Legal
Privacy Policy
Last updated — May 13, 2026
UpSec.Watch (“we”, “us”, or “our”) operates the uptime monitoring and security scanning service available at upsec.watch (the “Service” ). This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and the rights you have over your data.
We are incorporated in Hong Kong SAR and operate globally. Where our users are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process personal data in accordance with the General Data Protection Regulation (GDPR) and applicable national implementing legislation. For users in other jurisdictions, we apply equivalent data protection standards to the greatest extent practicable.
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Service.
Information We Collect
We collect the minimum information necessary to deliver and improve the Service. The categories below describe what we collect, how it is collected, and why it is needed.
Account Data
When you create an account using our magic-link authentication (powered by Supabase Auth), we collect:
- Email address — your primary identifier and the address to which we deliver magic-link sign-in emails and service notifications.
- Display name — an optional name you may set in Settings, used in the dashboard and email correspondence.
- Avatar URL — we derive a Gravatar image URL from the SHA-256 hash of your email address. No raw email hash is stored on third-party servers; Gravatar only receives a hash if your browser requests the image. You may disable Gravatar loading in your browser via standard content-blocking tools.
- Plan tier and billing status — the subscription plan associated with your account (Hobby, Plus, Pro, or Team). Raw payment card or bank details are never stored by UpSec.Watch.
- Notification preferences — toggles you configure in Settings that control which events trigger email or channel notifications.
Asset Configuration Data
The Service monitors external URLs, hostnames, and network endpoints that you explicitly add. For each monitored asset we store:
- URL or hostname, port, and monitoring protocol (HTTP/HTTPS, TCP).
- Monitoring interval, regions, keyword-match strings, and any custom request headers or body content you supply.
- Per-asset notification channel configuration — webhook URLs, Discord/Slack webhook endpoints, Telegram bot tokens and chat IDs, or ntfy topic URLs you provide for alert delivery.
- Asset display name, type (website or server/host), and status (Pending, Protected, Reviewing, Down, Paused).
You are responsible for ensuring that the assets you add are systems you own or are authorized to monitor. See our Terms of Service for the Acceptable Use Policy.
Monitoring & Scan Data
Each time our infrastructure checks one of your monitored assets, we record the result. This telemetry data includes:
- Uptime check results — HTTP status code, response time in milliseconds, whether the check succeeded or failed, the Cloudflare colo (data-center region) the check was issued from, and a timestamp.
- Security scan results — vulnerability findings (CVE identifiers, severity rating, affected component), technology stack detected (web server, CMS, frameworks), and the timestamp of the scan. Raw scanner output is stored in Cloudflare R2 object storage.
- Daily aggregate statistics — one row per asset per calendar day recording uptime percentage, average/minimum/ maximum response time, and incident count. These aggregates do not contain personally identifiable information and are retained indefinitely to power historical trend views.
Usage Analytics
We do not currently operate an analytics platform. If we add usage analytics in the future (e.g., page views, feature interaction events, session duration), we will update this policy, provide appropriate notice, and where required obtain consent before collecting such data.
Payment Data
Subscription payments are processed by a third-party payment processor (to be announced). The payment processor receives your billing name, card details, and billing address directly; UpSec.Watch receives only a tokenized customer reference and your active plan tier. We never handle, store, or transmit raw payment card information.
Technical & Network Data
Cloudflare, which provides our global CDN, Pages hosting, and Worker infrastructure, automatically collects basic technical data as part of routing requests. This includes your IP address, browser user agent string, operating system, approximate geographic region (country/city), and request metadata (URLs, HTTP method, status code, bytes transferred). This data is processed under Cloudflare's privacy policy and is used for DDoS protection, routing optimization, and abuse prevention.
How We Use Your Information
We use the information we collect exclusively for the purposes described below. We do not use your data for advertising profiling or sell it to third parties.
- Providing the Service — operating uptime monitoring checks at the intervals you configure, executing security scans, storing results, and making them available through your dashboard.
