Privacy Policy

Last updated: 8 July 2026

Drafted with AI assistance. This is a starting point, not a substitute for review by a qualified lawyer in your jurisdiction before relying on it commercially.

This Privacy Policy explains what information Are We Up? ("we," "us") collects when you use the Service, why we collect it, who we share it with, and the choices you have. We try to collect only what's needed to run the Service.

1. Information we collect

Account data. Your email address and a password hash (we use bcrypt — we never store or can retrieve your plain-text password).

Monitoring data. The URLs, hosts, ports, and settings of the Monitors you create, and the check results we generate on your behalf — status, response time, status codes, error messages, and timestamps. Because monitoring a URL involves making requests to it, the hosts and IP addresses of the things you monitor are inherently part of this data.

Alert channel configuration. The alert destinations you connect — for example an email address, a Telegram chat ID, a Slack or Discord webhook URL, or a custom webhook endpoint. These configurations can contain secrets (bot tokens, webhook URLs, signing secrets) that would let someone post to your chat or endpoint if exposed, so we treat this data as sensitive and store it accordingly. Don't share your account credentials, and let us know if you believe an alert-channel secret has leaked so it can be rotated.

Status page subscriber data. If someone subscribes to email updates on one of your public status pages, we store their email address and subscription/confirmation status so we can send them status updates and let them unsubscribe.

Billing data. If you subscribe to a paid plan, payments are processed by Stripe. We store your Stripe customer ID and subscription ID so we can manage your plan, but we never see or store your full card number.

Technical and log data. Standard server logs (IP address, request metadata, timestamps) for security, debugging, and abuse prevention, and error reports sent to our error-tracking tool when something breaks.

Cookies and session tokens. We use cookies/local storage to hold your login session (access and refresh tokens) so you stay signed in. We don't use third-party advertising or tracking cookies.

2. Why we collect it

We use this data to operate the Service: running your checks on schedule, evaluating whether a Monitor is up or down, sending your alerts through the channels you configured, rendering your public status pages, authenticating you, and managing your subscription and billing. We also use your account email to send transactional messages — verification, password resets, downtime/recovery alerts, billing and payment notices, and important account or policy updates.

3. Who we share it with

We don't sell your data. We share data only as needed to run the Service, with:

Stripe, to process payments and manage subscriptions;
Brevo, our transactional email provider, to deliver verification, alert, and account emails;
Sentry, for error tracking, which may receive technical details about errors (and occasionally incidental request data) when something fails;
Telegram's API, if you connect a Telegram alert channel, so alerts can be delivered to your chat; and
— the specific third-party destinations you configure as alert channels (e.g., a Slack workspace, a Discord server, or a webhook endpoint you control) — we send alert content to these because you told us to.

Public status pages display only the monitor status information you choose to publish on them; they're visible to anyone with the link (or search engines, unless you enable "no-index").

We may also disclose data if required to by law, or to protect the security or legal rights of the Service, our users, or others.

4. Data retention

Check-result history is retained according to your plan and pruned automatically afterward:

— Free plan: 90 days
— Pro plan: 365 days
— Business plan: 730 days

Account data, monitor configuration, alert channel configuration, and status pages are kept for as long as your account is active. If you delete your account, your monitors, check results, alert channel configuration, status pages, and subscriber lists are permanently removed from our active systems; residual copies may briefly persist in backups until they age out of our normal backup rotation.

5. Your rights

You can access, export, or delete most of your data yourself at any time from account settings. You can also contact us to request access to, correction of, or deletion of your personal data, or to ask what we hold about you.

If you're in the EU/UK or another jurisdiction with its own data protection law (for example GDPR), you may have additional rights, such as the right to object to certain processing or to lodge a complaint with your local data protection authority. We aim to honor these kinds of requests in good faith, but we're a small operation and haven't formally certified compliance with any specific regional framework — if you need documentation of a specific legal compliance status (e.g., a signed DPA), please contact us to discuss.

6. Security

Passwords are hashed with bcrypt, authentication uses short-lived signed tokens, outgoing webhook alerts are HMAC-signed so recipients can verify they came from us, and traffic to the Service is served over HTTPS. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable, industry-standard steps to protect your data.

7. Children

The Service is not directed at children, and we don't knowingly collect personal data from anyone below the age required to consent to data processing in their jurisdiction.

8. Changes to this policy

We may update this Privacy Policy as the Service evolves. For material changes, we'll make a reasonable effort to notify you by email before they take effect.

9. Contact

Questions about privacy, or want to exercise a data right described above? Email support@areweup.app.