Legal
Effective
What data handup, its websites and its optional connections handle, and who sees it. Plain answers, no tracking.
handup is made by an individual developer, named at the end of this policy (“we”, “us”). This policy covers the handup software, the websites gethandup.dev, docs.gethandup.dev and media.gethandup.dev, license purchases, and support messages. handup has no user accounts. Questions or requests: contact support.
The handup daemon stores requests (titles, summaries, previews, attached files and agent input), decisions, audit history, paired-device records and settings in a SQLite database and files on your own computer, by default under ~/.local/share/handup on Linux. Requests can contain anything your agents put in them, including secrets; handup redacts recognizable credentials, but you should treat this data as sensitive.
handup has no telemetry, analytics or crash reporting, and it doesn't check for updates in the background. Apart from the license checks described below, using handup locally sends nothing to us or to Polar.
By default the daemon deletes resolved requests after 90 days or once there are more than 2,000 of them; it never deletes pending requests. You can change these limits. We can't see, access or delete your local data; removing it is up to you.
handup works fully for a 14-day trial from the first time the daemon starts. The trial needs no key and sends nothing anywhere. After the trial, handup needs a license.
When you activate, the daemon contacts gethandup.dev once and sends only your license key. Our site asks Polar whether the key is valid for handup (sending Polar the key and our Polar organization ID) and, if it is, returns a signed license file. That file contains your Polar license key ID, your Polar customer ID, the email address on your purchase, the masked key Polar displays (like ****-XXXXXX) and the time it was issued. It is stored on your computer next to your key. Our site doesn't log or store your key or the license; Vercel sees the connection as described under Our websites. Machines without internet access can import a license file instead.
After that, while your computer is online, the daemon asks Polar directly at api.polar.sh every few days whether the key is still valid. It sends only the license key and our Polar organization ID; Polar receives your IP address as part of the connection. Nothing about your requests, agents or devices is sent.
A valid license keeps working offline forever: if a check can't reach Polar, nothing changes. Only a definite answer from Polar that the key is revoked or disabled, for example after a refund, locks handup. Removing the license in handup deletes the local license file and key.
Some features send data off your computer. Each one is optional and configured by you. Here is exactly what each sends.
When you pair a phone or browser, it talks to your daemon over the network you chose. Data goes between your own devices; we don't receive it. Tailscale or your network provider handle the traffic under their own terms.
The relay forwards messages between your daemon and your phone when they can't reach each other directly. Requests, previews, decisions and device tokens are encrypted end to end (Noise IK, X25519 and ChaCha20-Poly1305) with keys that stay on your daemon and phone. The relay can't read them. It does see and store some metadata to do its job:
Whoever runs the relay controls these records. Today that is you: we don't operate a relay for customers. If we launch a managed relay, we will update this policy before it starts.
Android builds that include Firebase register with Google's Firebase Cloud Messaging when the app runs. After you pair the app, it gets a push token from Google and sends it to each paired computer, where the daemon stores it. This happens whether or not you allow Android notifications. Google processes the token, a Firebase installation ID, app and device identifiers and IP address to deliver messages. We don't use Firebase Analytics or Crashlytics.
Push sending is on by default for license holders. Our push service at push.gethandup.dev, which runs on Cloudflare Workers, delivers it: your daemon sends it your signed license (your purchase email, Polar customer and license IDs and a masked key), each phone's push token and device ticket, and the request ID and risk level. The title is included only if you set notifications.push.payload = "title", and then with recognizable credentials redacted. To get a ticket, the phone first sends the service its push token, and the service sends a one-time code to that token through Firebase. The service forwards wake-ups to Firebase and stores none of this. For each request it logs only which endpoint was called, the result, the time taken and delivery counts, never licenses, IDs, tokens, tickets, titles or IP addresses; Cloudflare keeps these lines for 3 days. Your daemon keeps a summary of its last delivery (time, result, device count) on your computer for handup doctor.
If you set up your own Firebase project instead, your daemon sends to Firebase directly. Those messages contain the request ID, its risk level and the request title, with recognizable credentials redacted. Request titles are written by your agents and can reveal what you are working on. Setting notifications.fcm.payload = "wake" replaces the title with “Approval requested”. When a relay sends the wake-up instead, it carries a generic title and no request details unless you set remote.relay.push = "title". Previews, commands and decisions are never included in push messages.
If you configure ntfy, your daemon publishes to the server and topic you choose (ntfy.sh unless you set another). Each message contains the request title and the reason it needs attention (credentials redacted), a risk tag and priority, and a link containing the request ID. If you turn on include_content, the summary and preview text are sent too. ntfy.sh caches messages for a short time under its own policy; anyone who knows your topic name can read it, so pick a hard-to-guess one or use your own server.
previews.html.allow_network (off by default).Checkout happens on Polar's hosted page. Polar is the merchant of record and collects your name, email, billing address, tax details and payment information, which its payment processor Stripe handles. Polar uses that data under its own Privacy Policy, which also covers Polar's own cookies and analytics on the checkout page.
