1.0.0 Store submissions in progress — follow along

Know the moment something you rely on breaks.

Watchtower inspects the websites and domains you own or depend on — registration, the full TLS chain, DNS, email authentication, Certificate Transparency, security headers, ports and health endpoints — then pages you when one of them stops working. Every check runs on your device. There is no Watchtower account, and no Watchtower server.

  • Android 10+ and iOS
  • No account, no analytics
  • GPL-3.0-or-later

The browser build is discovery only: a browser has no platform resolver and no foreground service, so it runs on DNS-over-HTTPS and cannot keep checking once you close the tab. Monitors and pages are Android and iOS.

watchtower · add monitor
The single Add monitor form: one field for a domain, URL or host:port, with Watchtower working out the kind of check from what you enter.
watchtower · scan
A scan report for wikipedia.org: a first-scan baseline card explaining that scanning again will report what changed, above an at-a-glance grid showing HTTP 200, TLS with 37 days left, SPF and DMARC found, and 6 DNS record types.
  • 0
    Watchtower accounts to create
  • 0
    Analytics or tracking SDKs
  • 3
    Kinds of monitor: domain, TCP, assertion
  • 4
    Expiry reminders: 30, 14, 7 and 1 day out
What it checks

One domain in, a full picture out.

Enter a domain or subdomain. Watchtower runs every applicable probe in parallel and reports what it found — and which source answered, so a degraded check never passes for a healthy one.

Registration

Expiry date, registrar, status codes and nameservers, read over RDAP rather than scraped from a webpage.

TLS leaf and full chain

Subject, issuer, expiry and validity window — plus every intermediate the server actually presents, and whether the platform considers the chain trusted.

Captured natively on Android and iOS. Most uptime tools stop at the leaf certificate.

DNS records

A, AAAA, MX, NS, TXT and CAA. On Android these come from the device’s own resolver by default, so a scan is not disclosed to a public DNS-over-HTTPS provider.

Email authentication

SPF, DMARC and CAA, summarised the way you actually read them: is SPF aligned, is DMARC enforced, is the policy too strict to survive.

Certificate Transparency

Issuance history from two independent logs, and the subdomains they reveal — a quick map of what a domain exposes.

HTTP and HSTS

Status code, redirect chain and security headers, with a plain reading of what HSTS is actually set to.

TCP host and port

A socket check against any host:port you choose, on a cadence you set. Good for databases, game servers and anything that does not speak HTTP.

HTTP body assertions

Assert that a health endpoint returns 200 and still contains the string you expect. ok=true means the service is really up, not just reachable.

Change since last scan

Every scan is compared with the previous one on this device, so a withdrawn DMARC record, a moved expiry date, a new certificate issuer or a dropped mail exchanger shows up as a change instead of having to be noticed by eye.

The comparison is local. There is nothing stored off-device to compare against.

The app

Calm, dense, and honest about state.

Real screenshots from a release build. Every panel shows which source answered, when it was checked, and whether the result is still fresh.

The scan screen: a Domain entry field, an optional Scan subdomains checkbox, a Run scan button, and a note explaining that a scan is local-first but still contacts the selected site and public lookup services.
Scan entryStates plainly what a scan sends, before you send it.
Scan result header with a Healthy verdict, and an at-a-glance grid of availability, TLS, registration, email auth, DNS and subdomain counts.
At a glanceEvery fact populated, and the baseline saved for next time.
The TLS certificate panel expanded, listing subject, issuer, expiry date, time remaining, the number of presented intermediate certificates and the platform trust verdict.
The presented chainSubject, issuer, intermediates, and whether the platform trusts it.
Per-source status list showing whether RDAP, DNS, Certificate Transparency and the HTTP target each answered or failed.
Per-source statusA failed lookup is shown, never hidden behind a green tick.
The Monitors tab with a healthy TCP target, its cadence, latency budget and last-check time inline, a single Add monitor button, and the time of the last background check.
Your monitorsCadence, budget, last check, and when the last sweep ran.
The Settings screen: a Transparent by design card stating there is no account or backend, a DNS resolver choice between the device resolver and a custom DNS-over-HTTPS endpoint, and a Site list section that copies watched addresses to the clipboard.
SettingsThe resolver is your choice, and the site list is one tap from the clipboard.
Alerting

It escalates until you acknowledge it.

