Last updated: July 19, 2026
Middle Monitor is an observability platform: our customers send us operational data about their own systems so they can monitor them. This policy explains what data we handle, why, where it is stored and what rights you have.
When you create an account we collect your name, email address and a password. Passwords are stored hashed and are never readable by us. Organization details you provide (organization name, members, roles) are stored to operate your workspace.
The core of the service is telemetry that your systems send through the agent, the SDKs or the API: traces, metrics, logs, error reports, profiles and host information.
You control entirely what is sent. Telemetry may embed personal data if your applications include it in logs or error messages; we process such data on your behalf and on your instructions, as a processor.
Do not send secrets (API keys, passwords, tokens) in telemetry. Configure your applications to filter sensitive values before they reach the SDK.
Paid plans are billed through Stripe, our payment processor. Card details are entered on and stored by Stripe; we never see or store your full card number. We keep invoicing records as required by law.
When you use the contact form we receive the name, email address and message you submit, and we use them only to answer you.
We measure site traffic with a self-hosted, cookieless analytics tool. It collects aggregated usage data only (pages viewed, referrer, browser family) and cannot identify you or follow you across other sites. No data is shared with advertising networks.
All customer data is stored and processed on servers located in the European Union.
Telemetry is retained according to your plan (7 days on the Free plan, 30 days on Pro, configurable on custom plans) and is then deleted automatically.
Account data is kept for as long as your account exists and deleted when the account is closed. Invoicing records are kept for the duration required by law.
We never sell personal data. We share data only with the subprocessors needed to run the service:
Each subprocessor only receives the data required for its role.
All traffic to and inside the platform uses TLS. Passwords are hashed, API access is authenticated with scoped tokens, and access to production systems is restricted.
We set no advertising or third-party tracking cookies. The application stores authentication tokens and your language preference in your browser's local storage, strictly to keep you signed in and remember your settings.
Under the GDPR you can request access to, rectification, erasure or portability of your personal data, and object to or restrict its processing. Send any request through the contact form; we answer within the legal timeframe. You can also lodge a complaint with your local supervisory authority.
We will update this page when our practices change and adjust the date at the top. Significant changes are announced to account owners by email.