Effective: October 10, 2026
Last updated: October 10, 2026
This notice covers the UpBeep apps for Windows, iPhone, Apple Watch and Android, our servers, our website upbeep.app, buying UpBeep, and support. UpBeep is made by Adam K Goodwin, a sole proprietor doing business as UpBeep ("we", "us").
In short
No accounts, no analytics, no advertising. We don't sell information or use it for advertising.
Most things stay in your office. Your pages, messages, tasks, office calendar, people's names, notes, office map, and voice messages and their transcripts are stored on your office's own computers and phones, and travel over your office's own network.
Some things do leave your office. Section 2 lists each one:
Notices that wake a locked phone. These go through our push server, then Apple (for an iPhone) or Google (for an Android phone). Page notices can be read by our push server, and on an iPhone by Apple too, as can the iPhone's "Waiting on you" notice. Message notices are sealed, as are task notices where available and every notice to an Android phone, so Apple and Google can't read them.
Messages for phones away from the office (and, where available, task notices). Where this feature is switched on, they travel through our relay on Amazon Web Services, sealed end to end so the relay can't read them. They're held only until they're delivered, and deleted after a few days at most. Pages never travel this way.
The licence check-in, to confirm your subscription.
Dictation. Speech dictated on a watch or a phone keyboard is turned into text by Apple, Google or the device's maker.
Buying through Paddle.
Update checks and downloads (from GitHub), and an optional speech model (from Hugging Face).
Things you choose to send us: support emails, crash reports and logs.
Visiting our website.
Patient information. UpBeep is not meant for patient information, and your office agrees to keep anything that could identify a patient out of it. We offer no business associate agreement (BAA). Please read section 10.
1. What stays in your office
These never leave your office's network through UpBeep, except as section 2 describes:
What you put into UpBeep:
the office's name and map, rooms, page types, and people's names;
pages, and who cleared them;
messages, replies, reactions, read receipts, typing, polls, status and staff photos;
tasks and lists: what they say, who they're assigned to, due dates and reminders, who completed them, comments and hearts;
the office calendar: opening hours, closed days and holidays, including any your office imports;
timers, reminders and sticky notes.
It's all stored on your office's computers and paired phones, and sent only to your other UpBeep computers and paired phones over your own network. Where task notices for phones are available, they travel the same way. Sticky notes and the privacy screen stay on their own computer.
Voice. Voice messages and their written transcripts are made on your office's own computers, and the audio for transcription is thrown away. Nothing is sent anywhere to be transcribed. (A testing switch, off unless someone turns it on, keeps recordings on that computer and turns itself off after 24 hours.)
Pairing a phone. A phone joins your office by scanning a code shown on an office computer, or by typing its eight letters. There's no account and no email. The phone asks for the office password, if your office has one, and the name of the person it belongs to. Both stay in your office.
Phones and watches.
iPhone. The iPhone app talks to your office computers over your office network. Its only other internet contacts are Apple's push registration (section 2.1) and, if messages away from the office is on and the phone is away, our relay (section 2.2).
Android. The Android app talks to your office computers over your office network. Its only other internet contacts are Google's Firebase Cloud Messaging, which gives the phone a push address and delivers its wake-up notices (section 2.1), and, if messages away from the office is on and the phone is away, our relay (section 2.2). We don't use Firebase for analytics or advertising.
Apple Watch. The watch works through its iPhone.
Other smartwatches. The Wear OS app isn't available yet. A watch paired with an Android phone, such as a Samsung Galaxy watch, can show the phone's UpBeep notifications, as the phone's and the watch's own settings allow (section 2.9).
The diagnostic log on each computer. It leaves only if someone sends it (section 2.7).
Encryption on your network:
With an office password, UpBeep encrypts everything it sends between your computers.
Without one, other devices on your network can read that traffic. We recommend setting a password.
Phone links are always encrypted with that phone's own key.
