upsight

Privacy

Privacy Policy

Effective 14 August 2026

This policy explains how Upsight ("we", "us") collects, uses, stores, and deletes data when you use our service, including the Upsight apps for Slack, Discord, and Telegram. "Customer Data" means the data you provide to us or that we process on your behalf to deliver the service.

What data we collect

  • Account data — name, email, and organization details used to create and manage your account.
  • Integration data — credentials and tokens needed to connect the services you authorize, and the configuration you set (for example, which alerts route to which destination).
  • Slack data — when you connect Slack, we receive your workspace and channel identifiers and names and an OAuth bot token, so we can post the notifications you configure. We request only the scopes needed to list channels and post messages; we do not read your team's conversations.
  • Discord data — when you add our bot to a Discord server, we receive the server and channel identifiers and names so we can post the notifications you configure. The bot posts only; we do not read your server's conversations.
  • Telegram data — when you add our bot to a Telegram group or channel, we receive that chat's identifier and title so we can post the notifications you configure. Our bot runs with Telegram's privacy mode enabled, so it receives only the commands addressed to it (the one-time code that links the chat) and not the chat's other messages.
  • Usage and log data — technical records generated when the service runs (for example, request metadata and system logs) used to operate and secure the service.

Where our app incidentally receives data that is not required for a feature (for example, identifiers contained in a request payload), that data is not used for any other purpose and is subject to the retention terms below.

How we use data

  • To provide, maintain, and secure the service and the integrations you enable.
  • To deliver the notifications and reports you configure.
  • To respond to support requests and troubleshoot operational issues.
  • To meet legal, security, and legitimate business obligations.

We do not sell Customer Data, and we do not use it to train our own models.

How data is stored

We store Customer Data using access-controlled cloud infrastructure with appropriate technical and organizational security measures. Sensitive credentials and integration tokens are encrypted, and access is restricted to authorized systems and personnel.

Sub-processors

We use third-party sub-processors to host and operate the service. Our infrastructure and database provider is Supabase (see supabase.com), and AI features are processed by OpenAI (see openai.com). Sub-processors are engaged under terms that require appropriate safeguards for Customer Data.

AI features

Some features use a large language model to generate insights and summaries. These requests are processed by OpenAI under its API data-usage terms, which exclude API inputs and outputs from model training.

  • Tenancy — LLM processing is logically isolated by customer organization. Data is processed only in the context of the requesting organization and is not shared with other Upsight customers.
  • Residency — LLM requests are processed by OpenAI; residency and processing locations are governed by that service and its applicable data-processing terms.
  • Retention — we do not use Customer Data to train our own models, and we do not sell it. LLM request data is retained only as necessary to provide the service and troubleshoot operational issues; retention by OpenRouter and its upstream provider is governed by their applicable data controls.

How long we keep data

We retain Customer Data only for as long as necessary to provide the service, meet legitimate business needs, and comply with applicable legal obligations. We delete or anonymize Customer Data when it is no longer required to provide the service — for example, following account termination or a valid deletion request — subject to applicable legal and backup-retention requirements. Data in backups is removed according to our standard backup retention cycle.

Accessing, exporting, or deleting your data

You may request access to, a copy of, or deletion of your data, including rights available under laws such as the GDPR and CCPA where applicable. To make a request, email support@upsight.fyi. We verify the request, identify the associated account and organization data, and securely delete or anonymize applicable personal data from our active systems within a reasonable timeframe, subject to legal, security, and legitimate retention requirements. You can also remove any chat integration at any time from your workspace settings — or from Slack, Discord, or Telegram themselves — which revokes our access and stops further processing of that app's data.

Contact

For any question or request about this policy or your data, contact us at support@upsight.fyi.

Changes

We may update this policy from time to time. Material changes will be reflected by the effective date above.