- Delivering notifications — sending downtime alerts and recovery notices via email (Zoho SMTP), and via the channel integrations you configure: Discord webhooks, Slack webhooks, Telegram bot messages, ntfy push notifications, and generic HTTP webhooks.
- Displaying dashboards and reports — rendering uptime history, response-time charts, security score rings, vulnerability findings, and the 365-day contribution wall in the web application.
- Enforcing plan limits and billing — applying the asset count, minimum monitoring interval, region count, data retention window, and notification channel limits that correspond to your active subscription plan.
- Preventing abuse and unauthorized scanning — detecting and blocking attempts to scan assets that users do not own or are not authorized to test, enforcing rate limits, and maintaining an audit trail of scan jobs.
- Improving service reliability and features — investigating incidents, debugging failures, analyzing aggregate (non-personal) usage patterns to prioritize engineering work, and improving the accuracy of security scan findings.
- Communicating with you — responding to support requests, sending transactional emails (magic-link sign-in, plan changes, important policy updates), and, only with your explicit consent, sending optional product update emails.
- Complying with legal obligations — retaining records required by Hong Kong tax law or responding to lawful orders from competent authorities.
Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, or Switzerland, every processing activity is grounded in one of the legal bases set out in Article 6(1) of the GDPR. The table below maps our key processing activities to their applicable legal basis.
Art. 6(1)(b) — Performance of a Contract
- Creating and maintaining your user account and authenticating you via magic link.
- Running uptime checks and security scans against assets you have added, at the frequency and with the configuration you specified.
- Storing check results and making them available in your dashboard for the retention period included in your plan.
- Delivering downtime and recovery notifications through the channels you have configured.
- Processing your subscription, applying plan limits, and managing account deletion.
Art. 6(1)(f) — Legitimate Interests
We rely on legitimate interests where our interest in operating a secure, reliable, and improving service is not overridden by your fundamental rights and freedoms.
- Security and abuse prevention — detecting unauthorized scanning attempts, enforcing acceptable-use restrictions, and protecting the network infrastructure and other users from misuse.
- Service improvement — analyzing anonymized, aggregated telemetry to improve scanner accuracy, reduce false positives, and prioritize feature development.
- Bug investigation and incident response — retaining logs for a reasonable period to diagnose failures and respond to security incidents.
Art. 6(1)(a) — Consent
- Optional marketing or product-update emails — sent only if you explicitly opt in. You may withdraw consent at any time by clicking “unsubscribe” in any such email or by contacting support@upsec.watch.
- Any future analytics collection (page views, feature usage) will require separate, specific consent before activation.
Art. 6(1)(c) — Legal Obligation
- Retaining business and tax records as required under Hong Kong Companies Ordinance and Inland Revenue Ordinance.
- Responding to lawful requests from courts, law enforcement agencies, or data protection supervisory authorities.
- Notifying affected users of personal-data breaches as required by applicable law.
Where we rely on legitimate interests, you have the right to object to that processing at any time. See Section 8 (Your Rights) for details on how to exercise this right.
Data Storage & Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, to honour our contractual obligations to you, and to comply with applicable legal requirements.
Infrastructure & Storage Locations
- Supabase(cloud-hosted Postgres database and authentication platform) — stores user account data, asset configurations, uptime check results, notifications, scan job metadata, and daily aggregate statistics. Data is encrypted at rest and in transit by Supabase's infrastructure.
- Cloudflare Workers (global edge network) — executes uptime checks from Cloudflare data centers worldwide. Ephemeral check data is submitted to authenticated first-party API endpoints backed by Supabase; no persistent data is stored in Workers KV or Durable Objects beyond transient state required to execute a single check cycle.
- Cloudflare R2 (object storage, US and EU regions available) — stores raw security scanner output files and generated PDF reports. Objects are encrypted at rest. A URL reference to each stored object is recorded in Supabase; the object itself contains technical scan artifacts, not personally identifiable information.
Detailed Uptime Check Retention by Plan
Individual uptime check records (containing status code, response time, region, and timestamp) are retained for the following periods and then permanently deleted:
- Hobby (Free) — 7 days
- Plus — 30 days
- Pro — 90 days
- Team — 365 days
Aggregate Statistics
Daily aggregate statistics (one row per asset per calendar day, recording uptime percentage, average/minimum/maximum response time, and incident count) contain no personally identifiable information and are retained indefinitely. These aggregates power the long-term historical trend views in your dashboard.