We never see your full card number. Polar shows us the order details it makes available to sellers, such as your name, email address, country, what you bought, the amount paid and your license key status. We use them to provide your license, handle refunds and support, and keep tax and accounting records. Our website stores no orders or buyer details.
gethandup.dev and docs.gethandup.dev are hosted on Vercel; site videos and images are served from media.gethandup.dev on Cloudflare R2. Like any web host, these providers receive your IP address, browser user agent, the pages and files requested and the time, and keep request logs for security and operations under their own policies.
We count page views with Vercel Web Analytics, which sets no cookies. It records the page, referrer and approximate country, browser, operating system and device type; visitors are told apart by a hash of the request that is discarded after 24 hours, and we see only aggregate numbers, never individual visitors. The same analytics, also without cookies, count clicks on the Download and Buy buttons of gethandup.dev, recording which button, the page, and for downloads the platform and file chosen.
gethandup.dev also counts page views with Umami Cloud (Umami Software, Inc.; data stored in the United States), which sets no cookies either. It records the page, referrer, campaign tags in the link (such as utm_source), approximate country, region and city, language, screen size, browser, operating system and device type. Umami does not store your IP address; visitors are told apart by a hash of the request that changes every month, and we see only aggregate numbers. We don't use tracking pixels or advertising, and we set no tracking or advertising cookies. There are no accounts on our sites; the only form is the support form described below.
The support page sends what you enter: the kind of message, your message, your email address if you give one, the page you sent it from and, when you came from the app or CLI, the handup version, platform and which client opened the page. You can remove those attached details before sending.
Cloudflare Turnstile checks that a person is sending the form. It loads from Cloudflare when you open the support page and processes your IP address and browser signals to do that, under Cloudflare's Turnstile policy. The form is received by a function we run on Amazon Web Services, which emails it to us through Amazon SES. To limit abuse it counts messages per sender under a one-way hash of your IP address, which expires after about two hours. It doesn't store your message or your IP address; its logs, kept for 30 days, note only delivery and rejection outcomes, without message content or IP addresses.
Messages are delivered to our mailbox, hosted by Purelymail. We use your email address only to answer you and keep a record of the conversation. Please remove secrets, tokens and private data from logs before you send them. We keep support messages as long as they are useful for helping you and for our records; you can ask us to delete them at any time.
These are the companies involved in running handup's websites, sales and optional features:
| Provider | What it does | When |
|---|---|---|
| Polar Software, Inc. | Merchant of record: checkout, payment, tax, receipts, license keys (card payments via Stripe); checks license keys are still valid | When you buy a license, and every few days while a licensed handup is online |
| Vercel | Hosts gethandup.dev and docs.gethandup.dev, including the endpoint that exchanges a license key for a signed license; cookieless, aggregate page-view and Download/Buy click analytics | When you visit the websites |
| Umami Software, Inc. (Umami Cloud) | Cookieless, aggregate page-view analytics for gethandup.dev, including referrers and link campaign tags | When you visit gethandup.dev |
| Cloudflare (R2) | Serves videos and images from media.gethandup.dev | When a page loads site media |
| Cloudflare (Turnstile) | Checks that the support form is used by a person, not a bot | When you open the support page |
| Cloudflare (Workers) | Runs our push service at push.gethandup.dev, which asks Firebase to wake licensed users' phones | With a license and a paired Android phone, unless you use your own Firebase or turn push off |
| Amazon Web Services | Receives support form messages and emails them to our mailbox (Lambda, DynamoDB, SES) | When you send the support form |
| Purelymail | Hosts our support mailbox | When you contact support |
| Google (Firebase Cloud Messaging) | Delivers Android push notifications | Android builds that include Firebase, when our push service or your own Firebase setup sends a notification |
| ntfy (ntfy.sh or your own server) | Delivers ntfy notifications | Only if you configure ntfy |
Polar, Google, Cloudflare, Amazon Web Services and ntfy.sh act under their own privacy policies. Services you choose and run yourself, such as Tailscale, a self-hosted relay or ntfy server, or webhook endpoints, are between you and them.
If you are in the EU or UK: we use purchase and support data to perform our contract with you (your license, refunds and support), to meet legal obligations (tax and accounting records), and for our legitimate interest in keeping our services secure and counting aggregate website visits. We don't rely on consent for anything that requires it, because we don't do tracking or marketing.
Depending on where you live (for example under the GDPR or California law), you may have the right to access, correct, delete or export personal data we hold about you, to object to or restrict its use, and to complain to your data protection authority. We won't treat you differently for using these rights.
Email contact support to make a request. We may ask you to confirm you control the purchase email address. We can act on what we hold, such as support emails and the order details Polar shows us; we can't reach data that lives only on your devices or inside encrypted relay messages. For Polar's records, you can also contact Polar directly.
handup keeps device tokens hashed on the daemon, stores the Android app's credentials in Keystore-backed storage, and encrypts relay traffic end to end. No system is perfectly secure, and the security of your machines, paired devices and backups is up to you.
We are based in the United States, and our providers process data in the United States and elsewhere. When you buy, email us or visit our sites, your data may be processed outside your country.
handup is a developer tool and is not directed at children under 13. We don't knowingly collect personal data from children under 13. If you believe a child has sent us personal data, email contact support and we will delete it.
We will update this policy when handup's data handling changes, for example before a managed relay ships, and change the effective date at the top. For material changes we will post notice on this site before they take effect. See also our Terms of Service. Contact: Ariel Frischer, contact support.