Legal
UpTo Privacy Policy
Privacy Policy for the UpTo app
This policy covers the UpTo mobile app for iOS and Android. It sits alongside the Monument Apps Privacy Policy, which covers our website and sets out your rights, our GDPR basis for processing, and California-specific disclosures. Where the two differ about UpTo, this policy governs.
This policy is effective as of 10 August 2026.
The short version
UpTo is a private place to keep up with friends. There are no ads, no algorithmic feed, and no tracking. We collect what is needed to run the app and nothing else, we do not sell it, and we do not share it with advertisers or data brokers.
What we collect
This list matches the privacy declarations we file with the app stores and the privacy manifest inside the app.
- Email address. Identifies your account and receives sign-in codes. Provided by you, or by Apple or Google when you sign in with them. If you use Sign in with Apple and choose to hide your email, we receive only Apple’s private relay address.
- Name. Your first and last name, which form the display name your friends see.
- Account identifier. An internal identifier for your account, plus the identifier your sign-in provider gives us.
- Photos. Images you attach to posts, and your profile photo. They are resized on your device before upload and held in private storage that requires a signed, expiring link to read.
- Other content you create. The text of your posts and comments, your connections, your blocks, and any reports you submit.
- Time zone. Read from your device so the one-post-per-day rule follows you rather than a stale setting.
- Crash, performance, and diagnostic data. Recorded when the app or our servers hit an error, so we can fix it.
All of the above is linked to your account. None of it is used to track you across other companies’ apps or websites. UpTo contains no advertising identifiers, no analytics SDK, and no third-party trackers.
We do not access your contacts, your location, your microphone, your health data, or any photo beyond the ones you deliberately pick.
Who can see what you post
Content you post in UpTo is not public. Posts, photos, and comments are visible only to people whose connections you have accepted. We do not publish them to a public feed, surface them through discovery or recommendations, sell them, use them for advertising, or use them to train machine-learning models.
Privacy of this kind is a limit on us, not a guarantee about other people. Anyone you have shared something with can photograph or copy it, and we cannot control what they do with it afterwards.
Service providers
These are the only third parties that process personal information on UpTo’s behalf:
- Supabase — authentication, database, and storage of your posts and photos
- Google Cloud Platform — hosting for our application servers
- Resend — delivery of transactional email, such as sign-in codes
- Sentry — crash and error reporting
- Apple and Google — only where you choose to sign in with them
There is no analytics provider, no advertising network, and no payment processor in this list, because UpTo uses none of them.
One thing worth being precise about: our marketing websites do use analytics, and this page is on one of them. Tapping a policy or support link inside UpTo opens a web page in a browser, and while you are on that page the website privacy policy applies rather than this one. The app itself measures nothing about you.
Our crash reporting is configured not to send personally identifying information, and URLs are redacted before a report leaves the app or our servers, so that invitation links and signed photo links are not recorded.
Keeping and deleting your information
We keep your account information for as long as your account exists.
You can delete your account at any time from Settings inside the app. Deletion is permanent. It removes your posts, photos, comments, connections, and sign-in identity. Photos are removed from storage by a scheduled process shortly afterwards.
Two things outlive deletion: reports other people made about your content, which we keep as moderation records, and encrypted backups, which age out on their normal retention cycle. If you cannot get into the app to delete your account, write to hello@monumentapps.com from the address on the account and we will do it for you.
Children
UpTo is not directed at children. You must be at least 13 years old to create an account, and we will terminate any account we learn belongs to someone younger.
Your rights
Your rights of access, correction, deletion, portability, and objection — including under GDPR and California law — are set out in the Monument Apps Privacy Policy and apply to UpTo in full.
Changes to this policy
If we change what UpTo collects or who processes it, we will update this page and the date above before the change reaches you.
Contact
Monument Apps, LLC
hello@monumentapps.com
