Who we are
UpButler is operated by HootCodes LTD, a company registered in the European Union ("we", "us"). For personal data about our own customers we are the data controller. You can reach us about anything in this policy at [email protected].
Our two roles
UpButler handles two kinds of personal data, and our responsibilities differ for each:
- As a controller for data about our customers and their team members: account emails, billing status, usage of the product.
- As a processor for data our customers put into UpButler or collect through it: in particular the email addresses and webhook URLs of people who subscribe to a customer's status page, and anything contained in the monitors, incidents and notes a customer creates. We process that data only on the customer's instructions, to provide the service.
What we collect
Account and workspace data
- Your email address, and optionally your name. We sign you in with one-time email codes or through Google or GitHub, so we do not store passwords. If you use Google or GitHub, we receive your verified email address, name, profile picture URL and account id from them.
- Workspace membership, roles and invitations.
- API keys and session tokens, stored only as one-way hashes.
What you configure and what we measure
- Monitors: URLs, hosts, request headers and bodies, scripts, alert channels. Treat headers and scripts as configuration you control; avoid putting personal data in them.
- Check results: status codes, timings, TLS and DNS details, and short excerpts of responses used to explain failures.
- Status pages, components, incidents, maintenance windows and the notes you write.
Billing
Payments are handled by Polar, our merchant of record. Polar collects your payment details and billing address; we receive your plan, subscription status and a customer reference. We never see your full card number.
Technical data
IP addresses and request metadata, used for rate limiting, abuse prevention and security logs. Security-relevant actions (sign-ins, two-factor changes, API keys, members, billing, deletions, domains) are recorded in your workspace's audit log with the actor and IP address. Workspaces created by AI agents through our API are rate-limited per IP address for the same reason.
How we use it
- To provide the service (performance of our contract with you): run checks, send alerts, publish status pages, deliver subscriber notifications, generate AI reports you request.
- To keep it secure and working (legitimate interest): prevent abuse, investigate incidents, fix bugs.
- To bill you (contract and legal obligation), through Polar.
- To tell you about the service: essential messages about your account, security and changes to these terms. Product news only if you opt in, with an unsubscribe link in every message.
We do not sell personal data, and we do not use it for advertising.
AI processing
AI incident reports, post-incident summaries and "polish with AI" are produced by large language models accessed through OpenRouter. When one of these features runs, we send only the context it needs: the monitor or component name, check results (status codes, timings, TLS and DNS details, a short response excerpt), the incident timeline, and the text you asked us to polish. We do not send your account details or your subscriber lists.
Your data is not used to train AI models: we only route requests to model providers that do not collect or store prompts for training. AI analysis can be switched off per monitor. By default, automatic incidents use an AI-written, customer-safe summary on your status page; you can turn that off per status page, and the internal technical analysis is never published.
Sub-processors
We use a small number of providers to run UpButler. Each is bound by a data processing agreement.
| Provider | Purpose | Data involved |
|---|---|---|
| EU-based infrastructure provider | Hosting, databases, backups | All service data |
| Polar | Merchant of record: checkout, invoices, VAT, subscriptions | Billing contact and payment details |
| Postmark | Transactional and status update emails | Recipient email addresses, message content |
| OpenRouter (and the model provider it routes to) | AI incident analysis and writing help | Incident and check context, as described above |
We will update this list before adding a new sub-processor that handles customer data. Ask us if you want to be notified.
International transfers
Our primary infrastructure is in the EU. Some sub-processors are based in, or route data through, countries outside the European Economic Area, such as the United States. Where that happens we rely on an adequacy decision (including the EU-US Data Privacy Framework where the provider is certified) or the European Commission's Standard Contractual Clauses.
How long we keep it
- Check results and incident history: for the history period of your plan (30 days on Free, 1 year on Starter and Pro, 2 years on Business), then deleted or aggregated into uptime figures that contain no personal data.
- Account and workspace data: while your account is active. When you delete a workspace or your account, we delete the data within 30 days, except where the law requires us to keep it.
- Unclaimed agent workspaces: deleted automatically 7 days after creation if no human claims them.
- Status page subscribers: until they unsubscribe, the customer removes them, or the page is deleted.
- Audit log entries: 400 days, then deleted automatically.
- Backups: rolling backups expire on a fixed schedule, after which deleted data is gone for good.
- Billing records: kept by Polar for as long as tax law requires.
Cookies
We use a single, essential session cookie to keep you signed in, and your browser's local storage to remember your light or dark theme. We do not use advertising cookies or cross-site trackers, so we do not show a cookie banner.
Security
Data is encrypted in transit. Sessions and API keys are stored as hashes, outgoing webhooks are signed, and script and browser checks run in isolated sandboxes. Access to production systems is limited to the people who need it. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as the GDPR requires.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and get a copy in a portable format;
- correct it if it is wrong;
- have it deleted;
- restrict or object to processing based on our legitimate interests;
- withdraw consent where we rely on it, such as product news emails.
Most of this you can do yourself in the dashboard or through the API. Otherwise email [email protected] and we will answer within 30 days. You also have the right to lodge a complaint with your local data protection authority.
If you subscribed to a status page
Status pages on UpButler belong to our customers. If you subscribed to updates from one, that company is the controller of your data and UpButler processes it on their behalf. Every email has an unsubscribe link, and you can manage your subscription from the link in your confirmation email. For anything else, contact the company that runs the page; if you cannot reach them, write to us and we will help.
Changes to this policy
If we make material changes, we will email account owners and post a notice in the dashboard at least 30 days before they take effect. The date at the top shows when this policy last changed.
Contact
HootCodes LTD, operator of UpButler. Privacy questions: [email protected]. Everything else: [email protected].