A notification you swipe away is not an alert. On Android a foreground service keeps checking with the app closed, and a failure keeps paging until you say you have seen it.

  • Full-screen alert, sound, vibrationEscalation continues until acknowledged.
  • Acknowledge, Mute 1h, Re-checkHandled from the alert itself, without opening the app.
  • Per-monitor tuningCadence, failure threshold, latency budget, sound, vibration and quiet hours — per monitor, not global.
  • Survives a rebootMonitoring resumes without you opening the app.
  • Offline-capable soundA bundled alarm tone ships with the app, so alerting still works with no network.
  • Stale is never greenIf a result is older than expected it is labelled stale. An old pass is not a pass.
wikipedia.org                                  healthy

availability  HTTP 200            responded in 184 ms
tls           38d left           chain: 3 intermediates, trusted
registration  108d left          registrar: Wikimedia Foundation
email auth    SPF + DMARC        both aligned
dns           6 record types     A AAAA MX NS TXT CAA
subdomains    0 found            2 CT entries checked
http          HSTS 31536000      0 redirects

checked 2026-09-26 12:52
rdap ok  dns ok (device resolver)  ct ok  target ok
Local-first

No account. No backend. Nothing to leak.

Because Watchtower operates no server, the developers cannot see your data even in principle. What that does not mean is spelled out below, because “private” is not worth much without the caveat.

Stays on your device

Monitors, check history, settings and the last result per monitor are written to private app storage only. Deleting the app deletes all of it — there is no server-side copy, so there is nothing to request the deletion of.

  • No analytics, advertising, attribution or crash-reporting SDK
  • No advertising identifier, and no location, camera, contacts or storage access
  • Parsing, diffing, expiry arithmetic and every alert decision happen on-device
  • Android DNS goes to the resolver your device is already configured to use — or to a DNS-over-HTTPS endpoint you choose, if you would rather query every record type
  • Moving to a new phone copies a plain list of addresses and nothing else — cadence, thresholds, quiet hours and learned expiry dates stay behind

What does leave your device

A scan is not offline. To answer a question about your domain, Watchtower has to ask someone who already knows the answer — so the domain string you typed is sent to these public services, which each see your IP address, the query and the time:

  • IANA / ICANNRDAP bootstrap — which registry to ask
  • The domain’s registryRegistration data over RDAP
  • crt.sh and Cert SpotterCertificate Transparency logs — these publish query logs
  • Cloudflare DoHDNS-over-HTTPS on iOS and web always; on Android only if you opt in by pointing the app at a DoH endpoint
  • The site itselfMonitors connect directly to the host, port or URL you configured

Every one of these permissions has a stated reason, and none of them is marketing. The full privacy policy names each service, its operator and its own policy — read it before you monitor a domain whose existence needs to stay private.

Who it’s for

Built for the handful of things you actually own.

Not for a fleet of nine hundred endpoints. For a personal site, a side project, a homelab, or the services you quietly depend on at work.

Personal sites and side projects

Catch the renewal you forgot and the certificate that quietly expired on the one domain that matters.

Homelabs and self-hosted services

A TCP monitor per service, a body assertion per health endpoint, and a phone that tells you which one died while you were asleep.

Small teams and organisations

A lightweight way for one operator to watch a small set of sites and services they own or depend on — without adding a vendor, a signup or a data processor.

