OpenUptime

Privacy Policy

OpenUptime is open-source uptime monitoring and status pages. This policy explains what the hosted service at openuptime.app collects, why, and what control you have. It is written by the OpenUptime contributors and describes how the software actually behaves; the source is public so you can check.

What we collect

  • Account data: your email address and name, and a hash of your password (we never store the password itself). If you sign in with GitHub, we receive your GitHub profile name, email and account identifier.
  • Session data: when you sign in, a session record is created with a random token, expiry, and the IP address and user agent of the device.
  • Workspace content you enter: workspaces, projects, monitors (names, target URLs and hosts, headers, keywords), check results (status, latency, status code, error text), incidents and updates, maintenance windows, status pages, and team membership.
  • Alert channel configuration: the destinations you configure for alerts, such as email addresses, Slack or generic webhook URLs, Telegram bot tokens and chat IDs, and PagerDuty routing keys. Treat these as secrets and use dedicated webhooks and bots.
  • Alert delivery log: a record of which alerts were sent to which channel and whether delivery succeeded.
  • API keys: keys you create to call the API, with the workspace and projects they are limited to.
  • Status page subscribers: if you subscribe to someone's public status page, we store your email address, preferred language and a confirmation token so we can email you about incidents.
  • Rate-limit counters: short-lived counters keyed by client IP address, used to stop abuse of public endpoints such as status page subscriptions. They are removed within about a day.

Cookies and local storage

We use only functional cookies, and no tracking or advertising cookies.

  • A signed session cookie that keeps you signed in.
  • ou_lang: your language choice.
  • ou_project: the project you last selected in the app.
  • Your light/dark theme preference is kept in your browser's local storage and never sent to us.

What we do not do

  • No advertising and no selling or renting of personal data.
  • No advertising or cross-site tracking scripts. The hosted site uses Plausible-style, cookie-free analytics (script served from click.pageview.click) that counts page views in aggregate and does not build profiles of individuals. The pages load fonts from Google Fonts, which means your browser contacts Google to fetch them.

How we use data

We use your data to run the service: authenticating you, running your checks, opening and resolving incidents, sending alerts and notification emails, showing your status pages, and preventing abuse. We do not use your monitoring data for any other purpose.

Who processes data

  • Cloudflare runs the application on Cloudflare Workers, connects to the database through Hyperdrive, and sends transactional email (sign-in, password reset, invitations, alerts, subscription confirmations) through Cloudflare Email Service.
  • The database provider hosts the Postgres database that stores the data described above.
  • Destinations you configure: when an alert fires, we send its content (monitor name, target, incident title) to the Slack, Telegram, PagerDuty, webhook or email destination you set up. Those services have their own policies.

Retention

  • Check results are kept for 90 days, then deleted. A per-workspace setting for this is planned.
  • The alert delivery log is kept for 30 days by default; workspace owners can change this from 1 to 365 days in settings.
  • Account, workspace, monitor, incident and status page data is kept until you delete it or delete your account.
  • Subscribers remain until they unsubscribe (every email contains an unsubscribe link) or the status page owner removes them.

Your rights

You can access, correct, export and delete your data. Export and account deletion are available from account settings in the app (/app/account), which are still being finished; until they are live, email us and we will handle your request. Workspace owners can also remove monitors, status pages and subscribers at any time. If you are in a region with data protection law such as the EU or UK, you also have the rights to object to or restrict processing and to complain to your data protection authority.

Security

Traffic is encrypted in transit. Passwords are stored only as hashes. No system is perfectly secure; if you find a vulnerability or suspect a breach, please contact us at privacy@openuptime.app.

Children

OpenUptime is not intended for people under 16 and we do not knowingly collect their data.

Changes

If we change this policy in a material way we will update the date below and, where practical, notify account holders by email.