A password is also needed for sealed message notices, for notices to Android phones, and for messages away from the office (section 2).
2. What leaves your office
2.1 Waking a locked phone (our push server, Apple and Google)
So that a locked phone still gets pages and messages (and, where available, task notices), an office computer also sends a notice through our push server (on Amazon Web Services) to Apple's push service for an iPhone, or to Google's Firebase Cloud Messaging for an Android phone. Apple or Google then delivers it to the phone. This happens only if your office has paired a phone. An office that pairs no phone never contacts our push server.
(a) Registering the office and its phones. When the app starts, a paired iPhone gets push addresses ("tokens") from Apple, and an Android phone gets one from Google's Firebase, without asking. The phone gives them to an office computer over your Wi‑Fi. That computer then registers the office once, and each phone whenever its tokens change and again after the computer restarts. With messages away from the office on, a phone that's away can also send our push server a new token itself (section 2.2). Turning off notifications on an iPhone doesn't stop this, and the same may be true on Android.
To get its push address, the Android app's Firebase software registers the app with Google, as any Android app that uses Google's push service does. It may send Google technical details needed to deliver notices, such as an identifier for that installation of the app. Google handles this under its own terms.
| Item | What is sent |
|---|---|
| The office | Its public key (used to check that requests really come from your office) |
| Every request | An office identifier made from that key; a short identifier for the sending computer, made from a hash; the time; a one-time number; a signature; and, like any internet request, your office's internet (IP) address |
| Each phone | A random phone identifier; the platform (iPhone or Android); for an iPhone, Apple's environment setting and up to three Apple push tokens (for notices, the lock-screen activity, and starting that activity); for an Android phone, one Google push token; and, if your office uses messages away from the office, the phone's public signing key, so our relay can check requests that come straight from that phone |
(b) Page notices. Our push server can read these, and so can Apple on an iPhone. A page is sent this way when the phone:
is paired and has a push token;
was heard on your office Wi‑Fi in the last 30 minutes;
isn't set to Away (Emergency still goes through);
is in an office that isn't in privacy-screen-only mode;
didn't confirm the page over its own link within 5 seconds;
for an Android phone, is in an office that has a password (because the notice must be sealed, as described below).
The notice carries, readable to our push server:
the place: the room name, or the person's name for a page sent to a person, or "Reminder";
the page name: for a reminder or timer, the reminder's own typed name (up to 60 characters are sent);
the sender's label;
whether it's an Emergency, when the page opened, and whether it's a quiet page;
identifiers for the page and the phone;
when your office last saw that phone on its Wi‑Fi;
whether the phone allows Critical Alerts.
For an iPhone, Apple receives:
the title "‹page› · ‹place›" and the text "From ‹sender›";
the category and identifiers;
an instruction to discard the notice after 60 seconds if it can't be delivered.
These notices are encrypted on the way (TLS), but our push server and Apple can read the place, page name and sender.
For an Android phone, the place, page name and sender are sealed inside the notice before it leaves your office, as described in (d). Google gets only the push token, an identifier, how long to keep trying (60 seconds) and the sealed notice, so Google can't read the place, page name or sender. The phone opens the seal and shows the page on its lock screen.
Notes on pages are never sent in readable form. An iPhone notice leaves them out, and an Android notice can carry them only inside the seal.
(c) The iPhone "Waiting on you" lock-screen notice. This can be read by our push server and Apple. When an iPhone that's in the office (seen in the last 30 minutes) isn't connected to the office and pages are waiting, the lock screen shows a live "Waiting on you" count. A notice is sent when it starts, on every change, every 10 minutes while pages wait, and when it ends.
It carries, readable:
your office's (clinic's) name (when it starts);
the number of waiting pages;
the oldest waiting page's room (or person, or "Reminder"), its page name (or reminder name) and when it opened;
"Emergency · ‹room›" while an Emergency waits;
the time;
the phone identifier and when the office last saw that phone.