And what it deliberately is not

A local-only app structurally cannot do some things that hosted uptime services do. Rather than ship a thinner version of those, here is the trade:

  • No shared dashboard and no automatic sync.A monitor lives on the device that created it. You can copy your list of watched sites to the clipboard as plain text and paste it on another device, but nothing is synced for you, and there is no account to sync through.
  • No webhooks and no remote push.Alerts are delivered locally to your device.
  • iOS gets expiry reminders and on-open discovery.No real-time background paging in this release; iOS cannot promise it.
  • Background cadence is best-effort on Android.Doze and OEM power rules can delay a check, so results are labelled stale rather than shown as healthy.
Questions

The ones worth asking.

Do I need a Watchtower account?

No. There is no signup, and no Watchtower server to sign in to. Your monitors and their results live in private storage on the device that created them. Uninstalling the app is the complete erasure path.

Is a scan actually offline?

No, and claiming otherwise would be dishonest. The domain you type is sent to RDAP and to Certificate Transparency log operators, because they are the parties that hold the answer. On Android, DNS is resolved by the device’s own resolver by default, so Android scans are not disclosed to Cloudflare — though you can point Watchtower at a DNS-over-HTTPS endpoint if you prefer that, and iOS and web use one because they have no public API for arbitrary record types. The privacy policy names every service and its operator.

Why does it use public services at all?

Because there is no other way to answer “when does this domain expire” or “what else is issued for this name” from a phone without shipping a copy of the registry and log data. The trade is: third parties see the domain you query, and in exchange you get those answers without a backend, a vendor account or a monthly bill.

Can it watch something on my own network?

Yes, as long as the phone can reach it. A TCP monitor opens a socket to any host:port you choose, and an assertion monitor issues an HTTP request to a URL and checks the response — both work fine against a LAN address, as long as you are on the network that serves it. Note that a phone off your home Wi-Fi will not reach 192.168.x.x.

What is the actual differentiator, versus Uptime Kuma or a hosted service?

Two things. First, the TLS full chain: Watchtower records the intermediates the server actually presents and reports the platform’s trust verdict, captured natively on Android and iOS. Second, the privacy shape: no account, no dashboard to log into, and nothing to hand a vendor. In exchange you give up history charts and webhooks — which is a real loss, and the previous section says so.

Will it drain my battery, or will Android kill it?

Neither is fully avoidable, so Watchtower is explicit about it. Checks are on a cadence you choose, with a per-monitor latency budget, and there is an optional battery-optimisation exemption. Android may still delay a cycle while the device is idle — so a result past its expected freshness is shown as stale, never as healthy.

Why F-Droid as well as the stores?

F-Droid builds from source with no tracking, no proprietary services and no account, and its recipe for Watchtower is in the repository already. The project also ships reproducible-build tooling, so two clean builds of the same commit produce the same APK. Play remains the most convenient option for most people, and both are being worked on.

How much does it cost?

Nothing. Watchtower is free software under the GNU General Public License, version 3 or later. You can read, modify and redistribute it; if you distribute a modified version, you pass on the same freedom.

Get it

Not in a store yet. Here is how to follow it.

1.0.0 is cut and the store metadata is written, but neither submission has gone through review. The issue tracker is the honest place to watch progress — and the place to ask for a channel you would rather have.

Source & issues Available now

Read the code, follow the commit history, or open an issue.

GPL-3.0-or-later · full history, no redactions
Android · F-Droid In progress

Recipe, tag and screenshots are in the repository; the submission is not filed yet.

Built from source · reproducible · no tracking
Android · Google Play In progress

Listing copy, privacy URL and screenshots are written and waiting on upload.

Full-screen alerts need a Play policy declaration
iOS Planned

Discovery and expiry reminders work today; real-time paging is not promised.

Reminder checkpoints 30 / 14 / 7 / 1 days out

Want it on your phone?

Watch the submission progress on the issue tracker, or ask to be told when a channel goes live. The source is public either way, and you can build the APK yourself today.