digitup

Privacy

We collect as little as we can to check and watch your sites, and we never sell data or show ads. Here's exactly what we keep and why.

Who is responsible

digitup, based in the United States, is responsible for the data described here.

Checking a site without an account

  • The address you enter and what the check found.
  • A one-way hash of your IP address (never the address itself), your browser's user agent, and a random ID kept in your browser. We use these only to limit how many checks one person can run.

Checks made without signing in are deleted after 6 hours. We keep this to stop abuse of the service (our legitimate interest, Art. 6(1)(f) GDPR).

Your account

  • Your email address, name and password. We only store a hash of the password.
  • If you sign in with GitHub, Google or Vercel: the name, email address and picture they share with us.
  • For your security, each signed-in session records the IP address and browser it was started from.

We need this to provide the service you signed up for (Art. 6(1)(b) GDPR). We keep it until you ask us to delete your account.

Your sites, checks and monitoring

  • The sites you add, how you proved they're yours, and the results of checks and monitoring.
  • We don't keep the content of your pages. Anything in a finding that looks like a key or password is masked before we store it.
  • If you set up tests of sign up, log in or checkout: the test account's details, encrypted, screenshots of failed tests, and emails sent to the test inbox we give you.
  • If you connect GitHub: we read the repositories you choose, only to check them. The code isn't kept after the check, only the findings, with secrets masked.

We keep these while your account exists, or until you remove the site.

Alerts

  • Your email address for alert emails and the weekly summary. Every email has a link to turn it off.
  • If you connect WhatsApp: your mobile number. If you connect Telegram: your chat ID and username.
  • A record of which alerts we sent, so we don't send one twice and can keep to the daily limit.

Removing a channel deletes its number or chat ID. Replying STOP on WhatsApp or /stop on Telegram does the same.

The error script on your site

If you add our script to your site, it tells us how many pages were viewed and which errors your visitors hit. It uses no cookies, doesn't identify visitors and doesn't send us their IP address. Error messages are stripped of email addresses and long numbers, and addresses of failed requests are stored without their query strings.

For your visitors' data you are the controller and we process it on your behalf.

Cookies

We only use the cookies needed to keep you signed in. Your browser also stores a random ID and a few settings in local storage. No analytics, no advertising and no tracking across sites.

Service providers

We use trusted providers for hosting, email and sign-in. Data may be processed in the United States, covered by standard contractual clauses.

Your rights

Depending on where you live, you can ask to see, correct, delete or export your data, and to restrict or object to how we use it. You can remove sites, alert channels and connected code yourself at any time. For anything else, write to hello@digitup.dev; we'll answer within a month. In the EU and UK you can also complain to your local data protection authority.

See also the privacy policy and the terms.

Last updated 3 October 2026.