When it starts, Apple shows "Waiting on you · N" with "‹page›, ‹room›".
(d) Message notices (and, where available, task notices). Sealed, so our push server, Apple and Google can't read them. These notices need your office to have a password.
Message notices to an iPhone near the office. If your office doesn't use messages away from the office (section 2.2), a message notice is sent to an iPhone only if:
your office is in full mode;
the iPhone isn't connected right now, was in the office within 30 minutes, and isn't set to Away;
the message is new (from the last 2 minutes) and isn't the phone's own.
There are at most 5 notices per phone per minute, and 20 while it's locked.
With messages away from the office. Where this feature is switched on, a notice is sent to a phone that uses it whenever no office computer is connected to that phone, whether the phone is in the office or away. It tells the phone that a sealed message (or, where available, a task notice) is waiting for it in our relay (section 2.2), and may carry a sealed copy of it. A phone set to Away isn't woken for other people's messages; they wait until the phone checks. There are at most 30 wake-ups per phone per minute, then one "more" notice.
Before it leaves your office, each notice is sealed end to end between your office's computers and that phone. It's padded to one of a few fixed sizes and locked with keys that we never have, so only that phone and your office's own UpBeep computers can open it. Sealed inside are:
for a message: the sender's name and room; the time; whether it's Private or mentions the person; the kind of message; and its text or a preview of it (a notice to an iPhone near the office carries no preview for a Private message, and says only "Voice message" for a voice message);
for a task notice, where available: what the notice says, and identifiers for the task;
for a page to an Android phone: the page details listed in (b).
What isn't sealed:
Our push server sees: the phone identifier; an identifier fixed for that item and phone; the notice's padded size; the expiry time; the office and computer identifiers; the timing; the internet address; and, for some notices, the minute the phone was last seen on your office Wi‑Fi.
Apple sees: the push token; fixed generic words, such as "New message"; the category; an identifier; whether the notice makes a sound; and the sealed bytes. Where task notices are available, Apple can tell them apart from message notices.
Google sees: the push token; the time; how long to keep trying; an identifier; and the sealed bytes, padded to a fixed size. Google gets no wording.
So our push server, Apple and Google learn which phone got a notice, and when, but not who sent it or what it says.
What our push server keeps. Page and "Waiting on you" contents are passed on and not stored or logged. Sealed notices are passed on and not stored. The only sealed items it keeps are those waiting in the relay (section 2.2). Otherwise it keeps only:
| Record | Kept for |
|---|---|
| Office record: its public key, office identifier, a tag for each computer with its last request time, and which computer is collecting for the office | Deleted 30 days after the office's last request |
| Phone record: phone identifier, platform, environment, up to three Apple push tokens or one Google push token, the phone's public signing key (if your office uses messages away from the office), status and timestamps | Deleted 60 days after the phone was last registered, or last used our relay, whichever is later. Notices alone don't extend this. Removing a phone in UpBeep may not delete this record straight away, so it can stay until it expires. Email us to delete it sooner. |
| One-time numbers (to block replayed requests) | 10 minutes |
| Rate counters | About 1 minute |
| A daily hash of the internet address, to limit new-office sign-ups | About 1 hour |
| A counter per message or page notice, to avoid duplicates | 1 hour |
| Server logs (Amazon CloudWatch): fixed wording only, with no identifiers, tokens or internet addresses | 14 days |
Deletion happens automatically and can lag by a few days. The push server keeps no backups.
Apple and Google hold an undelivered notice until it expires: for a page, "Waiting on you" or message notice, 60 seconds (at most 5 minutes; up to 1 hour for the end of "Waiting on you"). With messages away from the office, a wake-up about an item waiting in our relay can be held for up to the rest of the time the relay holds that item (a few days at most). Apple's privacy policy and Google's privacy policy apply to their handling.
Your choices:
Don't pair phones, or remove them.
