Trust & Security

We would rather you checked our privacy and security claims than took our word for them. Here is how you can verify each one yourself.

Your data

Camera video never leaves your device0 video framesVerify yourself

UpSensei watches your posture by running the pose-detection model (MediaPipe / TensorFlow) directly in your browser. The webcam video is analysed frame by frame on your own device — it is never uploaded, streamed, or stored on our servers.

Verify it yourself: open your browser’s developer tools, switch to the Network tab, and start a session. You will see that no video frames are ever transmitted.

By default no posture data leaves your device either: for guests and free accounts the posture analysis also runs in your browser, so not even coordinates are uploaded. To be plain about the one exception: each session starts with a licensing call carrying an opaque browser identifier, and that request has an IP address like any other, so “nothing leaves” is not literally zero contact. For guests and free accounts that one call is all there is. A Pro licence runs to the end of your billing period rather than an hour, and is renewed with one further call only if a session is still running at the moment it lapses — and when your browser is offline a licence that is still valid is reused instead of calling at all. For guests that call leaves one row on our server — a one-way fingerprint of that identifier, two counters, and a first- and last-seen timestamp — which is deleted automatically after 90 days. Only in Pro’s optional Cloud mode does your browser send pose coordinates — a handful of x/y/z points describing where your joints are — to our analysis server in the EU, to sync and replay sessions across devices. Even then these are numbers, not images: no picture, video, audio, face, name, or email is ever included.

A second camera angle sends no video either0 video framesVerify yourself

With Pro in Cloud mode one sitting can be recorded from two or three devices at once — your main device plus a phone propped to one side. Every device in that group works the way the one above does: it runs the pose model in its own browser and uploads only pose coordinates. No image and no video frame leaves any of them, without exception. An extra angle is more coordinates of the same kind, from a second camera — not a new kind of data. The option appears only on a device signed in to your account, with Pro, in Cloud mode; on-device analysis uploads no pose data, so there is no recording for it to join.

The extra device is a camera, not a second coach: it shows you its own skeleton so you can check you are in frame, and gives no posture alerts, no speech and no notifications. What it records belongs to the same recording as your main device’s and is kept on the same terms — and although it is not listed separately in your history, deleting that recording deletes it too, and retention expires the whole recording at once. During the session its coordinates can be sent back to your own main device so it can show the extra angles beside the main view.

Check for yourself: open the developer tools on the second device before you join, keep the Network tab open, and read the request bodies it sends. They contain batches of joint coordinates and no image data.

A browser app, not an installed programSandboxVerify yourself

An installed program, the kind of .exe you download and run, can do almost anything on your computer: reach the camera unnoticed, read your files, and send images home, with nobody watching. UpSensei deliberately runs in the browser instead: inside a sandbox with no access to your file system, and with camera access only after you explicitly grant it for this site.

The browser acts as an independent referee that we do not control. It shows you when the camera is active (the indicator in the tab), you can withdraw the camera permission at any time with one click (the lock icon next to the address bar), and the developer tools let you inspect every single transmission. And if you install UpSensei as an app through your browser’s install prompt (PWA), it still runs inside this same browser sandbox under the same rules.

Check for yourself: click the lock or settings icon to the left of the address. Your browser lists every permission this site holds there, and you can withdraw any of them at any time. For the technically curious: in the page’s response headers (Permissions-Policy, visible in the developer tools), UpSensei itself rules out microphone, location and payment access from the start.

Your account works without any email0 emailsVerify yourself

A free account carries no identifying details. You can use UpSensei entirely as a guest, and even a full account needs no email address: none is required and none is stored on our servers. Sign-in is handled by our German authentication provider, Hanko; if you choose to give an email address there, it stays with Hanko and we do not retrieve it. A Pro subscription adds two opaque Creem references on our side — the payment data itself lives separately with Creem (see “Sign-in and posture data are separated”).

Check for yourself: create an account. You are never asked for a name, and an email address is purely optional. Keep in mind: without an email address on file, a password reset is not possible.