Contact

OpenUptime contributors · privacy@openuptime.app

隐私政策

OpenUptime 是开源的可用性监控与状态页服务。本政策说明 openuptime.app 托管服务收集哪些数据、为什么收集,以及你可以如何控制。本政策由 OpenUptime 贡献者撰写,并如实描述软件的实际行为;源代码公开,欢迎核对。

我们收集的数据

  • 账户数据:你的邮箱、姓名和密码哈希(我们不会保存密码明文)。如果使用 GitHub 登录,我们会获得你的 GitHub 名称、邮箱和账号标识。
  • 会话数据:登录时会创建会话记录,包含随机令牌、有效期,以及设备的 IP 地址和 User Agent。
  • 你录入的工作区内容:工作区、项目、监控项(名称、目标地址、请求头、关键字)、检测结果(状态、延迟、状态码、错误信息)、事件及更新、维护窗口、状态页和团队成员。
  • 告警渠道配置:你设置的告警目的地,例如邮箱地址、Slack 或自定义 Webhook 地址、Telegram 机器人令牌与聊天 ID、PagerDuty 路由密钥。请将它们视为机密,并使用专用的 Webhook 和机器人。
  • 告警投递日志:记录哪些告警发送到了哪个渠道,以及是否发送成功。
  • API 密钥:你为调用 API 创建的密钥,以及其限定的工作区和项目。
  • 状态页订阅者:如果你订阅了某个公开状态页,我们会保存你的邮箱、语言偏好和确认令牌,以便就事件向你发送邮件。
  • 限流计数:以客户端 IP 地址为键的短期计数器,用于防止滥用公开接口(例如状态页订阅),约一天内清除。

Cookie 与本地存储

我们只使用功能性 Cookie,不使用任何跟踪或广告 Cookie。

  • 保持登录状态的已签名会话 Cookie。
  • ou_lang:你选择的语言。
  • ou_project:你在应用中最近选择的项目。
  • 浅色/深色主题偏好保存在浏览器本地存储中,不会发送给我们。

我们不会做的事

  • 不投放广告,不出售或出租个人数据。
  • 不含广告或跨站跟踪脚本。托管版使用 Plausible 风格的无 Cookie 统计(脚本来自 click.pageview.click),仅汇总统计页面浏览量,不建立个人画像。页面会从 Google Fonts 加载字体,因此你的浏览器会访问 Google 以获取字体文件。

数据的用途

我们仅将数据用于运行服务:验证身份、执行检测、创建与恢复事件、发送告警与通知邮件、展示状态页以及防止滥用。我们不会将你的监控数据用于其他目的。

数据处理方

  • Cloudflare:应用运行在 Cloudflare Workers 上,通过 Hyperdrive 连接数据库,并通过 Cloudflare Email Service 发送事务性邮件(登录、重置密码、邀请、告警、订阅确认)。
  • 数据库服务商:托管存放上述数据的 Postgres 数据库。
  • 你配置的目的地:告警触发时,我们会把内容(监控名称、目标、事件标题)发送到你设置的 Slack、Telegram、PagerDuty、Webhook 或邮箱,这些服务有各自的隐私政策。

保留期限

  • 检测结果保留 90 天后删除。按工作区配置该期限的功能正在计划中。
  • 告警投递日志默认保留 30 天;工作区所有者可在设置中调整为 1 至 365 天。
  • 账户、工作区、监控项、事件和状态页数据保留至你删除这些数据或删除账户为止。
  • 订阅者会保留至其退订(每封邮件都含退订链接)或被状态页所有者移除。

你的权利

你可以访问、更正、导出和删除自己的数据。导出和账户删除功能位于应用的账户设置中(/app/account),目前仍在完善;在其上线之前,请发邮件给我们,我们会处理你的请求。工作区所有者也可以随时删除监控项、状态页和订阅者。如果你位于欧盟、英国等有数据保护法的地区,你还享有反对或限制处理的权利,并可向数据保护机构投诉。

安全

传输过程加密,密码仅以哈希形式保存。没有任何系统是绝对安全的;如发现安全漏洞或怀疑发生数据泄露,请联系 privacy@openuptime.app。

未成年人

OpenUptime 不面向 16 岁以下人群,我们不会有意收集其数据。

政策变更

如对本政策作出重大修改,我们会更新下方日期,并在可行时通过邮件通知账户持有人。

联系我们

OpenUptime 贡献者 · privacy@openuptime.app

Last updated 2026-10-10最后更新:2026-10-10