Set a phone to Away.
Use privacy-screen-only mode.
To stop message notices: an office without a password gets none. An Android phone in an office without a password gets no page notices through Google either.
An office administrator can turn off Messages away from the office (section 2.2).
Your IT person can switch off all push notices on a computer (with the setting
UPBEEP_PHONE_PUSH=0).
2.2 Messages away from the office (our relay)
Messages away from the office is a feature that can be switched on. With it on, when a staff member's phone is away from the office network, for example at home or on mobile data, UpBeep can still get messages to and from it (and, where available, task notices to it). They travel through our relay: the same server on Amazon Web Services as our push server (section 2.1).
Pages never use the relay. A page never waits in the relay, and a page can't be cleared through it. A phone away from the office doesn't get pages. The one exception is a page notice to a phone that was on your office Wi‑Fi within the last 30 minutes (section 2.1(b)).
When it's used. Where the feature is available, it's shown on an office computer in Settings › Phones & watches as Messages away from the office. It's on for paired phones when your office has a password, and each phone's row there shows Gets messages away. An office without a password can't use it. A phone uses your office network whenever it can reach an office computer, and the relay only when it can't.
How it works:
Office to phone. When no office computer is connected to a phone, an office computer seals each new message and read receipt for that phone (and, where available, each task notice), and leaves it in the phone's mailbox on the relay. A wake-up notice (section 2.1(d)) tells the phone to collect it.
Voice messages. A voice message travels to an away phone as its written transcript, sealed; the recording stays on the office computer.
Phone to office. The phone seals what it sends (a message or a read receipt) and posts it to the relay. An office computer collects it, usually within a minute. If no office computer is on, it waits.
Collected means deleted. Once an item has been collected, its sealed contents are deleted from the relay.
Sealed end to end. Everything in a mailbox is sealed with keys made by your office's computers and that phone. We never have the keys, so the relay can't read what's inside: not the message text, which person sent a message or who it's for, read receipts, or what a task notice says. Only that phone and your office's own UpBeep computers can open it. The relay refuses anything that isn't sealed.
What the relay can see:
your office's relay identifier, a tag for each office computer, and which one is collecting for the office;
each phone's identifier, platform (iPhone or Android), push tokens and public signing key;
for each sealed item: which phone it's for or from, which way it's going, when it arrived and was collected, its padded size, and how many there are;
whether an office computer is online;
like any internet request, the internet address of the office computer or phone that contacts it. For a phone away from the office, that's the address of the network it's using, such as its mobile carrier's. The relay doesn't store internet addresses; the only exception is the daily hash in section 2.1, used to limit new-office sign-ups.
So the relay can tell when a phone is away from the office and sending or getting something, but not what it says, which person sent it, or who it's for.
What the relay keeps:
| Record | Kept for |
|---|---|
| A sealed item waiting to be collected, with its phone, office and item identifiers, direction, size and times | Only until it's delivered. An item that isn't collected is deleted after a few days at most. |
| The office and phone records | As in section 2.1 |
Your choices:
An office administrator can turn Messages away from the office off for the whole office, in Settings › Phones & watches on an office computer. Then no messages go through the relay.
An office without a password can't use it.
2.3 The licence check-in
Your office's licence tells its computers that UpBeep is paid for, and until when. It comes from our licence service on Amazon Web Services.
When. Any one office computer that's online checks in about once a day (every 22–26 hours). It checks more often as the paid-through date nears: every 6 hours or less in the last 7 days, and hourly in the last 2. It also checks when someone clicks Check again, and before UpBeep stops. Phones and watches never contact the licence service.
What's sent:
your office's identifier (a random identifier);
its current licence;
a random identifier UpBeep made for that computer (16 random bytes, not taken from its hardware);
UpBeep's version;
when the free trial started;
the computer's internet address.
It never carries pages, messages, tasks, notes, room names or people's names.