Sign-in and posture data are separatedSeparatedVerify yourself

Sign-in is handled by our German authentication provider, Hanko (whose cloud runs on AWS in Frankfurt — see the EU row); Hanko never sees any posture data. With us — and only in Pro’s optional Cloud mode — your posture data lives under a random account identifier: no name, no email address, no photo. Payment data for Pro subscriptions likewise lives separately with our payment provider.

This means that even if one of these datasets were lost, that dataset on its own would still not link a person to their posture data. Pseudonymous data is still personal data, so we do not promise absolute anonymity here. Keeping the datasets apart simply means that a single breach does not, by itself, establish that connection.

Check for yourself: watch the Network tab of your browser’s developer tools while you sign in. Your credentials go to auth.upsensei.eu (Hanko) and never to the application server.

Our promise: whether we ask Hanko for your optional email over a direct server channel is not something you can see in your browser. We do not. Our server only checks Hanko’s public signatures and holds no admin access that could retrieve emails. At this one point it comes down to trust, not a proof you can carry out yourself.

Everything is hosted in the EUEUVerify yourself

Everything runs in EU data centers: the application and database on Scaleway, a French provider, in its Amsterdam data center, and authentication with Hanko, a German company, whose cloud runs on AWS in the Frankfurt region. We transfer no personal data to a third country; payment for Pro runs with Creem as an independent seller under its own privacy policy. One deliberate exception outside our infrastructure: the status page lives on GitHub Pages (a US host) — it must stay reachable even when our own infrastructure is not, and it contains no user data.

US laws such as the CLOUD Act can compel US-based companies to hand over data, even data they hold in Europe. Scaleway, where any posture data we store lives (Cloud mode only), is a French company under European jurisdiction only, with no US datacenters, so no US provider can reach it. US companies appear in only two places, never near your posture data: on the sign-in path (AWS sits underneath Hanko, and if you choose to sign in with a Microsoft or Google account, that provider handles that one step), and — only if you connect Microsoft Teams for call silencing — in the ongoing polling of your call status from Microsoft for as long as you stay connected. With a passkey or password and no Teams connection, Microsoft and Google stay out of it entirely.

Check for yourself: look up the IP address behind upsensei.eu (for example with an online DNS lookup) and enter it in the RIPE database, the official European IP registry. The entry shows Scaleway in Amsterdam. The addresses behind auth.upsensei.eu belong to AWS; a plain whois shows Amazon’s US registration, while the IP ranges that AWS publishes place them in the Frankfurt region (eu-central-1).

Our promise: an IP lookup shows where our servers answer from, not that we run the database and its backups on Scaleway. We do. Scaleway is a French provider with datacenters only in the EU, so your posture data cannot physically leave it; that we keep the database there is, at this one point, our word rather than a browser check.

Scaleway on European data sovereignty

You never see a cookie bannerNo bannerVerify yourself

We never ask you to accept cookies, because we set none that would need your consent. Without an account and without a calling-service connection you have no cookies from us at all. Every cookie we set exists to run something you asked for — there are at most two:

“hanko” — appears when you sign in to an account; holds your session token; removed when you log out.

“msal.cache.encryption” — appears only when you connect Microsoft Teams for call silencing, written by Microsoft’s sign-in library (we ship that library, so we count the cookie as ours); holds the key that encrypts the Microsoft access tokens kept in your browser’s local storage; a session cookie, so your browser deletes it when you close it and those tokens can no longer be read.

Third-party services set cookies only on their own domains, never on ours: Microsoft and Google on their own sign-in pages, your own Nextcloud instance for a Nextcloud connection, and Creem on its checkout pages when you subscribe to Pro. Each provider’s own privacy policy applies, and we technically cannot read those cookies at all.

We use no advertising cookies, no analytics cookies, no third-party trackers, and no device fingerprinting — which is why there is no cookie banner to click away.