Account Data
Your account data (email address, display name, notification preferences, plan tier, Supabase Auth session records) is retained for as long as your account is active. If you delete your account from Settings > Danger Zone, a cascading deletion job removes all personal data from the database in batches within minutes. After deletion, anonymized aggregate statistics (which carry no personal identifiers) may be retained.
Security Scan Artifacts
Raw scan output files stored in Cloudflare R2 are deleted when you delete the associated asset or your account. Retention of scan artifacts follows the same plan-tier windows as uptime check data for detailed findings; vulnerability summaries stored in Supabase follow the same cascading deletion as other asset data.
Logs and Technical Data
Application-level logs are retained for up to 30 days for debugging and incident response purposes. Cloudflare network-layer logs are subject to Cloudflare's own retention policies (typically 72 hours for standard logs).
Third-Party Services
To operate the Service we engage a small number of carefully selected sub-processors. Each sub-processor receives only the minimum data necessary to perform their function and is contractually bound to appropriate data protection standards.
- Supabase, Inc. — authentication, Postgres database, and Data API infrastructure. Processes application data including user accounts, asset configurations, check results, notifications, and scan metadata. Privacy policy: supabase.com/privacy.
- Cloudflare, Inc. — CDN, DNS, application hosting (Cloudflare Workers), uptime check execution (Workers), and scan artifact storage (R2). Processes IP addresses, request metadata, and stored artifacts. As part of operating the global network, Cloudflare may process data in multiple countries. Privacy policy: cloudflare.com/privacypolicy.
- Zoho Corporation (Zoho Mail) — SMTP email transport for magic-link authentication emails and notification emails. Receives the recipient email address and message content for each email we send. Privacy policy: zoho.com/privacy.html.
- Payment processor (to be announced) — processes subscription payments. Receives your billing name, payment card details, and billing address directly. UpSec.Watch receives only a tokenized customer reference and plan status. The processor will be listed here upon launch of paid subscriptions along with a link to their privacy policy.
- Notification channel providers — when you configure optional integrations (Discord, Slack, Telegram, ntfy, or generic webhooks), alert message content is transmitted to the respective platform under your own account credentials. We act as a data processor on your behalf; the platform operator is the data controller for your account on that platform.
We do not sell, rent, or trade your personal data to third parties for their own marketing or commercial purposes — under any circumstances.
We may disclose personal data to competent authorities when required by a valid legal order. Where permitted by law, we will notify you of such a request before complying. We publish a transparency report if we receive government data requests.
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred to the successor entity. We will provide at least 30 days' notice via email and a banner in the application before any such transfer occurs, and you will have the option to delete your account if you do not wish your data to be transferred.
Data Security
Protecting your data is a core part of the Service we provide. We implement appropriate technical and organisational measures to guard against unauthorised access, disclosure, alteration, or destruction of your personal information.
- Encryption in transit — all connections between your browser and our application, between our Workers and Supabase, and between our scanner and Supabase are encrypted using TLS 1.2 or higher. HTTP connections are automatically redirected to HTTPS.
- Encryption at rest— data stored in Supabase is encrypted at rest by Supabase's managed infrastructure. Scan artifacts in Cloudflare R2 are encrypted at rest by Cloudflare's managed encryption.
- No password storage — authentication is performed exclusively via magic link (a single-use, time-limited token delivered to your email address). We never store passwords or password hashes.
- Authenticated Worker-to-API communication — the Cloudflare Worker submits uptime check results to first-party API endpoints that validate a shared secret before writing to Supabase.
- Row-level access control — Supabase Row Level Security policies and first-party API authorization checks enforce user-level ownership. Users can only read and modify their own assets, check results, and notifications. There is no reliance on security-through-obscurity for access control.