What comes back: your office's signed licence. It shows the plan, whether it's a trial or paid, the paid-through date, any cancellation date, and whether yours is a founding office.
From Paddle. When your office subscribes, renews, has a payment fail, cancels, or gets a refund or chargeback, Paddle tells the licence service. It sends: subscription and customer identifiers from Paddle, status, plan, product and price identifiers, the relevant dates, your office's UpBeep identifier, and transaction and event identifiers. The licence service stores no name and no email address. Nothing goes from the licence service back to Paddle.
What the licence service keeps:
| Record | Kept for |
|---|---|
| Your office's record: its identifier, subscription status and dates, and Paddle's identifiers for it | While the subscription is active or past due, and with no fixed end for a founding office. Otherwise until 365 days after the later of the end date and the last check-in. A stopped office whose computers keep checking in keeps extending this. |
| Trial log: which computer identifier started a trial for which office, and when | 2 years |
| For a paid office: each computer identifier that checks in, and a keyed hash of each internet address it checks in from, to detect one licence shared across locations | 30 days |
| Rate counters, keyed by office identifier and a hashed address | 2 hours |
| Paddle event identifiers | 30 days |
| Transaction records: product and price identifiers, refund and chargeback times | 1 year |
| A note of any manual change we make to an office's billing status (who made it and why) | As long as we need it for billing, tax and accounting records |
| Automatic backups (point-in-time recovery) | 35 days |
| Server logs: counts and fixed wording, plus a keyed hash of the office identifier when licence sharing is reported | 14 days |
A firewall (AWS WAF) limits how often any one internet address can call the service.
Your choices. The check-in can't be turned off without UpBeep stopping, because it's how UpBeep knows your office has paid. While your office's UpBeep is stopped, it makes no update checks and sends no notices to phones. It keeps checking in, so it can start again when you renew.
2.4 Dictation (watches and phone keyboards)
Apple Watch. When someone replies to a message on an Apple Watch, they can dictate. This is Apple's own dictation, and it is always available in UpBeep's watch app.
Apple turns the speech into text. Depending on the watch, the language and Apple's settings, the audio may be sent to Apple's servers. UpBeep never receives the audio.
The text then goes from the watch to its iPhone and on to your office, like a typed reply.
Apple says it doesn't keep dictation audio unless the device's owner has opted in to "Improve Siri & Dictation". See Apple's Siri and Dictation privacy notice.
To avoid dictation, use Scribble or the keyboard, or turn dictation off in the watch's settings.
Wear OS watches. A Wear OS watch, such as a Samsung Galaxy watch, that shows an Android phone's UpBeep notifications can reply to a message by voice.
The watch's own voice input turns the speech into text, and may send the audio to Google or the watch's maker, under their own terms. UpBeep never receives the audio.
The text then goes to the phone and on to your office, like a typed reply.
To avoid dictation, type the reply or turn voice input off in the watch's settings.
Phone keyboards. The microphone key on an iPhone or Android keyboard sends speech to Apple, Google or the keyboard's maker under their own terms. UpBeep doesn't turn it off.
Please don't dictate patient information.
2.5 Buying through Paddle
Paddle.com is our reseller and merchant of record.
Visiting /buy/. Our Buy page (/buy/ on our website) loads Paddle's checkout from Paddle on every visit. Paddle receives the visit (your internet address and browser details) and may set its own cookies there.
Choosing a plan. The page gives Paddle the price you chose and your office's UpBeep identifier, taken from the link the app opens. That's how Paddle can tell our licence service which office paid.
Paying. You give Paddle your name, email address, payment details and country or address. Your card details go to Paddle, never to us.
What Paddle shares with us. In Paddle's dashboard we can see the buyer details Paddle holds for your purchase (such as name, email address and country), what you bought, and the payment status. Paddle also sends our licence service the subscription events in section 2.3.
How we use it. We use this only to run and support your subscription, to send renewal reminders and notices about these terms, and to meet tax and legal duties.
