Privacy

Privacy policy

Last updated 7 September 2026 · version 1

HopMango monitors servers. Doing that well means holding some data about your systems and a little about you. This page says exactly which, where it lives, for how long, who else touches it and how to delete it yourself. No legal fog: if something here is unclear, write to us and we will fix the wording.

Who is responsible

The service at hopmango.com, app.hopmango.com and api.hopmango.com and the HopMango app for iOS are operated by VTS Services Inc, Ann Arbor, Michigan, United States ("HopMango", "we"). We are the data controller for your account data and for this website, and the data processor for the monitoring data your organization sends us: that data belongs to your organization, which decides what to monitor.

For anything about this policy, including requests to access or delete your data, write to hello@hopmango.com with the word Privacy in the subject.

Where HopMango runs, and what that means

HopMango is one product with four surfaces, and which one you use decides who holds your data:

  • The hosted service. The portal at app.hopmango.com and the API at api.hopmango.com run on servers we operate. Everything in this policy applies.
  • Self-hosted. HopMango can be installed on your own servers. In that case nothing reaches us: your organization is the only controller, and only the sections about this website and about the app's local storage apply.
  • The agent. A small program you install on the servers you monitor. It opens no listening ports, runs without root and only talks to the HopMango server you point it at. It never talks to us unless that server is ours.
  • The iOS app. Connects to whichever HopMango server you type on the sign-in screen, hosted or self-hosted. It sends nothing to anybody else.

Throughout this page, "the server" means the HopMango installation you or your organization chose.

This website

hopmango.com is a static site. It sets no cookies and loads nothing from third parties. There is no third-party analytics on it, and never has been: the only measurement here is our own product, and the paragraph after the next one says exactly what it records. The font, the images and the styles are served from our own domain. It has one form, on the contact and support pages: what you write there is sent to us as an e-mail through our mail provider and stored nowhere else.

Like every web server, ours writes an access log with the requesting IP address, the page requested, the time and the browser identification, used only to keep the site running and to investigate abuse. Those logs are kept for at most 30 days.

This site and the portal at app.hopmango.com carry HopMango's own RUM snippet: the one our customers install, pointed at ourselves. It records page timings, JavaScript errors, which requests were slow or failed, and a latency sample against our control server, together with the browser family, the device type and the country, worked out on our side from an IP address that is truncated before anything is stored. It sets no cookie and writes nothing at all in your browser: the identifier of a page view lives in memory and dies with the page, so two visits cannot be tied to each other, let alone to a person. It reaches nobody else — the snippet is served from our own domains and reports to our own API.

That country is worked out on our own servers with the free DB-IP IP-to-Country Lite database, a file of address ranges we download once a month and read locally. IP geolocation by DB-IP, used under the Creative Commons Attribution 4.0 licence. Nothing is sent to DB-IP and nothing is looked up over the network: the truncated address is matched against that local file, and then it is gone.

Your account

Accounts are created by opening an organization at app.hopmango.com, or by invitation from an owner of one. For each person we keep:

DataWhy
E-mail addressIdentifies you when signing in; it is the only way to find your account
Name (optional)Shown to colleagues on incidents you acknowledge and in the audit log
PasswordStored only as an argon2id hash. We cannot read it and never send it anywhere
Role and membershipsWhich organizations you belong to and what you may see and do in each
SessionsA random token per sign-in (portal or app), when it was opened, when it expires and when it was revoked. Sessions expire after 30 days and can be closed from the portal or the app
Time of last sign-inShown to owners so they can see who is active
Audit log entriesEvery configuration change in an organization is recorded with who made it and when. The log is append-only

Invitations and password resets are single-use links handed to you by an owner of your organization. We do not send e-mail: there is no mail server behind HopMango, on purpose.