- Cascading data deletion — when you delete an asset or your account, a batched deletion job removes all associated records across every table, including uptime checks, daily stats, scan jobs, scan results, and notifications. Deletion is permanent and irreversible.
- Dependency management and code review — we keep production dependencies up to date, monitor for security advisories affecting our stack, and review all code changes before deployment.
- Principle of least privilege — internal service accounts and API keys are scoped to the minimum permissions required to perform their function. Production secrets are stored as environment variables in Cloudflare and Supabase, never in source code or version control.
No security measure is infallible. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR Article 33) and will notify you without undue delay when the breach is likely to result in high risk to you (Article 34). Notifications will be sent to the email address associated with your account and will include the nature of the breach, the categories and approximate number of affected records, likely consequences, and steps we are taking to address it.
If you discover a security vulnerability in the Service, please report it responsibly to support@upsec.watch. We will investigate promptly and credit good-faith disclosures in our security acknowledgements.
Your Rights
Depending on your location and the applicable law, you may have some or all of the rights described below. EU/EEA users have all of these rights under the GDPR. Users in other jurisdictions have equivalent rights under applicable local privacy laws where in force. We honour these rights globally to the greatest extent practicable, regardless of legal jurisdiction.
- Right to access (Art. 15 GDPR)— you may request a copy of the personal data we hold about you, information about how we process it, the categories of recipients, and the intended retention period. To request access, email support@upsec.watch with the subject line “Data Access Request”.
- Right to rectification (Art. 16 GDPR) — you may correct inaccurate personal data at any time. Your display name and email preferences can be updated directly in Settings. For other corrections, contact support@upsec.watch.
- Right to erasure / “right to be forgotten” (Art. 17 GDPR) — you may delete your account at any time from Settings > Danger Zone. Doing so permanently and irreversibly deletes your user record and triggers cascading deletion of all associated personal data (assets, check results, scan jobs, notifications, Supabase Auth sessions and account records). Only anonymised daily aggregate statistics, which carry no personal identifiers, may be retained.
- Right to data portability (Art. 20 GDPR)— you may request an export of your personal data in a structured, commonly used, machine-readable format (JSON). Email support@upsec.watch with the subject line “Data Portability Request”. We will prepare and deliver the export within 30 days.
- Right to restrict processing (Art. 18 GDPR) — you may pause monitoring on specific assets at any time from the asset settings, which suspends active data collection for those assets. For broader processing restrictions, contact support@upsec.watch.
- Right to object (Art. 21 GDPR) — you may object to processing activities that are based on our legitimate interests (Art. 6(1)(f)). To exercise this right, email support@upsec.watch explaining which processing activity you object to and why. We will cease the processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent (Art. 7(3) GDPR)— where processing is based on your consent (e.g., optional marketing emails), you may withdraw consent at any time by clicking “unsubscribe” in any such email or by emailing support@upsec.watch. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- Right not to be subject to automated decisions (Art. 22 GDPR) — we do not make decisions about you solely through automated processing that produce legal or similarly significant effects. Plan enforcement (asset limits, interval minimums) is rule-based and not profiling.
To exercise any of the above rights, email support@upsec.watch. We will respond within 30 calendar days. If the request is complex or there are a large number of requests, we may extend this period by a further two months and will notify you accordingly within the first 30 days.
We may ask you to verify your identity before processing a request to ensure that personal data is not disclosed to an unauthorised party. We do not charge a fee for exercising your rights unless a request is manifestly unfounded or excessive, in which case we will inform you before proceeding.
Right to lodge a complaint— if you are located in the EU/EEA and believe we have not handled your personal data in accordance with the GDPR, you have the right to lodge a complaint with the data protection supervisory authority in your EU/EEA member state. A list of EU supervisory authorities is available at edpb.europa.eu. For UK users, the relevant authority is the Information Commissioner's Office (ico.org.uk). For Swiss users, the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
Children's Privacy
UpSec.Watch is a technical SaaS product designed for and directed exclusively at adults — specifically developers, IT professionals, and business operators who manage web infrastructure. The Service is not intended for, designed for, or directed at children.