Paddle's own policy. Paddle handles payment as an independent business, under Paddle's privacy notice.
2.6 Updates and downloads
Update check. UpBeep checks for updates 8 seconds after it starts, then every 6 hours. It doesn't check while UpBeep is stopped.
It's an ordinary web request, for a fixed file at GitHub, which hosts our releases. The request address carries nothing about your office, and no version.
GitHub sees your internet address and the standard request headers, which may identify the updater software, its version and your computer's operating system. See GitHub's privacy statement.
There's no setting to turn it off.
Update download. Only when someone clicks Install, from GitHub.
Later. We may move updates and downloads to our own servers on Cloudflare, under upbeep.app. A later version may also send a coded office key, so updates can roll out to offices in stages. We'll update this notice before either happens.
Optional speech model. Downloaded only if someone clicks Download the more accurate model in Settings › Voice. If a download didn't finish, it resumes the next time that Settings section opens.
It comes from Hugging Face, a public model library, and carries no UpBeep identifiers.
Hugging Face sees your internet address, like any website would.
Use Remove to delete the model.
2.7 Things you choose to send us
Support email. If you email support@upbeep.app, we get your address and whatever you write or attach.
Cloudflare's email routing forwards it to our support inbox, which our email provider hosts.
We use it only to help you. We keep it only as long as we need it to help your office and keep a record of our support, and then delete it.
Please don't send patient information, or screenshots or files that show it.
iPhone crash reports.
Apple gives the iPhone app technical crash reports. The app keeps the newest 10 on the phone, outside its backups.
A report leaves only if someone taps Settings › About › Share crash report and chooses where to send it.
It holds technical details only: code addresses, the error type, why the app stopped, app and iOS versions, and the time. It has no office information.
Apple's own crash sharing. If an iPhone's owner has turned on sharing with app developers (in the iPhone's Settings › Privacy & Security › Analytics & Improvements), Apple may pass us crash reports and usage statistics.
Google Play (Android). For the Android app from Google Play, Google may pass us crash and "not responding" reports from phones whose owners have opted in.
The Windows diagnostic log.
It stays on the computer: the current file plus 2 older ones, each up to 50 MB.
It leaves only if someone attaches it to an email.
It's designed to hold fixed messages and coded identifiers, not the text of pages or messages, but please look before you send it.
How long we keep these. We keep crash reports and logs sent to us only as long as we need them to find and fix the problem, and then delete them.
2.8 Our website
No tracking. upbeep.app sets no cookies of its own, includes no analytics or trackers, and loads nothing from other companies.
The one exception: /buy/. It loads Paddle's checkout (section 2.5).
Hosting. The site is hosted on Cloudflare, which processes each request (internet address, browser details, the page asked for) to deliver it and protect the site. To protect the site from abuse, Cloudflare may set a strictly necessary security cookie. See Cloudflare's privacy policy.
Do Not Track. Our site doesn't track you across other sites, so it treats every visitor the same whether or not "Do Not Track" is on.
Other companies on our site. No other company tracks you on our site, except Paddle on /buy/.
2.9 Your devices' own features (not ours)
Operating systems. Windows, iOS and Android may send their own information to Microsoft, Apple or Google under their policies. Examples are Windows Error Reporting, WebView2 updates and diagnostics, and SmartScreen checks when the installer runs. UpBeep doesn't control these.
Smartwatches showing phone notifications. If a staff member's Android phone is paired with a smartwatch, such as a Samsung Galaxy watch, the watch can show the phone's UpBeep notifications, with the same text as on the phone, as the phone's and the watch's own settings allow. The watch's actions (such as Clear page or Reply) go back through the phone. The phone, the watch and their makers' software handle this, usually over Bluetooth, under their makers' policies, not UpBeep. To stop it, turn off UpBeep's notifications for the watch in the phone's or the watch's settings.
