Privacy notice
What Udibo collects when you visit this site, join the waitlist, or hold an account here; why; who it reaches; how long it is kept; and how to have it removed. It is written from the code that runs, not from a template.
Last updated 1 September 2026.
Who is responsible
Udibo, operating from Ohio in the United States. For anything about your information — a question, a copy of what is held, a correction, or deletion — write to [email protected] and a person will answer. There is no charge and you will not be asked why.
If you signed in to someone else's product
Udibo runs sign-in for other companies' products. If you reached Udibo that way, the company running the product decides what is collected about you and why, and this notice is theirs to write. Udibo holds that data on their instructions, uses it for nothing of its own, and passes any request about it to them. Ask them first; if you cannot reach them, write to [email protected] and we will help.
Anything Udibo's staff do inside a customer's product — even acting as one of its users to help with support — is written to that customer's own audit log, and a support session shows a banner the whole time.
Visiting the site
Reading these pages records nothing about you beyond the request log the hosting provider keeps to serve and protect the site. There is no advertising, analytics, or tracking here. Your choice of light or dark theme is stored in your own browser and never sent to us.
The cookies Udibo sets are the ones that keep you signed in, protect forms from cross-site submission, and remember a browser you have signed in from before — none of them is used to profile you.
Joining the waitlist
The waitlist collects your email address, your answers to any questions on the form, and the time you joined. That is used to tell you when sign-ups open and to send the confirmation and removal emails that let you control the entry — nothing else. It is not used for marketing, not sold, and not shared with anyone for their own purposes. The lawful basis is your consent, which you withdraw by removing the entry.
To remove it, enter your address in the removal box on the waitlist page, or follow the removal link at the bottom of any email Udibo sends you. You will get a confirmation link, and using it deletes the address and your answers. The link is what proves the mailbox is yours — otherwise anyone who guessed your address could remove you.
Holding an account
An account on Udibo's own dashboard is the one case where Udibo itself decides what to collect. It is what running the service for you requires, and no more:
- Who you are
- Your username, email address, and name, plus any profile details you choose to add. Your password is stored only as a hash; a second-factor secret is stored encrypted and recovery codes hashed, so none of them can be read back.
- Where you are signed in
- Each session records the IP address and browser it was started from, so you can see and revoke it from your security page.
- What happened to the account
- Sign-ins and failed attempts, password resets, and every administrative change, each with the address and browser it came from. This is what lets you — and Udibo — answer whether an action was really yours.
- Browsers you have used before
- A memory of which browsers and networks have signed in to the account, so an unfamiliar one can be recognised.
Holding the account is the basis for the first two; keeping the account secure is the basis for the rest, and it is not optional. The tenants you create hold your customers' data, which is yours and theirs — Udibo holds it on your instructions and uses it for nothing of its own.
Who else it reaches
Only the services Udibo runs on, each acting on Udibo's instructions and none of them permitted to use your information for their own purposes:
Neon Hosts the database every account, session, and waitlist entry is stored in.
Deno Deploy Runs the site and the service, and keeps its request logs.
Resend Delivers the emails an account needs — verification, password reset, sign-in codes and links, invitations — and the waitlist's confirmation and removal emails.
Cloudflare Runs the anti-bot challenge on the sign-up, sign-in, password-reset and waitlist forms, which sees your IP address and browser signals to tell a person from a script.
Upstash Holds the short-lived counters that limit repeated attempts at a form, keyed by network address or account. Each expires with the window it counts.
These services are based in the United States, so your information is processed there. Udibo will publish a fuller subprocessor list, with advance notice of changes, when the hosted service opens.
How long it is kept
- A waitlist entry
- 90 days after it has served its purpose — you were told sign-ups are open, invited, or declined. An entry still waiting is never purged. Removing yourself deletes it at once.
- A session
- Until you sign out, it expires, or you revoke it from your security page. Deleting your account revokes every session and clears the address and browser recorded on each.
- Sign-in and administrative records
- 365 days from the event, then deleted. These are kept for security and outlive account deletion, so an account cannot erase the record of what was done with it.
- The memory of a browser you have signed in from
- 365 days from its last use, then deleted.
- The account itself
- Deleting an account suspends it, which is reversible on request. To have it erased outright rather than suspended, write to us.
Your rights
Depending on where you live you may have the right to a copy of what is held about you, to have it corrected, to have it deleted, or to object to it being held at all. Write to [email protected] and Udibo will do it. Removing a waitlist entry and revoking a session need no request — both are self-serve, as described above.
Changes
If this notice changes in a way that affects what happens to information already held, everyone it affects is emailed before the change takes effect. Smaller corrections are made here with the date above updated.

