UptimeCraft Back to site

Privacy Policy

Last updated 3 August 2026

UptimeCraft is operated by Premier Code, Inc. ("we", "us"). This policy explains what we collect, why, who else sees it, and what you can ask us to do about it. It describes the service as it actually works rather than in the abstract, so where something is stored indefinitely or sent to a third party, we say so.

1. Information you give us

Account and team

Your name, email address and a one-way hash of your password (we never store the password itself). Your team's name, plan, and — if you have subscribed — identifiers issued by Stripe. We record whether your email has been verified and what role you hold.

Monitor configuration

The addresses you ask us to check, along with anything you configure alongside them: request methods, custom request headers, request bodies, keywords to match, DNS record expectations and UDP probe payloads.

Worth knowing: custom headers and request bodies are stored so that we can replay your check, and they are sent to our monitoring agents in the regions you select. If you put an API key or token in one, we hold it and transmit it. Prefer a dedicated, low-privilege credential for monitoring, and rotate it like any other secret.

Alerting destinations

Email addresses and the webhook URLs you configure for Slack, Discord, Microsoft Teams or your own endpoints. Sending an alert means sending its content to those destinations, which are outside our control.

Support and status pages

Support tickets and their replies, including anything you paste into them. If you publish a status page, the email addresses of people who subscribe to it.

Payment details

Card details are entered on Stripe's own checkout and never reach our servers. We store the identifiers Stripe returns, the amount, the currency and whether the payment succeeded.

2. Information we generate or observe

3. How we use it

To run the service you asked for: performing checks, recording results, raising incidents, sending alerts, showing your dashboards, billing you, and answering your support requests. We also use it to keep the service working and secure — investigating faults, preventing abuse and enforcing plan limits.

We do not sell your data, and we do not use the contents of your monitors, check results or support tickets for advertising.

4. Who else processes it

We rely on these providers. Each sees only what it needs to do its job.

Provider Purpose What it sees
DigitalOcean Hosting, database, monitoring agents Everything we store
Stripe Payments and subscriptions Your billing details and card data
Mailgun Sending email Recipient addresses and message content
hugemx.com Backup email delivery when Mailgun is unavailable Recipient addresses and message content
Google reCAPTCHA on our forms, and Google Analytics Browser and interaction signals, pages visited, referrers
Ahrefs Web Analytics Traffic statistics Pages visited and referrers. No cookies are set

Our pages also load styling and JavaScript libraries from public content delivery networks, which necessarily see your IP address as your browser fetches them.

5. Where your data goes

Our database and application run in the United States. Checks run from the regions you choose, which currently include New York, San Francisco, Atlanta, Toronto, London, Amsterdam, Frankfurt, Bangalore, Singapore and Sydney. Selecting a region means your monitor's configuration — including any headers or request body you set — is sent to a machine in that country so the check can run from there.

6. How long we keep it

Your account and everything in it stays for as long as your account is open. We do not expire accounts for inactivity on a paid plan.

When you close your account

Closing your account removes your data: your profile, your team, your monitors and their configuration, your check history, incidents, support tickets, status pages and their subscribers, and your alerting destinations. Ask us at privacy@uptimecraft.com and we will complete it within 30 days.

One exception: records of payments already taken. Tax and accounting rules require us to keep invoices and their amounts, so those survive account closure. Where we can do so without breaking the records, we replace your name and email in them with an anonymous reference, so what remains is a transaction rather than a person.

Monitoring history

Check results and incident history are currently kept for the life of the account, and nothing expires them on a schedule. We are introducing retention periods that vary by plan, so that longer history becomes part of what a paid plan buys. We will publish the period alongside each plan and tell account holders before any data is removed under it.

Short-lived items

Password reset tokens are single use and expire quickly. Session records last as long as your session.

7. Cookies

We set one cookie, which keeps you signed in and carries the token that protects forms against cross-site request forgery. It is strictly necessary: the service cannot work without it, and it is not used for advertising or profiling. Google reCAPTCHA may set its own cookies on pages where it runs. Our analytics provider does not use cookies at all.

8. Security

Traffic to and from the service is encrypted in transit. Passwords are stored using bcrypt, which is designed to be slow to attack and cannot be reversed. Internal traffic between our control plane, monitoring agents and heartbeat receiver is authenticated with mutual TLS, so a component can only do what its own certificate permits. Our database is managed by DigitalOcean and encrypted at rest.

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will tell you and any relevant regulator as the law requires.

9. Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, obtain a copy in a portable form, object to or restrict certain processing, and complain to your data protection authority. If you are in the European Economic Area or the United Kingdom, these rights come from the GDPR; if you are in California, from the CCPA as amended.

Much of this you can do yourself from your account. For anything else, write to privacy@uptimecraft.com and we will respond within 30 days. We will not charge you or treat you differently for exercising a right.

10. Data you bring with you

If the systems you monitor, the pages we fetch or the job output you send us contain other people's personal data, you are the controller of that data and we process it on your instructions. You are responsible for having a lawful basis to send it to us.

11. Children

UptimeCraft is a tool for operating software and is not intended for anyone under 16. We do not knowingly collect their data, and will delete it if we discover we have.

12. Changes

If we change this policy in a way that materially affects you, we will email account holders and update the date at the top before the change takes effect.

13. Contact

Privacy questions: privacy@uptimecraft.com. Anything else: support@uptimecraft.com.

Premier Code, Inc.

See also our Terms of Service.