Scanning the pairing code with another app. On Android, if someone scans the pairing code with another app, such as the camera app or Google Lens, instead of UpBeep, that app may process it. The code holds your office's identifier and name, your office computers' network addresses, and a one-time pairing code.
3. Who handles information for us
| Company | What for | What they handle | Role |
|---|---|---|---|
| Amazon Web Services (US, Ohio region) | Hosts our push server and relay, and our licence service | Sections 2.1–2.3 | Our service provider |
| Apple | Push notices to iPhones; dictation; App Store; crash reports from users who opt in | Sections 2.1, 2.4, 2.7 | Independent, under Apple's policies |
| Google (Firebase Cloud Messaging) | Delivers wake-up notices to Android phones | Section 2.1 | Our service provider, under Google's Firebase terms. It gets only sealed notices. |
| Paddle | Reseller and merchant of record | Section 2.5 | Independent, under Paddle's policies |
| Cloudflare | Website hosting; email routing for support@ | Sections 2.7, 2.8 | Our service provider |
| GitHub | Hosts releases and update checks | Section 2.6 | Independent |
| Hugging Face | Hosts the optional speech model | Section 2.6 | Independent |
| Android keyboard and Wear OS watch dictation; Google Play | Sections 2.4, 2.7 | Independent, under Google's policies | |
| Our email provider | Our support inbox | Section 2.7 | Our service provider |
We don't sell personal information, or share it for cross-context advertising. If we add or change a service provider that handles your office's information, we'll update this notice first.
4. How we use information
We use the information that reaches us to:
deliver notices to phones, and messages to and from phones away from the office (and, where available, task notices);
confirm your office's subscription, and stop one licence being used at several locations;
help you when you contact us, and fix bugs;
keep our servers secure and stop abuse (for example with rate limits);
handle billing, tax and legal duties.
We don't use it for advertising, we don't sell it, and we don't use it to train AI models.
5. How long we keep information
| What | Where | Kept for |
|---|---|---|
| Your office's pages, messages, tasks, office calendar, names and the rest | Your office's computers and phones | Until your office deletes them. We don't hold them, except sealed, on the way to or from a phone away from the office (below). |
| Push server records | Our push server | Office: 30 days after its last request. Phone: 60 days after it was last registered or last used our relay. Short-lived items: minutes to an hour. Logs: 14 days. (Section 2.1) |
| Notice contents (pages, messages and, where available, tasks) | Our push server | Not stored |
| Sealed messages (and, where available, task notices) for or from a phone away from the office | Our relay | Only until delivered. An item that isn't collected is deleted after a few days at most. (Section 2.2) |
| Undelivered notices | Apple, Google | Until they expire: 60 seconds to 1 hour for pages, "Waiting on you" and message notices; for a wake-up about an item waiting in our relay, a few days at most. (Section 2.1) |
| Licence records | Our licence service | Section 2.3 (from 2 hours to 2 years; no fixed end for active or founding offices) |
| Support emails | Our inbox | As long as we need them to help your office and keep a record of our support |
| Crash reports and logs you send | Our inbox | As long as we need them to find and fix the problem |
| Purchase records | Paddle | Under Paddle's policy |
6. Security
Connections to our servers. All connections to our servers are encrypted (TLS). Requests to our push server and relay are signed with your office's key (or, for a phone away from the office, the phone's own key) and protected against being replayed.
Sealed end to end. Message notices (and, where available, task notices), notices to Android phones, and everything held in our relay are sealed end to end, with keys we never have. The relay refuses anything that isn't sealed.
Identifiers. Where we can, our servers keep keyed hashes instead of raw identifiers or internet addresses.
Keys and logs. Server keys are kept in AWS Secrets Manager. Logs hold fixed wording and counts, not content.
Your office network. On your network, UpBeep encrypts traffic between computers when your office has a password, and always encrypts phone links.
