Privacy Policy

Last updated: June 26, 2026

This Privacy Policy explains what information SSLRadar collects, how we use it, and the choices you have. We aim to collect as little as possible to run a free SSL certificate checker and monitoring service.

Information we collect

  • Account information — your email address, and (if you sign in with Google or GitHub) your name and avatar provided by that service. A display name is otherwise derived from your email.
  • Domains you check and monitor — the domain names you submit, and the public certificate metadata we retrieve for them (issuer, validity dates, covered names, etc.).
  • Approximate location — a two-letter country code derived from your network, provided by our CDN (Cloudflare) via request headers. We do not collect precise location.
  • Technical data — your IP address, browser information, and server logs, used for security, rate limiting, and abuse prevention.
  • Cookies — essential cookies needed for sign-in and session security. We do not use third-party advertising cookies.

How we use information

  • To provide the Service — checking certificates and monitoring the domains in your account.
  • To send you transactional emails, including SSL certificate expiry alerts for domains you monitor.
  • To secure the Service, enforce rate limits, and prevent abuse.
  • To understand usage in aggregate and improve the Service.

We do not sell your personal information.

Public information

SSLRadar is a public tool. Domains checked through it may appear in public areas such as the "Recently checked" list and shareable report pages at /domain/<name>. These pages show only public certificate information — never your account details. If you do not want a domain to appear on these public boards, use the "Don't show on public boards" option on the domain's report page.

Service providers

We share limited data with trusted providers only as needed to operate the Service:

  • Cloudflare — content delivery, security, and the country code described above.
  • Amazon Web Services (Amazon SES) — to deliver account and expiry-alert emails.
  • Google and GitHub — only if you choose to sign in with them, to authenticate your account.

Data retention

We keep account and monitoring data while your account is active. Public check records are retained to power the recent-checks feature. You can delete your account at any time from your settings; doing so removes your account and the domains you monitor.

Your rights

  • Access or update your account information from your settings.
  • Delete your account, which removes your personal data and monitored domains.
  • Hide any domain from public boards as described above.
  • Depending on your location, you may have additional rights under laws such as the GDPR or CCPA. Contact us to exercise them.

Security

We use industry-standard measures to protect your data, including encryption in transit and hashed passwords. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Children

The Service is not intended for children under 16, and we do not knowingly collect personal information from them.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above.

Contact

Questions about your privacy? Email us at [email protected].