Uptime Guard (the “App”) is a website, API and domain monitor built to respect your privacy. This policy explains in plain language what data the App handles, where it is stored, and the limited network connections it makes. It is published by Onest Tech (the “Developer”, “we”, “us”), the developer of the App.
The short version
We operate no servers and no accounts. We do not collect, transmit, sell or share your personal data — we never receive it in the first place. Everything you add to the App — the sites you monitor, their check history, your settings and credentials — is stored only on your device, in an encrypted database. The App connects to the internet only to (1) check the websites and endpoints you add, (2) perform diagnostics you explicitly run, and (3) deliver alerts to any notification channels you choose to set up.
1. Who this policy covers
This policy applies to the Uptime Guard mobile application for Android and iOS, published by Onest Tech. It does not apply to the third-party websites, APIs or services that you choose to monitor or query with the App; those are governed by their own privacy policies.
2. Data we do not collect
We want to be explicit about this, because it is central to how the App is designed:
- We do not require or offer an account, login or sign-up.
- We do not operate a backend server; your data is never uploaded to us or synced to any cloud by the App.
- We do not include third-party analytics, advertising, tracking or crash-reporting SDKs.
- We do not collect device identifiers, advertising IDs, contacts, location or usage profiles.
- We, the Developer, do not receive any of the information you enter into the App.
3. Data stored on your device
All information you create in the App is stored locally on your device. It never leaves your device except through actions you explicitly take (see Backups and exports). This includes:
- Monitors you add — names, website URLs and domains, and any logo image you attach.
- Monitoring configuration — check intervals, expected status codes, keyword rules, and pause or snooze state.
- Results and history — check outcomes, response times, uptime statistics, incident records, and TLS/SSL certificate and domain expiry data.
- Imported API collections — for example Postman collections or cURL commands, together with their request definitions, variables, credentials and results.
- App settings and non-personal in-app counters used only to time helpful prompts (for example, when to suggest enabling notifications). These counters stay on your device.
How it is secured
The App’s local database is encrypted at rest using SQLCipher. The encryption key is generated on your device and stored in platform secure storage — the Apple Keychain on iOS, the Android Keystore on Android — and is never written to disk in plaintext. You can optionally enable a biometric or device-credential lock (Face ID, fingerprint or PIN) to restrict access to the App.
4. Network connections the App makes
The App connects to the internet only in the following situations:
| Connection | Where it goes | What is sent |
|---|---|---|
| Website / uptime checks | The websites and URLs you add as monitors | A standard HTTP(S) request with a User-Agent header, which you can configure. No personal data is attached. |
| API monitors | The API endpoints defined in the collections you import | The requests exactly as defined in your imported collection, including any variables or credentials you entered for them. |
| TLS / SSL certificate checks | The host of the site you are checking (port 443 / HTTP) | A connection to read certificate validity and reachability. No personal data is attached. |
| DNS lookup & Domain Health | Google Public DNS (dns.google) over HTTPS |
Only the hostname you enter. DNS-over-HTTPS is required to fetch records such as MX, TXT and NS from a mobile device. |
| Domain registration / expiry | RDAP (rdap.org) over HTTPS |
Only the domain name you are checking, to retrieve public registration and expiry data. |
| Alert channels (optional) | The destination you configure: Slack, Discord, Telegram (api.telegram.org) or any custom webhook URL |
The alert message only — monitor name, the affected host or URL, and the event (for example down, recovered, certificate or domain expiry). |
Aside from the sites you monitor and the services listed above, the App contacts no other third parties.
5. Third-party services
Google Public DNS
The DNS Lookup tool and the DNS portion of the Domain Health report resolve records by
sending the hostname you enter to Google’s public DNS-over-HTTPS resolver
(https://dns.google/resolve). When you use these features, the hostname you
query is transmitted to Google and is subject to Google’s privacy practices. See the
Google Public DNS Privacy page.
RDAP registration data
Domain expiry information is retrieved from the public RDAP service
(rdap.org), which requires no key or account. Only the domain name you are
checking is sent.
Outbound alert channels
Alerting to external services is optional and inactive until you configure it. If you add
an alert channel, the App sends alert messages to the destination you provide —
Slack, Discord, Telegram (via api.telegram.org) or any custom webhook URL.
Those messages contain the monitor name, the affected host or URL, and the event. Data
you send to these services is handled under their own privacy policies, not ours.
6. Permissions and why they are used
| Permission | Purpose |
|---|---|
| Internet | To perform the checks and diagnostics described above. |
| Notifications | To alert you when a monitored site goes down or recovers. Notifications are generated on your device. |
| Biometric / Face ID | Optional. To lock the App so only you can open it. |
| Run at startup & wake lock (Android) | To schedule periodic background checks so monitoring continues without the App open. |
| Foreground service (Android, optional) | Used only if you enable Real-time mode, which re-checks monitors every 1–5 minutes with a persistent status notification. |
| Photos / image picker | Optional. Used only if you choose to attach a logo image to a monitor. The App accesses only the image you select. |
7. Data sharing and disclosure
We do not sell, rent or share your personal data, because we never receive it. The only parties that receive any information are those you direct the App to contact:
- the websites, APIs and hosts you choose to monitor, which receive the checks you configure;
- Google Public DNS and the RDAP service, if and when you use the DNS Lookup or Domain Health tools;
- any alert channel you set up — Slack, Discord, Telegram or a webhook — which receives the alert messages described in Section 4.
Each of these is governed by its own privacy policy. We may disclose information only if required to do so by law — but note that we, the Developer, hold no user data to disclose.
8. Backups and exports
The App lets you export or back up your data to a file. This is entirely user-initiated: the exported file is created only when you choose to export, and it is placed where you direct it — for example saved locally or sent through your device’s share sheet. Once you share or store an exported file outside the App, it is under your control and the control of any service you send it to. We recommend protecting exported files, as they contain your monitoring data.
9. Data retention and deletion
Because your data lives only on your device, you are always in control of it:
- Delete an individual monitor, incident or history entry from within the App at any time.
- Uninstalling the App removes its local database and its encryption key from your device, permanently deleting everything the App stored.
We apply no retention period of our own, because we hold no copy of your data.
10. Children’s privacy
The App is a general-purpose developer and operations tool and is not directed to children. It does not knowingly collect personal information from anyone, including children.
11. Your rights
Depending on where you live, you may have rights under laws such as the GDPR or the CCPA — for example to access, correct, export or delete your personal data. Because all of your data is stored locally on your device and we neither hold nor process it, you can exercise those rights directly and immediately: view, edit, export or delete your data in the App, or uninstall it. If you have questions about this, contact us using the details below.
12. Changes to this policy
We may update this policy from time to time — for example if features change. When we do, we will revise the “Last updated” date at the top of this page and, for material changes, provide notice within the App or on this page. Continued use of the App after an update constitutes acceptance of the revised policy.
13. Contact us
If you have any questions about this Privacy Policy or the App’s privacy practices, we are happy to answer them:
Onest Tech — developer of Uptime Guard
Email: [email protected]
Support: Support & FAQ
This page is published to satisfy the privacy policy requirements of Google Play and the Apple App Store.