Privacy Policy
Last updated 3 August 2026
UptimeCraft is operated by Premier Code, Inc. ("we", "us"). This policy explains what we collect, why, who else sees it, and what you can ask us to do about it. It describes the service as it actually works rather than in the abstract, so where something is stored indefinitely or sent to a third party, we say so.
1. Information you give us
Account and team
Your name, email address and a one-way hash of your password (we never store the password itself). Your team's name, plan, and — if you have subscribed — identifiers issued by Stripe. We record whether your email has been verified and what role you hold.
Monitor configuration
The addresses you ask us to check, along with anything you configure alongside them: request methods, custom request headers, request bodies, keywords to match, DNS record expectations and UDP probe payloads.
Worth knowing: custom headers and request bodies are stored so that we can replay your check, and they are sent to our monitoring agents in the regions you select. If you put an API key or token in one, we hold it and transmit it. Prefer a dedicated, low-privilege credential for monitoring, and rotate it like any other secret.
Alerting destinations
Email addresses and the webhook URLs you configure for Slack, Discord, Microsoft Teams or your own endpoints. Sending an alert means sending its content to those destinations, which are outside our control.
Support and status pages
Support tickets and their replies, including anything you paste into them. If you publish a status page, the email addresses of people who subscribe to it.
Payment details
Card details are entered on Stripe's own checkout and never reach our servers. We store the identifiers Stripe returns, the amount, the currency and whether the payment succeeded.
2. Information we generate or observe
- Check results — the outcome of every check we run for you: status codes, response times, whether the target was reachable, and the error text when it was not.
- Incidents — when a monitor went down, when it recovered, and the alerts we sent.
- Heartbeat pings — when your jobs called us, how long they ran, and any message a failing job chose to send us (capped at 2 KB).
- Session data — a session record in our database and a corresponding cookie in your browser, so that you stay signed in.
- IP addresses — used to rate-limit password reset requests, so that the form cannot be used to flood someone's inbox.
3. How we use it
To run the service you asked for: performing checks, recording results, raising incidents, sending alerts, showing your dashboards, billing you, and answering your support requests. We also use it to keep the service working and secure — investigating faults, preventing abuse and enforcing plan limits.
We do not sell your data, and we do not use the contents of your monitors, check results or support tickets for advertising.
4. Who else processes it
We rely on these providers. Each sees only what it needs to do its job.
| Provider | Purpose | What it sees |
|---|---|---|
| DigitalOcean | Hosting, database, monitoring agents | Everything we store |
| Stripe | Payments and subscriptions | Your billing details and card data |
| Mailgun | Sending email | Recipient addresses and message content |
| hugemx.com | Backup email delivery when Mailgun is unavailable | Recipient addresses and message content |
| reCAPTCHA on our forms, and Google Analytics | Browser and interaction signals, pages visited, referrers | |
| Ahrefs Web Analytics | Traffic statistics | Pages visited and referrers. No cookies are set |
Our pages also load styling and JavaScript libraries from public content delivery networks, which necessarily see your IP address as your browser fetches them.
5. Where your data goes
Our database and application run in the United States. Checks run from the regions you choose, which currently include New York, San Francisco, Atlanta, Toronto, London, Amsterdam, Frankfurt, Bangalore, Singapore and Sydney. Selecting a region means your monitor's configuration — including any headers or request body you set — is sent to a machine in that country so the check can run from there.
6. How long we keep it
Your account and everything in it stays for as long as your account is open. We do not expire accounts for inactivity on a paid plan.
When you close your account
Closing your account removes your data: your profile, your team, your monitors and their configuration, your check history, incidents, support tickets, status pages and their subscribers, and your alerting destinations. Ask us at privacy@uptimecraft.com and we will complete it within 30 days.
One exception: records of payments already taken. Tax and accounting rules require us to keep invoices and their amounts, so those survive account closure. Where we can do so without breaking the records, we replace your name and email in them with an anonymous reference, so what remains is a transaction rather than a person.
Monitoring history
Check results and incident history are currently kept for the life of the account, and nothing expires them on a schedule. We are introducing retention periods that vary by plan, so that longer history becomes part of what a paid plan buys. We will publish the period alongside each plan and tell account holders before any data is removed under it.
Short-lived items
Password reset tokens are single use and expire quickly. Session records last as long as your session.
7. Cookies
We set one cookie, which keeps you signed in and carries the token that protects forms against cross-site request forgery. It is strictly necessary: the service cannot work without it, and it is not used for advertising or profiling. Google reCAPTCHA may set its own cookies on pages where it runs. Our analytics provider does not use cookies at all.
8. Security
Traffic to and from the service is encrypted in transit. Passwords are stored using bcrypt, which is designed to be slow to attack and cannot be reversed. Internal traffic between our control plane, monitoring agents and heartbeat receiver is authenticated with mutual TLS, so a component can only do what its own certificate permits. Our database is managed by DigitalOcean and encrypted at rest.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will tell you and any relevant regulator as the law requires.
9. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, obtain a copy in a portable form, object to or restrict certain processing, and complain to your data protection authority. If you are in the European Economic Area or the United Kingdom, these rights come from the GDPR; if you are in California, from the CCPA as amended.
Much of this you can do yourself from your account. For anything else, write to privacy@uptimecraft.com and we will respond within 30 days. We will not charge you or treat you differently for exercising a right.
10. Data you bring with you
If the systems you monitor, the pages we fetch or the job output you send us contain other people's personal data, you are the controller of that data and we process it on your instructions. You are responsible for having a lawful basis to send it to us.
11. Children
UptimeCraft is a tool for operating software and is not intended for anyone under 16. We do not knowingly collect their data, and will delete it if we discover we have.
12. Changes
If we change this policy in a way that materially affects you, we will email account holders and update the date at the top before the change takes effect.
13. Contact
Privacy questions: privacy@uptimecraft.com. Anything else: support@uptimecraft.com.
Premier Code, Inc.
See also our Terms of Service.