Privacy Policy

Last updated: 23 August 2026

This policy explains what ApiMoni collects, why, who it is shared with, and what control you have over it. It describes the service as actually built — where a practice differs from what you might assume, we say so plainly.

1. Who we are

ApiMoni (“we”, “us”) is an API monitoring service operated by Tuncay Altinpulluk. We are the data controller for the personal data described in this policy.

For any privacy question or request, contact us at support@apimoni.com.

2. What we collect

Account information

When you register we store your first name, last name and email address, along with your plan tier, the time your account was created and the time you last signed in. If you register with a password, we store only a bcrypt hash of it — never the password itself.

Google sign-in

If you choose “Sign in with Google”, Google sends us a signed token containing your Google account identifier, your email address, whether Google has verified that address, and your first and last name. We request only the openid, email and profile scopes. We never see your Google password, and we have no access to your Gmail, Drive, Calendar, contacts or any other Google service.

We store the Google account identifier so we can recognise you on your next visit. If the email address on your Google account matches an existing ApiMoni account, we link the two so you can use either sign-in method for the same account.

The monitoring you configure

We store what you enter when you set up an endpoint: its name, URL, HTTP method, expected status code, check interval, timeout, response-time threshold, any keyword you want matched, your alert settings, and any notification email address you provide.

This includes any request headers and request body you configure, stored as you entered them and not encrypted at rest. If you put an API key, bearer token or other credential in a request header so that ApiMoni can reach a protected endpoint, that credential is held in our database in readable form. Please use a dedicated, least-privilege credential for monitoring, and rotate it if you stop using ApiMoni.

Monitoring results

Each check writes a record containing the time, whether it succeeded, the HTTP status code, the response time in milliseconds, and any error message. We also store up to 5,000 characters of the response body so failures can be diagnosed. If your endpoints return personal data, that data will be present in these records — point ApiMoni at health-check or status endpoints rather than at endpoints that return real user records.

For endpoints with TLS certificate monitoring enabled, we additionally store the certificate’s expiry date, issuer and subject.

Messages you send us

If you use the contact form, we receive the name, email address and message you submit, and forward them to our support inbox.

Technical data

Our servers keep standard web logs, which include IP addresses, and we use the IP address of incoming requests to apply rate limits. We do not build profiles from this data.

3. Cookies and local storage

We use no analytics, advertising or tracking cookies of any kind. There is no Google Analytics, no tag manager, no advertising pixel and no third-party tracker on this site. The only cookies we set are the two that keep you signed in:

CookiePurposeLifetime
jwtKeeps you signed in between requests60 minutes
refreshTokenRenews your session without asking you to sign in again7 days, or 30 days if you tick “Remember me”

Both are HttpOnly, so page scripts cannot read them, and both are marked Secure and SameSite=Strict in production. They are strictly necessary to operate the service, so we do not ask for consent to set them. Signing out clears both.

Your browser also caches your name and email in local storage so the interface can render immediately on load. Signing out removes it.

4. How we use it, and on what basis

  • To provide the service — creating your account, signing you in, running your checks, storing their history and sending alerts. Legal basis: performance of our contract with you.
  • To keep the service secure and available — rate limiting, abuse prevention and diagnostics. Legal basis: our legitimate interest in a secure service.
  • To respond to you when you contact us. Legal basis: performance of our contract or our legitimate interest in answering enquiries.
  • To send service email — a welcome message and the alerts you have configured. These are operational, not marketing. We do not send marketing email, and we do not sell, rent or share your data with advertisers.

5. Who we share it with

We do not sell your personal data. We share it only with the following processors:

  • MailerSend — delivers our transactional email. Receives the recipient address and the message content of alerts and account email.
  • Google — only if you use Google sign-in. Google will know that you signed in to ApiMoni. See the Google Privacy Policy.
  • Our hosting provider, Namecheap Inc., which operates the server our application and database run on in Atlanta, Georgia, United States.

We may also disclose data where we are legally required to, or to establish or defend legal claims.

6. International transfers

Our servers are in Atlanta, Georgia, United States, and we are established in Türkiye. If you are in the UK or EEA, using ApiMoni therefore involves transferring your personal data out of that region as a matter of course — to the United States, where it is stored and processed, and to Türkiye, from where the service is operated. Neither is covered by a UK or EU adequacy decision for our purposes. The processors listed in section 5 may also process data outside the region.

For each of these transfers we rely on the transfer mechanism the provider concerned makes available. We are currently confirming the exact mechanism relied on for each processor and will state it here once we have; in the meantime, ask us at support@apimoni.com and we will tell you what applies to a particular provider.

Because we are established in Türkiye, transfers abroad are also subject to Turkish data protection law (KVKK), which has its own regime for sending personal data outside Türkiye.

7. How long we keep it

Account information is kept for as long as your account exists. Endpoint configuration and its monitoring history are kept until you delete the endpoint or ask us to delete your account. Deleting an endpoint deletes its entire monitoring history with it.

Each plan states a monitoring-history retention window — 30 days on Free, 90 days on Premium and 365 days on Enterprise. These windows describe the history we undertake to keep available to you; we do not currently run automatic deletion of older records, so history may be retained beyond the window until you delete the endpoint or ask us to remove it. We will update this section when automatic deletion is in place.

8. Your rights

Depending on where you live, you have the right to access the personal data we hold about you, to correct it, to have it deleted, to receive a copy in a portable format, to object to or restrict certain processing, and to withdraw consent where we relied on it.

You can view and correct your endpoint configuration at any time in the app, and delete any endpoint together with its history. There is currently no self-service button to delete your whole account — email support@apimoni.com and we will erase your account and all associated data. We aim to respond within 30 days.

If you are in Türkiye, these rights arise under KVKK, which additionally gives you the right to learn whether your data has been processed, to ask who it has been disclosed to at home or abroad, to have any inaccuracy notified to those recipients, and to object to a decision reached solely by automated analysis. We make no automated decisions about you.

If you are in the UK or EEA and are unhappy with how we have handled your data, you may complain to your local supervisory authority. In Türkiye, you may apply to us first and then complain to the Personal Data Protection Authority (KVKK).

9. How we protect it

  • All traffic to the site and API is encrypted with TLS.
  • Passwords are stored only as bcrypt hashes.
  • Session tokens are held in HttpOnly cookies that page scripts cannot read.
  • The database is not reachable from the public internet; it accepts connections only from the application on the same host.
  • Requests are rate limited to blunt brute-force and abuse.

As noted in section 2, endpoint request headers and bodies are stored without encryption at rest. No system is perfectly secure, and we cannot guarantee absolute security.

10. Children

ApiMoni is a tool for developers and businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

11. Changes to this policy

We may update this policy as the service changes. The “last updated” date at the top always reflects the current version, and we will tell you by email before any change that materially reduces your rights takes effect.

12. Contact us

Questions, requests or complaints: support@apimoni.com, or use the contact form. See also our Terms of Service.