Privacy
What we keep, and what we don't
Last updated 25 August 2026
UpkeepMinder holds a list of things you look after and when you last serviced them. That is not especially sensitive, and it is still yours. This page says exactly what is stored, who can reach it, and how to get rid of all of it.
Nothing here is sold, rented, or shared with an advertiser. There are no third-party analytics, no tracking pixels, and no ad network. There is no revenue model that would make any of that tempting later.
What is stored
| What | Why | How long |
|---|---|---|
| Your email address, and your name and picture if you sign in with Google | To have an account at all, and to know who logged a service in a shared workspace | Until you delete the account |
| Your assets, timelines, tasks and service records | It is the product | Until you delete them, or the account |
| Files you attach — receipts, photos | Because a service record with the receipt on it is worth more than one without | Until you delete them, or the account |
| Your timezone and email preferences | So a reminder arrives in the morning rather than at 3am | Until you delete the account |
| A hash of your session cookie | To keep you signed in | 60 days, or until you sign out |
| A record that a digest was sent to you | So a retry cannot send the same email twice | 120 days |
| A count of feedback reports, with a salted hash of the sending address | To rate-limit the form. Not the message, and not who wrote it | 400 days |
Passwords
There are none. You sign in with Google or with a one-time link sent to your email, so there is no password stored here to leak and none for you to reuse from somewhere else.
Session cookies
One cookie, um_session, which holds a long random value and nothing about you. Only its
hash is stored on our side, so a copy of the database is not a set of live logins. There are no other
cookies — nothing for analytics, nothing for advertising.
Who can see it
Your personal assets are visible to you. Anything in a shared workspace is visible to every member of that workspace, which is the point of one — including your name on the records you log there. Leaving a workspace stops your access to it; the records you logged stay, because the work still happened.
On our side, the operator can reach the database. That access is used to keep the service running and to answer a report you have sent in, not to read through what people are maintaining.
Where it lives
On Cloudflare — the database is Cloudflare D1 and attached files are in Cloudflare R2, both accessed only by the app's own server code. Email is sent through Cloudflare Email Service. Sign-in with Google sends Google a request to verify your identity token, which is what makes that button work; Google is told nothing about what you track.
UpkeepMinder previously ran on Google Firebase. Data moved to Cloudflare in August 2026, and the Firebase copy is being decommissioned.
Six kinds of message, and the list is closed:
- A sign-in link, when you ask for one.
- A weekly note about services coming due.
- A weekly note about services that are overdue.
- A note when a meter has gone long enough unread to make everything under it inaccurate.
- A weekly summary of what somebody else logged in a workspace you share.
- A monthly recap, if you switch it on.
Every one of those can be turned off individually, from Settings or from the link at the bottom of the message — the link works without signing in, because somebody who has lost access to an account must still be able to make the mail stop.
Separately and rarely, we may email every account holder about a change to the terms or about the service closing down. That has no unsubscribe link, because it is not a newsletter and there is nothing recurring to leave: it is the only way to tell you something you are owed in writing. It carries no offer and nothing to click but the app, the terms, and your account.
The feedback form
A report goes to one mailbox that a person reads. It carries what you wrote, the address you chose to give, and a bundle of facts about the app's state — the page you were on, your browser, how many assets and tasks you have. The dialog prints that bundle in full before you send it.
It does not carry your asset names, task names, notes, memos or any meter reading. What is stored in the database afterwards is a count: the topic, the day, and a salted hash of the connecting address so the form can be rate-limited. Not the message.
Getting your data out
Your service history exports to CSV from the History tab, any time, no request needed. That is deliberate — a free service that might one day stop has no business being the only copy of your records.
Deleting it
Deleting your account removes the account, every asset, timeline, task and service record in your personal space, every file you uploaded, your sessions, and your email preferences. Not archived, not flagged — deleted.
Workspaces you own alone go with you. Workspaces with other people in them do not, because their assets and their history are not yours to delete: you are removed from the workspace, and if you were its only owner, the longest-standing remaining member becomes one.
Records of digests already sent to you, and the anonymous feedback counts, are not tied to your identity once the account is gone and age out on the schedule in the table above.
Children
UpkeepMinder is not aimed at children and is not designed for use by anyone under 13.
Changes to this page
If what we do with your data changes in substance, the date at the top changes and every account holder is emailed about it. Fixing a typo is not a change in substance and will not generate an email.
Getting in touch
Use the feedback button anywhere in the app, or write to jettstauver829@gmail.com.