What does an account store?
A user record holds a name, an email address, whether that email is verified, and a password hash when the person signs in with a password. A session stores a token, plus the IP address and user agent captured at sign-in.
This is a draft for the product under construction. It says what the software stores. It is not legal advice and it is not the final policy.
Last updated 29 September 2026.
A user record holds a name, an email address, whether that email is verified, and a password hash when the person signs in with a password. A session stores a token, plus the IP address and user agent captured at sign-in.
The target URL, the schedule, check results (status, timing, a short redacted error), and certificate dates for TLS monitors. Authorization headers and notification secrets are encrypted before they are written. Heartbeat tokens and invitation tokens are stored as hashes.
Workspace members see the monitors in that workspace. A public status page shows the monitors attached to it. It does not show credentials or the probe URL. Status-page subscribers are emailed only after the address is verified.
Raw check rows follow the retention days on your plan. Aggregate uptime is kept so the status page can show a history after the raw rows are gone. You can ask hello@upkira.com to delete a workspace once account deletion is available in the product.