Privacy Policy

Last updated: August 2026

What we collect

Your account details (name, email, phone), your check-in history, the guardian contacts you add (name, email, phone), and, if you use the Legacy Vault, the messages and recipients you store there.

Why we collect it

Solely to run the safety check-in service: detecting missed check-ins, alerting your guardians, and — only if guardians confirm you cannot be reached — delivering any Legacy Vault messages you created.

Where your data lives

CheckUp runs on servers we lease from Hetzner Online GmbH, a hosting provider based in Germany, with data centers in the EU. Hetzner also provides our domain registration and DNS. Beyond that, every part of the service — the database, the application code, the check-in logic, the guardian alerts — runs on infrastructure we built and operate ourselves, using open-source software wherever we can, instead of routing your data through third-party platforms.

The one specialized service we rely on is Resend, which sends transactional email on our behalf — check-in reminders, guardian invitations, and alerts. Resend processes the email address and message content needed to deliver those emails, and nothing else. We don't use third-party analytics, advertising, or tracking services of any kind.

How long we keep it

You can delete your account at any time, which permanently removes your personal data. If your guardians confirm you have passed away, your data is permanently deleted after your Legacy Vault messages are delivered, in line with the settings you configured. A minimal, non-identifying record of that action is kept for legal accountability.

Your rights, and GDPR

CheckUp is built to comply with the EU General Data Protection Regulation (GDPR). If you're in the EU or EEA, this is what that means in practice:

Data controller: [legal entity name — to be added once our company registration is complete].

Cyber Resilience Act

As a digital product made available in the EU, CheckUp falls within scope of the EU Cyber Resilience Act (CRA). Its vulnerability-reporting obligations take effect in September 2026, with the full framework phased in through December 2027. We're building toward those requirements now — secure-by-design practices, responsible handling of vulnerabilities, and keeping our open-source dependencies current — rather than waiting for the deadline to arrive.

Age requirement

CheckUp is intended for users aged 18 and over.

Questions

Reach out any time via our Contact page.