Skip to main content

Legal

Privacy Policy

A clear account of what personal data upwhisper collects, why we need it and the rights you retain under the GDPR.

Effective 2026-07-13.

1. Who is responsible for your data

This website and service are operated as an independent project by Nbal Jabr, a private individual based in Sweden. I am the data controller responsible for the personal data processed through upwhisper.com. For questions about this privacy policy or to exercise your data protection rights, contact us at contact page.

2. What we collect

Account data: your name, email address, and password (stored as a salted hash, never in plain text) when you sign up, plus your role and company/account membership.

Billing data: if you're on a paid plan, Stripe processes and stores your payment details on our behalf - we never see or store your full card number ourselves, only the subscription status and billing history Stripe returns to us.

Domain and monitoring data: the hostnames you add for monitoring, and the check results we collect for them (SSL, DNS, registration, email-security, and HTTP data) - this is customer content you control, not personal data about you specifically, unless a hostname itself happens to identify a person.

Technical and abuse-prevention data: Vercel processes request logs as our hosting provider. The application also stores short-lived rate-limit records keyed by data such as an email address, user, account, domain, or source IP, depending on the action being protected. We use Vercel Analytics for aggregate page-view data (see “Cookies and analytics” below).

Communications: anything you send us via the contact form or email support, including the content of your message.

4. Who we share it with

We don't sell your personal data. We use the following providers to operate the Service:

Stripe (payment processing and billing) - stripe.com/privacy.

Resend (transactional email delivery for alerts, invites, and password resets) - resend.com/legal/privacy-policy.

MongoDB Atlas (database hosting for account and monitoring data).

Vercel (application hosting, and basic, privacy-focused page-view analytics) - vercel.com/legal/privacy-policy.

These providers publish their own privacy and data-transfer information. Their processing locations and safeguards can change, so consult their current policies for details.

We may also disclose data if required by law, or to protect the rights, property, or safety of upwhisper, our users, or the public.

5. How long we keep it

Account data: while the account is active and afterward only as needed to handle a deletion request, resolve disputes, or meet legal obligations. Contact us to request account deletion; self-service account deletion is not currently available.

Domain data: until you delete the domain or request account deletion. Deleting a domain also deletes its associated check history.

Full check results: automatically expire after 90 days, even while a domain remains monitored.

Password-reset links expire after one hour and email-confirmation links after 24 hours. Their token records are removed shortly after expiry.

Application rate-limit records expire after one hour. Hosting, email, analytics, and billing providers apply their own retention periods.

Billing records: for as long as needed to administer subscriptions and meet applicable accounting or legal obligations.

6. Your rights under the GDPR

You have the right to access the personal data we hold about you, request correction of inaccurate data, request erasure (“right to be forgotten”), request that we restrict or object to certain processing, and request a portable copy of your data in a structured, machine-readable format.

Where processing is based on consent, you can withdraw it at any time without affecting processing carried out before the withdrawal.

To exercise any of these rights, reach us through our contact page. We'll respond within one month, as required by the GDPR.

If you're not satisfied with our response, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with the data protection authority in your own EU/EEA country of residence.

7. Cookies and analytics

We use essential authentication, security, and selected-account cookies to keep signed-in sessions working. They are not used for advertising.

We use Vercel Analytics to understand aggregate page traffic. See Vercel's current privacy documentation for the data it processes and how it handles that data.

8. Security

Passwords are hashed, never stored in plain text. Authentication cookies use security attributes including httpOnly, and sensitive two-factor secrets are encrypted at rest. We rate-limit sensitive and expensive actions, and monitoring targets are screened to reject private or internal addresses identified before connection.

No system is perfectly secure, but we design and review the Service with these protections as a baseline, not an afterthought.

9. Children's privacy

The Service is intended for business use and isn't directed at children. We don't knowingly collect personal data from anyone under 16.

10. Changes to this policy

We'll update this page and its effective date if how we handle personal data changes.

11. Contact

Questions about this policy or your data? Reach us through our contact page.