Uptome

Privacy Policy

Last updated: September 17, 2026

Who we are

This Privacy Policy describes how Uptome (“we”, “us”, or “our”) collects, uses, and shares information when you use our web application, mobile apps, and related services (together, the “Services”). Branded variants of the same platform (including Uptome, VOS, and Nomni) are covered by this policy unless a specific deployment provides a different notice.

Questions about privacy: hello@uptome.ai.

Information we collect

Depending on how you use the Services, we may collect:

  • Account and profile information — email address, password, name, phone number, organization membership, roles, and location assignments.
  • Workplace content you submit — form responses such as text, numbers, dates, checklists, scores, and similar operational data entered by you or your organization.
  • Location — approximate or precise device location when a form or workflow requires geolocation at the time of submission (with your device permission).
  • Media and files — photos, signatures, PDFs, documents, and videos you attach to submissions or tasks.
  • On-device data (mobile) — session tokens, selected organization/location preferences, draft submissions, sync queues, and staged media stored locally so you can work offline until data syncs to our servers.
  • Push notification tokens (mobile) — a device token issued by Apple or Google so we can send you notifications about your activities and reviews. It is registered when you enable notifications and removed when you sign out.
  • Usage and diagnostics — product analytics, in-app feedback, crash and error reports, and performance metrics that help us operate and improve the Services. On mobile this includes the device advertising identifier, used for analytics only — we do not use it for advertising and we do not serve ads.
  • Support communications — messages you send to us, including via feedback tools or email.

We do not collect microphone audio in the mobile apps.

How we use information

We use the information above to:

  • Provide, maintain, and secure the Services for your organization
  • Authenticate users and manage access, roles, and locations
  • Store and sync submissions, media, and offline drafts
  • Send transactional email (invites, password resets, and organization-configured submission notifications)
  • Send push notifications about your activities, reviews, and follow-ups
  • Provide customer support and investigate issues
  • Monitor reliability, prevent abuse, and improve the product
  • Comply with legal obligations and enforce our terms

How we share information

We share information with service providers that help us run the Services, and as directed by your organization. Typical categories include:

  • Infrastructure and data hosting — Supabase for authentication, database, and file storage
  • Email delivery — Resend for transactional and notification email
  • Analytics, feedback, and monitoring (web) — Segment, Gleap, Sentry, and Vercel (including performance insights)
  • AI features (web) — OpenAI when your organization uses AI helper features; prompts and related content may be processed to generate responses
  • Video — VdoCipher for upload and playback of user-submitted video where enabled
  • Mobile app updates — Expo / EAS Update for over-the-air update checks
  • Organization-configured recipients — email or other exports of submission content sent to addresses or systems your organization configures

We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or asset transfer. We do not sell personal information.

Device permissions (mobile)

The mobile apps may request permission to use your camera and photo library to attach media to submissions, and location while the app is in use when a form requires geolocation. You can deny or later revoke these permissions in your device settings; some features may not work without them.

Retention

We retain account, submission, and related data for as long as your organization maintains an account or as needed to provide the Services, meet legal obligations, resolve disputes, and enforce agreements. Offline drafts and staged media on your device remain until synced, discarded, or cleared with the app or device storage.

Security

We use administrative, technical, and organizational measures designed to protect information, including encrypted transport (HTTPS), access controls, and secure storage of session credentials on mobile devices. No method of transmission or storage is completely secure.

International transfers

We and our service providers may process information in countries other than where you are located. Where required, we take steps intended to protect information transferred internationally.

Your choices and rights

Depending on your location and applicable law, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. Many account details can be updated through the product or by asking your organization administrator. You can also contact us at hello@uptome.ai.

Because Uptome is typically provided to workplaces, your employer or organization may control much of the data in the Services. We may need to refer certain requests to them.

Children

The Services are intended for workplace use by adults and are not directed to children under 16. We do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy from time to time. We will change the “Last updated” date above and, when appropriate, provide additional notice. Continued use of the Services after an update means you acknowledge the revised policy.

Contact

Privacy questions or requests: hello@uptome.ai.

Privacy Policy · Uptome