relating directly to your certificate monitoring:

  • Verification links upon enrollment.
  • Advance expiration warnings (30, 14, 7, 3, 1 days & day 0).
  • Certificate renewal confirmation notices.
  • Requested passwordless dashboard access links.

We will never sell, rent, or trade your email address to third-party marketing companies, data brokers, or advertisers.

6. Data Deletion & Right to Be Forgotten (GDPR / CCPA)

You maintain complete ownership of your data. You can delete individual monitors or purge your email and all associated monitoring records completely at any time:

  • Clicking the direct 1-click Unsubscribe link included in the footer of every notification email.
  • Visiting the passwordless Management Dashboard and clicking Delete on any domain.

Deleting a monitor immediately and permanently purges the record from our database without soft-deletes or retention holding periods.

7. Non-Intrusive Advertising & Infrastructure Funding

CheckSSLExpiry is 100% free forever without paid subscription tiers. To support infrastructure and network bandwidth costs, we may display unobtrusive, privacy-friendly advertisements that do not use invasive cross-site profiling.

8. Contact & Privacy Inquiries

If you have any questions, suggestions, or data requests regarding this Privacy Policy, you can submit feedback directly via our or email us at privacy@checksslexpiry.com.

CheckSSLExpiry

Instant public SSL/TLS certificate inspection and passwordless 24/7 expiration alerts. 100% free forever without accounts or paywalls.

Micro-Tools

  • SSL Checker
  • Expiry Calculator
  • CAA Policy Inspector
  • Certificate Inspector
  • HTTPS Security

Resources & Developers

  • Developer REST API
  • Model Context Protocol (MCP)
  • Security Blog & Guides
  • Technical FAQ
  • About Us
  • Contact & Support
  • Privacy Policy
  • Terms of Service

© 2026 CheckSSLExpiry (checksslexpiry.com). Built for developers, site owners, and sysadmins.

🛡️ 100% Free & Passwordless
Developer Feedback

Report a Bug / Feedback

Found a domain check issue, incorrect parsing, or have a feature request? Let us know.

Thank You for Your Feedback!

Your feedback helps us make CheckSSLExpiry the most accurate and reliable certificate monitoring tool on the web.