Legal Documentation

Privacy Policy

Effective Date: October 4, 2026•Last Updated: October 2026•Version: 2.1

1. Introduction & Scope

UpMe ("we," "our," or "us") provides a cloud-based keep-alive polling service designed to prevent inactive container spin-down and measure HTTP endpoint response times for web services, APIs, and microservices.

This Privacy Policy explains how we collect, process, store, and safeguard personal and operational information when you access or use the UpMe platform via our website, API, or console dashboard. By registering an account or configuring a monitored endpoint, you acknowledge and agree to the practices described in this document.

2. Information We Collect

We limit data collection strictly to what is required to administer accounts, deliver keep-alive polling, and provide real-time latency telemetry:

  • Account Credentials: When you register directly, we collect your self-selected username and email address. Passwords are never stored in plaintext; they are salted and hashed using one-way BCrypt encryption before storage.
  • Third-Party Profile Identifiers: When utilizing GitHub OAuth2 authentication, we receive your primary verified email address and public username as authorized by your GitHub account settings. We do not access your source code, private repositories, or organizations.
  • Target Endpoint Configurations: Service names and Uniform Resource Locators (URLs) you explicitly register with the engine for automated keep-alive polling.
  • Security & Access Logs: IP addresses and timestamps associated with console authentication requests, used exclusively for rate limiting, abuse mitigation, and account security.

3. Keep-Alive Polling & Telemetry

The primary functionality of UpMe is automated HTTP transmission. When our engine sends requests to your registered endpoints, the operational parameters include:

  • Randomized Pulse Timing: Requests are fired within a dynamic jitter window (randomized between 60 and 300 seconds) to simulate organic availability without triggering container sleeping heuristics.
  • Header Simulation: Requests utilize standard modern browser User-Agent strings and cache-control directives (Cache-Control: no-cache) to ensure pulses reach origin application instances.
  • Recorded Metrics: Following each pulse, the engine records only the resulting HTTP status code (e.g., 200, 404, 500), the round-trip latency in milliseconds, and the UTC execution timestamp.

4. Information We Do Not Collect

To maintain the security and architectural privacy of your software:

  • No API Payload Inspection: We do not parse, record, store, or index the content body returned by your target endpoints. Only status headers and round-trip timing are evaluated.
  • No Financial or Payment Data: UpMe is 100% free. We do not collect, process, or store credit card numbers, billing addresses, or bank account details.
  • No Third-Party Advertising Trackers: We do not monetize user data, sell telemetry to data brokers, or embed third-party surveillance scripts.

5. Data Retention & FIFO Policies

We practice data minimization in our database storage:

  • First-In, First-Out (FIFO) Telemetry Retention: For each active target, UpMe retains a rolling maximum of six (6) ping logs in persistent storage. When a seventh ping is logged, the oldest record is permanently deleted.
  • Monitor Deletion: Removing an endpoint from your console immediately and irreversibly deletes the monitor definition and all associated ping records from the database.
  • Inactive Tokens: Password reset tokens and email verification tokens automatically expire and are purged from database records after 24 hours.

6. Data Security & SSRF Protection

We employ defense-in-depth measures to secure the platform and protect our infrastructure from exploitation:

  • Cryptographic Protections: All console communications occur over Transport Layer Security (TLS 1.3). Passwords are encrypted using salted BCrypt, and API sessions are verified via signed JSON Web Tokens (JWT).
  • Server-Side Request Forgery (SSRF) Filters: All submitted URLs undergo strict domain and IP validation prior to scheduling. Our engine rejects loopback addresses (127.0.0.1, localhost), private RFC 1918 subnets (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), and link-local cloud metadata endpoints (169.254.169.254).

7. Third-Party Authentication (OAuth2)

UpMe supports Single Sign-On (SSO) through GitHub OAuth2. When you authenticate using GitHub, your authentication handshake is managed directly by GitHub Inc. We only receive basic identity confirmation (email and username) necessary to establish your session. You may revoke UpMe's authorization at any time directly through your GitHub Account Settings.

8. User Rights & Data Deletion

Regardless of your geographic location, you retain full autonomy over your stored information:

  • Right to Rectification: You may edit your target names and URLs directly from the dashboard at any time.
  • Right to Erasure ("Right to be Forgotten"): You may delete individual monitors or request the complete deletion of your account and personal identifiers by contacting us. Upon confirmation, all associated data is purged within 48 hours.

9. Children's Privacy

UpMe is an engineering service intended for software developers and system administrators. We do not knowingly solicit or collect personal information from individuals under the age of 16. If we become aware that personal information from a minor has been collected without parental consent, we will take immediate steps to delete that data.

10. Changes to This Policy

We may periodically update this Privacy Policy to reflect enhancements in service capabilities or adjustments to legal compliance. Material revisions will be accompanied by an update to the "Last Updated" timestamp at the top of this document. Continued use of UpMe after changes are posted constitutes acceptance of the revised policy.

11. Contact Information

For inquiries, data erasure requests, or compliance questions regarding this Privacy Policy, please contact our data controller directly:

Controller: Prince Pal
Platform: UpMe Keep-Alive Engine