Privacy
Draft for the public beta. This page has not been reviewed by a lawyer yet.
This page describes what upTake collects and why, in plain words.
Visitors of a site that uses the upTake script
- The script sets no cookie.
- For each page view, upTake records the page address, the page title, the referring site, campaign parameters, the country and city, the type of device and the browser.
- IP addresses are never stored. They are used once, combined with a secret that changes every day, to compute an anonymous identifier that cannot be linked to the same visitor the next day.
- A random identifier is kept in the browser tab for the length of the visit, to link the pages of one visit together. It is erased when the tab closes.
- Off by default: the site owner can turn on an option that keeps a second random identifier in the browser's local storage for 90 days, to link a first visit to a payment made on a later day. It is not shared between sites. A site owner who turns it on is responsible for telling their visitors and for asking for their consent where the law requires it.
- Visits are deleted automatically after 13 months (395 days).
- For this data, the site owner is the data controller and upTake acts as their processor, under the data processing agreement. To use your rights, contact the site you visited.
Makers who use upTake
- Your account: your email address, and your Google or Discord identity if you sign in with one of them.
- Your project: its address, the description you confirm, your tracked links, the actions you log and your reports.
- Stripe: with the read-only key you provide, upTake imports the amount, currency, date and identifiers of your payments. It never reads card data or customer email addresses.
- A payment is linked to a visit either by an identifier your site passes to Stripe, or by time: the visitor seen on your site in the 30 minutes before the payment. Revenue linked by time is always shown as estimated.
- GitHub: on the repositories you pick, upTake reads release notes and pull request titles. It never reads or stores your code.
- Discord and Slack: if you connect one, your weekly report and alerts (a first payment from a new source, a new release) are posted to the webhook you provide. Nothing is read from Discord or Slack.
- The keys and access you provide are stored encrypted and are never sent back to your browser.
Where the data is
- The database is hosted by Supabase in the European Union (Ireland).
- The application is hosted by Vercel.
Other services we rely on
- PostHog (hosted in the European Union): how you use the upTake app itself, such as pages opened and features used. You are identified by an account number, not by your email. No cookie is set, no session is recorded, and nothing you type is captured. This never covers the visitors of your site.
- Resend: sends the emails upTake addresses to you (reports, alerts, getting-started messages).
- Sentry: receives error reports from the app, with emails, keys and addresses removed first.
- Google Safe Browsing: checks the destination of a redirect link when you create one.
AI
To prefill your project, write your weekly report and draft announcements, upTake sends the text of your homepage, your aggregated numbers and the titles of your posts and releases to Anthropic's Claude API. No visitor-level data is sent. A screenshot you import is sent to the same API to be read, then discarded: upTake does not keep it.
Your rights and your data
- You can export all your data, and delete your account, from Settings. Deleting a project deletes its visits, payments, links, actions and reports.
- You can ask to access, correct or delete your personal data, or object to its use, by writing to [À COMPLÉTER : email de contact].
- If you are in the European Union, you can also complain to your data protection authority (in France, the CNIL).