Monitorable
  • How it works
  • Product
  • Pricing
  • Docs
Sign inStart free
  • How it works
  • Product
  • Pricing
  • Docs
  • Sign in

Legal

Privacy Policy

What Monitorable collects from you and from the servers you monitor, where it lives, how long it stays, and how to get it deleted.

Last updated 4 October 2026

Monitorable is a server-monitoring service. To run it, we hold two kinds of data: a little about you (your account) and a lot about your servers (the metrics the collector sends). This page says exactly what that is, in plain language. Where it links to the docs, the docs are the detailed, maintained source.

Who is responsible

Monitorable is run by its founder, Anton, who is the controller of the personal data described here. Legal-entity details will be added to this page when the company is incorporated. For anything in this policy, write to hello@monitorable.io.

What we collect about you

Account data. When you sign in with Google or GitHub we receive your email address, display name, and avatar from the provider — nothing else, and we never see your password there. When you sign in by email we hold your email address and send it a one-time link and code. Your account is created on first sign-in; there is no separate registration form.

Organization and team data. Organization names, member roles, and the email addresses you invite.

Notification destinations. The addresses and endpoints you configure for alerts — an email address, a Telegram chat, a Discord, Slack, ntfy, or PagerDuty target, or a webhook URL.

Billing data. If you take a paid plan, our payment provider handles your card details; we never receive them. We store the plan you are on, its status, and the provider’s identifiers for your subscription and invoices.

Session and security data. A short-lived access token (60 minutes) kept in your browser, a refresh token (30 days) set as a cookie, and the time and address of sign-ins. We do not run analytics or advertising trackers on the dashboard or on this site.

Support correspondence. Whatever you send to hello@monitorable.io.

What we collect from your servers

The collector you install sends one batch a minute over HTTPS, plus an empty hourly check-in over IPv4 and over IPv6 that carries only the server’s key, and nothing else. The full field list is on What is collected; in summary:

  • Host metrics — CPU, memory, swap, disk usage and I/O, network throughput, load, uptime, temperatures.
  • Server details — hostname, OS and kernel version, and CPU model. The public IPv4 and IPv6 addresses the collector connects from are recorded and looked up against an offline geolocation database on our own servers; they are not sent to any third party.
  • Docker containers — container ID, name, image, state, health, exit code, and per-container resource use.
  • systemd services — unit names, states, and per-unit resource use.
  • Disk health (SMART) — drive model and serial number, health status, temperature, wear indicators.

The collector never reads process lists, command lines, environment variables, file contents, or logs. It runs as an unprivileged user, opens no listening ports, and its source is public so you can check this yourself.

You are responsible for what your servers contain. If a hostname, container name, or unit name on your servers includes personal data about someone else, that data reaches us as part of the metrics you chose to send.

Why we process it

  • To provide the service you signed up for (contract): accounts, metrics storage, dashboards, alert evaluation, and delivering alerts to the destinations you configured.
  • To keep the service secure and working (legitimate interest): sign-in records, abuse prevention, error logs, capacity planning.
  • To bill you (contract and legal obligation) on paid plans.
  • To answer you when you write to us (legitimate interest).

We do not sell personal data, use it for advertising, or train models on your metrics.

Where it lives

The platform — the database, the metrics store, and the dashboard backend — runs on dedicated servers we operate in France, in the European Union. Downloads of the collector are served from EU-jurisdiction object storage.

We use a small number of processors to run the service:

ProcessorPurposeLocation
CloudflareNetwork edge in front of the dashboard, this website, and collector downloads (DDoS protection, TLS, caching)Global edge; EU-jurisdiction storage for downloads
Scaleway (Transactional Email)Sending sign-in codes, invitations, and alert emailsParis, France
CreemCheckout, invoicing, and subscription management for paid plansEU
Google, GitHubIdentity providers, only if you choose to sign in with themPer their own policies
Telegram, Discord, Slack, ntfy, PagerDuty, or your webhook endpointDelivering alerts, only to the destinations you configurePer the destination you chose

Alert messages contain the server name, the rule that fired, and the measured value. Configuring a destination is your instruction to send those messages there.

Metrics traffic from your servers to ingest.monitorable.net goes directly to our servers in France and does not pass through Cloudflare.

How long we keep it

  • Metrics are stored at two levels of detail: per-minute data for 35 days and hourly summaries for 400 days, after which they expire automatically (see Metrics history). Each plan states the metric-history period it offers on the pricing page.
  • Server details and snapshots (containers, services, disk health) are kept for as long as the server exists in your account.
  • Removing a server revokes its API key and deletes its details and snapshots immediately; there is no undo. Its metric history is no longer reachable from the dashboard and is not purged at that moment — it is deleted when the retention period above ends.
  • Account data is kept while the account exists.
  • Refresh tokens expire after 30 days; expired tokens are purged.
  • Billing records are kept for as long as tax law requires.

Your rights

Under the GDPR and comparable laws you can ask us to access, correct, export, restrict, or delete your personal data, and you can object to processing based on legitimate interest. To delete your account and everything in it, email hello@monitorable.io from the account’s address; we confirm the deletion in writing. You can also lodge a complaint with your local data-protection authority.

Metrics and server metadata are yours: you can see them in the dashboard at any time and ask us for a copy in an open format. Removing a server takes it out of your account at once and its metric history expires on the schedule above; deleting your account removes everything from ours.

Cookies

The dashboard sets one cookie, holding the refresh token that keeps you signed in. It is HttpOnly, Secure, and is cleared when you sign out. This website sets none of its own. Cloudflare may set the strictly necessary cookies it uses to protect the site. There are no analytics, advertising, or cross-site tracking cookies.

Security

Metrics travel over TLS. API keys are stored hashed. Tenancy is enforced on every query, not only at the edge. The collector runs unprivileged and its requirements and permissions are documented. If you find a vulnerability, please follow the security policy.

Children

Monitorable is a business tool and not directed at children under 16. We do not knowingly collect their data.

Changes

When this policy changes in a way that matters, we will note it here with a new date and, for significant changes, tell account holders by email before the change takes effect.

Monitorable

We watch, so you don’t have to.

Built on OpenTelemetry

Product

  • How it works
  • The product
  • Pricing

Resources

  • Docs
  • Quick start
  • Agent source

Company

  • Contact
  • Privacy
  • Terms
© 2026 MonitorableDedicated servers we operate in France.