Monitora

Privacy Policy

How Monitora collects, uses, retains, and protects your personal data, and the rights you can exercise over it.

Effective

1. Scope

This policy covers personal data Monitora processes for account holders — the people who register and operate Monitora. Operational telemetry you collect about your own infrastructure through the agent is your content: you are its controller and Monitora acts as a processor. This policy governs the account and identity data for which Monitora is the controller.

2. Data we process

We process only what the service needs to operate and to keep your account secure:

  • Identity — email address and display name, for authentication and transactional email.
  • Credentials — your password is stored only as a BCrypt hash; any TOTP secret is encrypted (AES-GCM) and recovery codes are hashed.
  • Verified contacts — additional email addresses you verify for alert routing.
  • Sessions — session id, device/user-agent, IP address, and last-seen time, used for session management and abuse detection.
  • Subscription — your plan, quota, and payment/invoice references.
  • Security & audit — a record of privileged administrative actions, for accountability.

We do not sell personal data and do not process special-category data.

3. How long we keep it

Active accounts are kept for the life of the account. When you delete your account it is first soft-deleted and stays recoverable for a grace window, after which it is irreversibly anonymized.

  • Retention window: 30 days. After this period a background job permanently scrubs your personal data (email, display name, credentials) and removes your sessions, tokens, and verified emails.
  • Single-use tokens (email verification, password reset, email change) are hashed, expiring, and purged once used.
  • Sessions are revoked on logout, password reset, or email change, and removed at anonymization.
  • The administrative audit trail is retained for accountability and carries no link to your identity once your account is anonymized.

4. Your rights

You can exercise your data-protection rights directly from the app or by contacting us:

  • Access & portability — download a complete copy of your account data as JSON from Settings → Privacy.
  • Erasure — request account deletion from Settings; your data is anonymized after the retention window.
  • Rectification — update your profile and change your verified email address at any time.
  • Restriction, objection, and withdrawal of consent — contact us using the details below.

You also have the right to lodge a complaint with your local data-protection supervisory authority.

5. How we protect your data

  • Passwords are hashed with BCrypt; two-factor secrets are encrypted and recovery codes hashed.
  • Access tokens are individually revocable, and optional two-factor authentication can be enforced at login.
  • Brute-force rate limiting protects authentication and administrative endpoints.
  • Agents are pull-only and IP-bound — they never expose an inbound port.
  • Secrets are injected at runtime and never committed; dependency and secret scans gate every deploy.
  • Data is encrypted in transit (TLS), and the database is backed up with a tested restore procedure.

6. Sub-processors & data location

We rely on a small set of sub-processors — infrastructure hosting (including managed Postgres), a transactional email provider, and, when enabled, a payment provider. Data is processed within infrastructure located in the European Union.

7. Contact

For privacy questions or to exercise any of your rights, contact us at privacy@monitora.codexa.it.com. We action requests within the timeframe required by applicable law.

See also our Terms of Service.