Check for yourself: open your browser’s developer tools, go to the Application (or Storage) tab, and look at the cookies stored for this site.

Security & operations

Mozilla HTTP ObservatoryA+Verify yourself

Scored A+ (110/100), all 10 tests passed.

This scan was last run on 17 July 2026. The grade reflects the state of the site on that scan date; the linked scanner always shows the current live result.

Qualys SSL LabsA+Verify yourself

Rated A+ for transport security, with zero warnings.

This scan was last run on 17 July 2026. The grade reflects the state of the site on that scan date; the linked scanner always shows the current live result.

Our servers run on renewable electricityRenewableVerify yourself

The application and database run in Scaleway’s Amsterdam data centers, and Scaleway powers all of its data centers with 100% renewable electricity, from wind and hydro. The Green Web Foundation — an independent non-profit that keeps the public registry of green hosting providers — lists Scaleway with proof documents per data center, including the Amsterdam sites our region runs in, and marks upsensei.eu as hosted green. Efficiency as well as source: Scaleway reported an average PUE of 1.37 for 2024 against an industry average around 1.55, and 1.38 and 1.20 for its two Amsterdam sites, cooling with outside air and evaporation rather than mechanical air conditioning.

Check for yourself: run upsensei.eu through the Green Web Foundation’s checker at thegreenwebfoundation.org/green-web-check/?url=upsensei.eu. The answer comes out of their registry, not from us. The same result is machine-readable at api.thegreenwebfoundation.org/greencheck/upsensei.eu, which returns “green”: true together with the hosting provider it found and the evidence documents behind that listing.

Our promise: this is a precise claim, not a green halo. It says the electricity for our hosting is covered by renewable energy through guarantees of origin, the standard European certificates — not that Scaleway generates it on site, and not that UpSensei is climate-neutral or emission-free. It covers neither the manufacture of the hardware nor the two pieces outside our own infrastructure: sign-in through Hanko on AWS in Frankfurt, and the status page on GitHub Pages. We buy no carbon offsets and claim no neutrality.

Scaleway on its environmental footprint

Microsoft-verified publisher for the Teams appVerifiedVerify yourself

When you connect a Microsoft work account to silence alerts during Teams calls, the connection uses our own Entra application, “UpSensei Meeting Detection”. It is published under a Microsoft-verified publisher (“UpSensei”, a member of the Microsoft AI Cloud Partner Program), so the Microsoft sign-in dialog shows a verified publisher rather than an unverified-app warning.

Check for yourself: start the Teams connection and read the publisher line in the Microsoft sign-in dialog.

Nextcloud as the open, self-hosted alternativeSelf-hostedVerify yourself

The same call-silencing also works with Nextcloud Talk, and it is the more sovereign option: Nextcloud is open source and runs on your own instance. Your browser talks directly to your server, your access data stays in your browser, and nothing about it passes through us or any third-party company.

Check for yourself: connect a Nextcloud instance in the call-silencing settings and watch the Network tab. The requests go straight to your own Nextcloud address, not to our servers.

security.txt, following RFC 9116RFC 9116Verify yourself

Found a security problem? We welcome responsible disclosure and will respond quickly.

We publish a security.txt following RFC 9116 at /.well-known/security.txt.

Send security reports to: admin@upsensei.eu

Public status pagePublicVerify yourself

Our uptime and incident history are published on a public status page, hosted independently of our own infrastructure so it stays reachable even during an outage.

What we build on

We choose our providers by how little they need to learn about you and whose law your data falls under. That is why these three.

Scaleway

Application and database. A French provider with datacenters only in the EU, outside the US CLOUD Act, so your posture data runs here rather than on a US hyperscaler.

Scaleway on European data sovereignty
Hanko

Sign-in. A German authentication provider, so we store no passwords and no account needs an email address.

Creem

Payments. An EU merchant of record (Armitage Labs OÜ, Estonia) that sells UpSensei Pro as the seller on record, so card details never touch our systems and a paid account stays pseudonymous with us.