Privacy Policy
Last updated: August 28, 2026
Platform Cert Check ("we", "the service") verifies TLS certificates against version-pinned platform trust stores. This policy explains what we collect when you use the service, why we collect it, and the choices you have.
1. What we collect
- Account data. When you register: your email address, name, and a hashed password. If you sign in with Google or GitHub, we receive the profile fields those providers share (name, email, avatar).
- Check data. The domains you check and the resulting reports (certificate subjects, issuers, validity dates, fingerprints, per-platform verdicts). Anonymous checks are ephemeral and discarded after the response; checks by signed-in users are stored as your history so you can revisit them.
- Monitoring data. Domains you register for monitoring, their daily sweep snapshots, and the alert emails sent to you about them.
- Billing data. Payments are processed by Stripe or Creem. We never see or store your card number; we store only your customer id, plan, and subscription status.
- Technical data. IP address (used for anonymous rate limiting), session cookies, and basic server logs.
- Product analytics. First-party usage events — pageviews (page path, referring site hostname, UTM tags) and product actions (running a check, signing up, adding a monitor, upgrading). Collected by our own servers only; there are no third-party trackers, advertising cookies, or cross-site identifiers. Anonymous events never include the domain you checked or your IP address.
2. What we do with it
- Provide the core service: run checks, keep your history, watch your monitored domains, and email you alerts you asked for.
- Enforce plan limits and prevent abuse (rate limiting, quota accounting).
- Process payments and manage your subscription.
- Understand aggregate product usage (funnel and volume trends) to improve the service.
We do not sell your data, show advertising, or use your checked domains for anything other than providing the service to you.
3. Certificates you paste
If you paste a certificate (PEM) instead of a domain, it is parsed in memory to produce the report. For signed-in users we store the certificate's public metadata (subject, issuer, fingerprints, validity) as part of the check record — never any private key, and you should never paste one.
4. Third parties
- Stripe / Creem — payment processing.
- Google / GitHub — optional sign-in providers.
- Resend — transactional email (alerts, verification, password reset).
Each provider processes data under its own privacy policy.
5. Retention & deletion
Check history is kept according to your plan (Free: last 5 checks; Pro: full history). Monitor snapshots are pruned to the most recent 30 per domain. You can delete monitored domains and API keys at any time from your dashboard. To delete your account and all associated data, contact us at the address below and we will erase it within 30 days.
6. Security
Passwords are stored hashed (Better Auth / scrypt). API keys are stored as SHA-256 hashes — the full key is shown only once at creation. All traffic is served over HTTPS in production.
7. Changes
If we change this policy materially, we will note the new date above and, for registered users, send an email notice.
8. Contact
Questions or deletion requests: support@tvbox-srv-certcheck.ichuanghi.com.