No system is perfectly secure. If we learn of a security incident that affects your office's information, we'll tell your office without undue delay, and as the law requires.
7. Your choices and requests
Your choices, in one place:
Phone notices. Don't pair phones, remove them, set them to Away, or use privacy-screen-only mode (section 2.1).
Office password. Set one. It also enables sealed message notices, notices to Android phones, and messages away from the office.
Messages away from the office. An office administrator can turn it off for the office (section 2.2).
Dictation. Use Scribble or the keyboard, or turn dictation or voice input off in the watch's settings (section 2.4).
Smartwatches. Turn off UpBeep's notifications for the watch in the phone's or the watch's settings (section 2.9).
Speech model. Don't download it, or remove it (section 2.6).
Crash reports and logs. Only send them if you want to (section 2.7).
Requests. Email support@upbeep.app, from the email on your Paddle account or from your office, to ask what we hold about your office, or to correct or delete it. We'll answer within 30 days. We can delete:
your office's push server and relay records (sealed items are deleted after a few days at most anyway);
support emails, crash reports and logs;
your office's licence record. We may keep what we must for tax, accounting, preventing licence misuse, or legal claims, and deleting the record ends the subscription.
For Paddle's records, ask Paddle.
If a privacy law gives you other rights over your information, email us and we'll honour them.
8. Children
UpBeep is a business tool for office staff. It isn't directed to children under 13, and we don't knowingly collect information from children.
9. Where information is processed
UpBeep is for offices in the United States. Our servers are in the United States (Amazon Web Services, Ohio). Paddle, Cloudflare, GitHub, Hugging Face, Apple and Google may process information in other places, under their own policies.
10. For dental and medical offices: patient information
UpBeep is not meant for patient information, including "protected health information" under HIPAA. When it sets up UpBeep, your office agrees, in a box it must tick, not to put anything that could identify a patient anywhere in UpBeep: pages, messages, tasks, notes, reminders, the office calendar, people or dictation (see section 10 of the Terms of Service).
Even so, here is where text your staff type can leave your office, so you can see why the rule matters:
Room names, page names, reminder and timer names, and the names of people pages are sent to. These appear in page notices to a locked phone and in the iPhone's "Waiting on you" notice. Our push server can read them, and so can Apple on an iPhone. Your office's name can be read the same way in "Waiting on you". Google gets them only sealed.
Messages for phones away from the office (and, where available, task notices), and message notices to locked phones. These are sealed: our relay, Apple and Google can't read who sent them or what they say. But they still leave your office's network, travel over the internet, and can wait on our relay for a few days at most.
Dictated replies and keyboard dictation. These go to Apple, Google or the device's maker.
Support emails, screenshots and logs. These come to us.
We don't offer a business associate agreement (BAA). We have no BAA with Apple or Google for UpBeep, and we make no claim that UpBeep is HIPAA compliant.
So, everywhere in UpBeep:
don't put anything that could identify a patient in pages, page, room, reminder or timer names, messages, notes or voice messages, tasks, list names or task comments, the office calendar, or UpBeep's list of people;
don't dictate patient information;
don't email us patient information, or screenshots or logs that show it.
Your office is responsible for its own HIPAA compliance and for making sure its staff follow this rule. If your office needs to send patient information to its staff, use a system it has a BAA for, not UpBeep. If patient information reaches us by mistake, tell us, and we'll delete what we hold. Our servers don't store page text, and our relay holds only sealed items it can't read, which it deletes after a few days at most. Apple and Google handle what they receive under their own policies.
11. Changes to this notice
If what UpBeep or our website sends or keeps changes, we'll update this notice before the version that changes it is released, and change the date at the top. For a change that matters to your office, we'll also email subscribed offices and show a notice in the app.
12. Contact
Adam K Goodwin, doing business as UpBeep 122 Upola Court, Bastrop, Texas 78602 support@upbeep.app · +1 706-619-8342