Privacy
Last updated October 5, 2026
What we keep about you
- Your email address, and an alert address if you add one and confirm it.
- Your password, stored only as a salted scrypt hash. We can’t read it.
- The domains and keywords you monitor, the lookalikes we find for them, and what you do with each one (dismiss, mark as yours).
- Sign-in sessions: a hashed session token and when it was last used.
- Your IP address, only as part of rate limits on sign-in and similar actions. These records are deleted after a day.
What we check about other domains
To find lookalikes we read public Certificate Transparency logs, query public DNS, ask domain registries for registration dates, and load the home page of each lookalike to see whether it is live or parked. None of this involves your personal data.
Your password and breached passwords
When you choose a password we check it against known data breaches using Have I Been Pwned’s range service. Only the first five characters of the password’s SHA-1 hash are sent; the password itself never leaves our server.
Who processes data for us
- Vercel hosts the website.
- Render runs the monitoring service and the database, in the United States (Virginia).
- Resend delivers our emails.
- Stripe processes payments. Your card details go to Stripe directly and never reach our servers; we keep only your Stripe customer ID and subscription status.
We don’t sell your data, show ads, or use analytics or tracking tools.
Cookies
One cookie keeps you signed in. It ends after 30 minutes without activity and after 12 hours at most. A second cookie stores your time zone so your daily log uses your days. There are no other cookies.
How long we keep it
Until you delete your account. Deleting it in Settings removes your account, domains, keywords and findings immediately. Copies of emails we sent are kept for 30 days.
Contact
Contact details for Typowatch will be published here before launch.