Last updated 8 September 2026
Uptime IOU, based in the United Kingdom, is the data controller for the information described here. Questions and requests go to hello@uptimeiou.com.
This is the complete list. It is taken from the database schema rather than written generically, so if something is not named here, it is not stored.
Card numbers. The contents of anything you host. Any data flowing through your services. No advertising identifiers, no cross-site tracking, and no profile of you as an individual.
One analytics script runs on the public pages. Sereno Analytics counts page views and which buttons get used, so it is possible to tell which parts of the site are worth keeping. It is cookieless and does not identify individuals — there is no way to tell from it that a particular person visited. It does not run on any page behind a login.
Nothing is sold, shared for advertising, or passed to anyone else.
When an account is closed, the provider credentials are erased immediately, along with the services, outage history, claims and credit records derived from watching your infrastructure. The saved card is dropped at the same moment, so nothing can be charged afterwards.
Records of money actually charged are kept, and this is the one thing that cannot be erased on request. UK tax law requires business records of transactions to be retained for six years, so the amount, date and what it was for survive, together with the minimum identifying detail needed to make sense of them. This is a legal obligation rather than a preference, and it is stated here rather than buried because a promise of complete deletion would not be true.
Under UK GDPR you can ask for a copy of what is held, ask for corrections, ask for erasure (subject to the retention above), object to processing, or complain to the Information Commissioner's Office. Requests go to hello@uptimeiou.com and are answered within one month.
Provider credentials are encrypted at rest. Access to the operator console requires a passphrase and a bot check. Card details never reach this service. No security claim beyond these is made here, because a claim that cannot be evidenced is worse than none.
Not yet reviewed by a solicitor. A Data Processing Agreement is likely required before signing a customer of any size, since this service processes data about their infrastructure on their instruction.