- We do not knowingly collect personal data from anyone under the age of 16. In jurisdictions where the applicable minimum age for digital consent is lower (for example, 13 in the United States under COPPA), we apply the higher threshold of 16 unless local law requires otherwise.
- Our account creation flow does not include an explicit age gate; we rely on the nature of the Service (technical monitoring tool requiring ownership or authorization over monitored systems) as a practical barrier to use by minors.
- If we become aware that we have inadvertently collected personal data from a person under the applicable minimum age, we will delete that data from our systems promptly, including from all backup stores within the next scheduled backup cycle.
- Parents or guardians who believe their child has created an account or provided personal data to UpSec.Watch should contact support@upsec.watch immediately with the subject line “Child Data Deletion Request”. We will investigate and take action within 72 hours.
If you are under 16 years of age (or the applicable minimum age in your jurisdiction), please do not use UpSec.Watch or provide any personal information to us.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the Service, changes in applicable law, or changes in our data processing practices. The “Last updated” date at the top of this page indicates when the most recent revision was made.
- Material changes — changes that meaningfully affect how we collect, use, or share your personal data, or that reduce your rights under this policy, are considered material. We will notify you of material changes by email (to the address associated with your account) at least 30 calendar days before the changes take effect. The notification will summarise what is changing and why, and provide a link to the updated policy.
- Non-material changes— minor clarifications, typographical corrections, restructuring for readability, and additions that do not affect your rights (such as adding a new sub-processor with equivalent data protection standards) will be reflected by an updated “Last updated” date on this page without advance email notice.
- In-app notice — for significant changes, we may also display a banner in the application dashboard directing you to review the updated policy.
- Previous versions — prior versions of this policy are available on request by emailing support@upsec.watch. We retain all historical versions for at least 3 years.
- Continued use— your continued use of the Service after the effective date of a material change constitutes your acceptance of the updated policy. If you do not accept a material change, you may delete your account before the effective date by following the steps in Settings > Danger Zone.
We encourage you to review this policy periodically. If you have questions about a specific change, email support@upsec.watch.
Contact Information
If you have any questions, concerns, or requests relating to this Privacy Policy or our data processing practices, please contact us using the appropriate channel below.
- Privacy inquiries and rights requests: support@upsec.watch — use this address to exercise your GDPR rights (access, correction, deletion, portability, objection), report a suspected breach affecting your personal data, or ask any question about how we handle your information.
- General support: support@upsec.watch — for questions about your account, subscription, monitoring configuration, or any other aspect of the Service.
- Legal notices and policy questions: support@upsec.watch — for formal legal correspondence, law enforcement requests, subpoenas, and requests for prior versions of this policy.
- Security vulnerability disclosures: support@upsec.watch — for responsible disclosure of security vulnerabilities in the UpSec.Watch platform.
- Postal address: UpSec.Watch, Hong Kong SAR, China.
We aim to respond to all privacy-related inquiries within 5 business days. For formal rights requests under GDPR or equivalent legislation, we will respond with an outcome within 30 calendar days as required by law.
EU/EEA Representative
As a company established outside the European Economic Area that offers services to EU/EEA residents, we are evaluating the requirement to appoint an EU representative under GDPR Article 27. If required, the name and contact details of our EU representative will be listed here. In the meantime, EU/EEA users may direct all inquiries to support@upsec.watch, and may also lodge complaints directly with their national data protection authority (a list is available at edpb.europa.eu/about-edpb/board/members_en).
Supervisory Authorities
If you are dissatisfied with our response to a privacy inquiry, or believe we are processing your personal data unlawfully, you have the right to lodge a complaint with a supervisory authority in your jurisdiction without prejudice to any other administrative or judicial remedy:
- EU/EEA residents — the data protection authority in your EU member state. Directory: edpb.europa.eu.
- UK residents— Information Commissioner's Office (ICO): ico.org.uk, telephone 0303 123 1113.
- Swiss residents — Federal Data Protection and Information Commissioner (FDPIC): edoeb.admin.ch.
- Hong Kong residents — Office of the Privacy Commissioner for Personal Data (PCPD): pcpd.org.hk.