upuppy — Privacy Policy

Last updated: 22 September 2026

upuppy monitors status pages and tells you when the services you rely on break. It needs remarkably little about you to do that, and this policy is meant to be specific about the little it does need rather than reassuring in general terms.

There are no accounts, no advertising, no analytics, and no tracking. We do not sell or share personal information, and nothing here is used to build a profile of you. The app contains no analytics or crash-reporting code. If you have chosen to share app analytics with developers in your Apple settings, Apple may show us aggregated, anonymous statistics; that is Apple's feature and your choice.

What stays on your device

On macOS and Windows, upuppy checks status pages directly from your computer. Your list of monitored services, their history, and your preferences are stored locally. They are not sent to us, and we cannot see them.

What the push service receives (iOS)

iOS cannot check status pages in the background, so alerts for the iOS app are delivered by our push service. To do that it stores:

What Why How long
A device token from Apple To deliver a notification to that device Until the device stops responding, or 30 days without contact
A random device identifier and secret So the device can prove a request is really from it Same
The list of status pages you follow So the service knows what to check and whom to notify Until you change it, or the device is removed
Your notification sound choice So a push respects the setting you picked Same
Purchase records from Apple To verify access and retain refund history See Purchases below

Your list of monitored services is the most sensitive thing here. It can suggest which vendors you use. It is stored so the service knows what to poll, it is never sold or shared, and deleting a service or turning off notifications for it removes it.

We do not receive your name, email address, Apple ID, contacts, location, or any advertising identifier.

Your IP address is visible to the push service whenever your device contacts it, as it is to any internet service. We use it only in memory, to limit abusive request rates, and do not store it in our database. It does appear in the standard request logs kept by Cloudflare and by our web server; ours are deleted automatically within about eleven weeks.

Purchases

Purchases are handled by Apple, which acts as the seller. We never see your card details or billing address.

To know whether your subscription is active, we store what Apple tells us: a transaction identifier, which product was bought, its expiry or refund dates, and whether it came from the production or test environment. Apple also notifies us of renewals, cancellations and refunds so access stays accurate without the app being opened.

Purchase records are not deleted when you disable notifications, uninstall the app, or when a device registration expires. They preserve renewal and refund history so an older proof of purchase cannot restore access that was refunded.

Contact us to request earlier deletion. Deleting a purchase record can require restoring purchases before the service recognizes your access again.

Service icons

To show a service's icon, the app requests it from that service's own website first, and falls back to DuckDuckGo's icon service. Those requests reveal the hostname of the service whose icon is being fetched. DuckDuckGo was chosen specifically because it does not use these requests for advertising; a previous version used Google, which we removed for that reason.

Processors

If you are in the EU, UK or a similar jurisdiction

Twilight Coders, LLC is the controller of the data described here. We process push registration and purchase data because it is necessary to provide the service you asked for (performance of a contract), and IP addresses for our legitimate interest in protecting the service from abuse. Data is processed in the United States.

You have the right to access, correct, delete or receive a copy of your data, to object to or restrict its processing, and to complain to your local data protection authority. The push service does not know who you are, so the quickest way to delete a device's push data is to turn off notifications in the app (see Deleting your data). For anything else, contact us at the address below.

Security

Every request from a device is individually signed, so one device cannot act as another. Device secrets are stored in the iOS Keychain, marked so they are not copied to iCloud or into backups.

Deleting your data

Turn off notifications in the app to request deletion of that device's push registration and subscriptions. The app retries if the service is unreachable; deletion takes effect when the request succeeds. Uninstalling cannot send a deregistration request. Abandoned registrations are removed when Apple reports an invalid token or after 30 days without contact, during the next cleanup run. Purchase records are handled separately as described above.

For anything else, contact us at the address below and we will delete what we hold.

Children

upuppy is not directed at children under 13 (or the equivalent minimum age where you live) and does not knowingly collect information from them.

Changes

If this policy changes materially, the app and this page will say so.

Contact

Twilight Coders, LLC
7262 Meade St, P.O. Box 1005, Westminster, Colorado 80030, USA
upuppy@twilightcoders.net