Privacy Policy
Last updated August 30, 2026
Expiroo is a domain and website monitoring service. This page explains what data we collect to run it, why, who we share it with, and the rights you have over it.
What we collect
Account information
Your email address, and your name if you provide one, when you create an account. Your password is never stored in plain text (see Security).
Domain and monitoring data
The domains and URLs you add for monitoring, and the data we look up about them: expiration dates, registrars, DNS records, SSL certificate details, uptime status, and the content checks you configure. This data is looked up from public registry sources (WHOIS/RDAP) and from the websites you ask us to monitor, not from anywhere private.
Usage data
Basic technical data needed to run the service: IP addresses (used for rate-limiting the free tools and abuse prevention, not stored long-term as part of your account), login timestamps, and an audit log of account actions (domain added, plan changed, and similar) kept for security and support purposes.
Cookies and tracking
Essential cookies (like your login session) are required for the site to work and aren't optional. Analytics and advertising cookies, Google Analytics and, where an administrator has connected it, the Facebook Pixel, only load after you accept them in the cookie banner. See ourCookie Policy for the full list and how to change your choice at any time.
Chrome Extension
This section covers the Expiroo Chrome extension specifically, in addition to everything above, which applies to the Expiroo product as a whole.
What the extension accesses
The extension reads the current tab's URL only at the moment you actively click the extension icon (Chrome's activeTabpermission). It does not run in the background, does not track your browsing history, and does not read the content of any page you visit, only the domain of the tab you're on when you click it.
When you click the icon, the extension sends that domain to Expiroo's API to look up its registrar, expiry, DNS, and SSL data, the same lookup our public free tools perform from a web form, just triggered from your browser toolbar instead.
Account connection
The extension only works once you explicitly connect your Expiroo account through expiroo.com/extension/connect. Once connected, the extension authenticates with a dedicated access token tied to your account, not your password and not your normal web login session. That token can only look up domain data and add domains to your monitored list, it cannot change your password, billing, or plan.
You can see every device or extension connected this way, and revoke any of them individually, at any time, fromAccount Settings → Connected Apps in your Expiroo dashboard. Revoking a connection takes effect immediately, the very next request the extension makes with that token is rejected.
What the extension does not do
The extension does not collect or store your browsing history, does not inject any script into the pages you visit, does not read page content beyond the domain itself, and does not share your data with any third party beyond what's already disclosed elsewhere in this policy for the core Expiroo product (see "Who we share data with" below, e.g. our infrastructure provider).
Data retention (extension)
Domain lookups performed through the extension are not logged or stored anywhere, they're looked up live and returned to the popup, the same as a lookup on our public tools pages. The extension's connection token itself (its hashed value, never the raw token) is kept for as long as the connection stays active, and is retained in revoked form as a historical record after you disconnect it, until you delete your account entirely, at which point it's deleted along with the rest of your account data.
How your data is stored
Account and monitoring data lives in a Cloudflare D1 database. Sensitive credentials our system holds on your behalf, such as payment provider API keys an administrator connects, are encrypted at rest with AES-256-GCM, never stored as plain text. Passwords are hashed, never stored or logged in a recoverable form (see Security for detail). All traffic to and from Expiroo is encrypted in transit (HTTPS).
Who we share data with
We share the minimum data needed with the following categories of service, and only for the purpose of running Expiroo:
- Payment processors (Stripe, PayPal), to process subscription payments. They receive what's needed to bill you; we don't store your full card details ourselves.
- Notification providers (Telegram, WhatsApp via Meta or Twilio, and our email provider), only if you connect that channel, to deliver the alerts you asked for.
- Advertising and analytics platforms (Google Analytics, Facebook), only after you accept analytics/marketing cookies, and only aggregate/behavioral data, never your monitored domain data or account credentials.
- Infrastructure providers (Cloudflare), who host the application and database. They process data on our behalf under their own security commitments.
We do not sell your data to anyone.
Your rights
You can access, export, or delete your data at any time. Deleting a domain or monitor removes it and its history immediately. To close your account entirely, use the account deletion request in your dashboard settings, or email us atalerts@expiroo.com. If you're in the EU/EEA or UK, you have rights under the GDPR (access, correction, deletion, portability, and objection to processing). The same request path covers these.
Data retention
We keep account and monitoring data for as long as your account is active, plus a reasonable window after deletion for backups and fraud prevention. Audit log entries are kept for security accountability and aren't deleted when a related record (like a domain) is removed.
Changes to this policy
If this policy changes materially, we'll update the date at the top of this page and, where required, notify you directly.
Contact
Questions about this policy or your data: alerts@expiroo.com.