Privacy policy
Last updated 11 August 2026
Standup is a daily reporting tool with an employee-controlled evidence trail. This policy describes what the software records, where it is stored, and what is shared. It is written to be checkable against the product’s behaviour rather than to be broad.
What the desktop agent records
On the machine where you install it, the agent periodically records the name of the application currently in the foreground and the title of its window, together with a timestamp. It also reads commit metadata from local git repositories you explicitly select.
It does not capture screenshots, screen recordings, keystrokes, clipboard contents, browsing history, file contents, network traffic, webcam or microphone input. There is no code path in the application that does any of these.
Where that data is stored
Locally, in a SQLite database in your user profile on that machine. It is not transmitted anywhere. Applications you add to your exclusion list are evaluated before a record is written, so an excluded application produces no record at all rather than a record that is redacted afterwards.
Local records are deleted automatically after the retention period you configure. Window titles are never written to any log file, crash report or telemetry stream.
What leaves your machine
Only the day you approve. Before anything is transmitted, the agent shows you the summary it assembled and lets you rename, merge, split, delete and add entries. What you submit is what is sent; anything you removed is not transmitted.
Raw activity samples are never transmitted. No server endpoint accepts them.
If you do not review a day, the agent may submit the summary it assembled shortly before your configured send time, and it is marked as auto-submitted rather than reviewed. You can disable this or change how long beforehand it happens.
Google data, and how it is used
With your explicit consent, Standup requests these Google scopes and uses them only as described:
- Sign-in (email, profile, openid) — to identify your account. No other identity data is requested.
- Google Sheets (spreadsheets) — to append one row per report to the specific spreadsheet you nominate, and to update that row if you later amend the day. No other spreadsheet is read or written.
- Gmail (gmail.send) — to send the report from your own account to the recipients you configure. This scope grants sending only: Standup cannot read, search, or delete your mail.
Standup’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is never used for advertising, never sold, and never used to train any machine-learning model.
Third parties
The narrative report is generated using an AI provider you choose and an API key you supply. The text sent to that provider is the day you approved, together with commit messages from repositories you selected. Their handling of that request is governed by their own terms; Standup does not send them anything you did not approve.
If you connect GitHub, commit metadata for the repositories you select is read to attribute work to you.
Credentials
OAuth tokens and API keys are encrypted at rest with AES-256-GCM using a per-record initialisation vector. They are never returned to any interface after being saved — only a non-reversible hint is displayed. You can disconnect any integration at any time, which revokes the stored grant.
What your employer can see
The report you approved, in the spreadsheet and email you configured. Administrators can additionally see operational status — whether a report was produced, skipped, missed or failed, and when a device last checked in.
Administrators cannot see your activity entries. There is no screen, export, report or API response in the product that renders one person’s activity detail to anyone else, and no permission that could grant it.
Retention and deletion
Local activity data is deleted on your configured schedule. Submitted summaries and generated reports are retained on the server for the period set by your organisation. You may request deletion of your account and associated data by contacting the operator below; uninstalling the agent removes all local data.
Contact
This deployment is operated by [operating entity]. Questions and deletion requests: [contact email].