Watchtower
Last updated: 22 September 2026
Watchtower is operated by SHAJ Studio. This policy explains what data the application accesses, what it stores, and what it does not.
Watchtower is a monitoring application for HighLevel agencies. It is installed once at agency level, reads configuration and activity signals from the agency's sub-accounts, and reports problems by email and through a dashboard.
Watchtower is read-only. It holds no write permissions to any HighLevel account and cannot create, modify, or delete anything in a customer's account or their clients' accounts.
Watchtower requests read-only permissions, which the agency approves at install. These allow it to read:
The full list of permissions is shown on the consent screen before installation.
We store configuration metadata and event counts, not customer records.
Specifically, we store:
We do not store contact records or message content. Incoming webhook data is stripped before it is written: contact names, email addresses, phone numbers, and the body text of emails and SMS messages are discarded and never persisted. What remains is the identifier and the fields our checks read.
Watchtower emails a digest to the recipients an agency configures, daily by default, or weekly, or paused, at the hour the agency sets. It contains sub-account names and the findings we detected, and links to your Watchtower dashboard, where each finding links straight to the setting in HighLevel that needs fixing. It does not contain contact data or message content.
Email is sent through Resend. Agencies choose their own recipients and can pause or stop email at any time from the settings page. Any recipient can also unsubscribe directly from a link included in every digest.
We record whether digest emails are opened, to measure whether they're useful.
OAuth tokens issued by HighLevel are encrypted at rest using AES-256-GCM. They are used only to make the read requests described above.
When an agency uninstalls Watchtower, all of their data is deleted from our database immediately: sub-account records, findings, stored events, settings, and access tokens.
Short-lived operational records also exist outside that immediate deletion. Webhook delivery logs on our own side expire automatically within four days and contain no contact records or message content. Our infrastructure and email providers' own logs, backups, and records of emails already sent expire according to each provider's own retention period, not ours. This can include a copy of a sent digest, held by our email provider, which names sub-accounts and the findings reported in it.
A later reinstall starts fresh.
Agencies may also request deletion at any time by contacting us.
Data is transmitted over TLS. Tokens are encrypted at rest. Access to the dashboard requires a signed token or an authenticated HighLevel session, and every request is scoped to a single agency's own data.
Where an agency's sub-accounts contain personal data belonging to their clients' customers, the agency remains the controller of that data. Watchtower acts as a processor, reads only what is described above, and stores none of it.
We will update this policy when what we store or access changes, and revise the date at the top.