Monitoring data your organization sends

This is the bulk of what a HopMango server holds. It is about machines, not people, and it is sent by the agent, the probes and the browser snippet your organization installs:

  • Hosts: hostname, operating system, agent version, tags, when it was last seen, and the checks it runs.
  • Checks and events: what is monitored, its rules, and every change of state (ok, warning, critical) with a timestamp. The agent evaluates on the host and sends transitions and per-minute aggregates, never raw samples.
  • Synthetics: the URLs your organization asked us to probe and the timing of each result, from our points of presence.
  • Real user monitoring (RUM): performance aggregates from your website's visitors. IP addresses are truncated at ingest and never stored in full, paths are normalized to remove identifiers, and no cookie is set by default. HopMango RUM does not identify individual visitors.
  • Incidents, notes and alert routing: which checks fired, who acknowledged, notes people wrote, and where alerts are delivered. Webhook URLs and other secrets are encrypted at rest and never shown back in full.

Free-text fields (check names, notes, tags) can contain whatever your organization writes in them. Please do not put personal data there.

Mango On-Call

If your organization uses on-call schedules, we also keep who is on call when, the contact methods each person adds (a phone number for voice calls, the devices signed in to the app), and a ledger of every page attempt: when, through which channel and whether it was delivered. That ledger exists so that an organization can prove what was sent to whom during an incident.

Voice calls, when the operator of the server enables them, are delivered through a telephony provider (see subprocessors). Push notifications to the iOS app go through Apple's push service. Neither receives more than the message and the destination.

The HopMango app for iOS

The app is a client for a HopMango server. It contains no analytics and no crash reporting service, no advertising and no advertising identifiers, no third-party software development kits and no tracking across apps or websites. It never asks for your contacts, photos, location, microphone, camera or health data. This is everything it handles:

DataWhereWhy
Server addressOn your device, in the app's settings, until you sign out or delete the appTo know which server to talk to
E-mail and passwordSent once, over HTTPS, to the server you chose when you sign in. Never stored on the deviceTo open a session
Session token, or the organisation API key if you use oneIn the iOS Keychain, on this device only: not synced to iCloud, not included in backups. Kept until you sign out, the session expires or the server revokes itTo authenticate every request without asking for the password again
Device push tokenSent to the server you signed in to, only if you enable notificationsSo that server can send you incident notifications through Apple's push service
Monitoring data you look atFetched from the server while you use the app and held in memory only; nothing is cached on diskTo show incidents, hosts and checks
Actions you takeAcknowledging or resolving an incident and writing a note are sent to the server under your nameSo colleagues see who did what

Notifications are optional. The app asks for permission only when you tap Enable notifications in Settings, and it works fully without them. They carry the incident's title and severity and never contain secrets. You can turn them off in iOS Settings at any time, and the server stops sending to that device when you sign out.

The app's privacy manifest declares no tracking and one single kind of collected data, your e-mail address. Its App Store privacy label says the same: the e-mail address is used only for app functionality, on your organization's server, and is linked to nothing else. The app collects no device identifier and no advertising identifier. The built-in demo organization on the sign-in screen runs entirely on the device and makes no network requests at all.

Mango AI and Anthropic

Mango AI is off by default. When an owner of your organization turns it on, HopMango sends a redacted incident context to Anthropic's Claude API to draft a summary, a suspected cause or a grouping proposal. The context contains check names, states, metrics and configuration changes from the incident window; configuration secrets are removed by an allowlist before anything leaves the server, and that redaction is tested with canaries on every build.

Anthropic processes that data as our subprocessor under its commercial API terms, which do not allow using it to train models. Mango AI never executes anything: it proposes, and a person decides. Every request is recorded in a usage ledger with token counts and cost, never with the request itself. An owner can turn Mango AI off at any time.

Who else processes data

We keep this list short on purpose. Each row is used only for the purpose stated, and only when the condition is met:

WhoWhatWhen
CubePath (United States)Runs the servers and the database of the hosted serviceAlways, for the hosted service
Anthropic PBC (United States)Claude API for Mango AI, on redacted incident contextOnly when an owner enables Mango AI
Apple Inc.Apple Push Notification service, delivering notifications to the iOS appOnly when a person enables notifications in the app
Twilio Inc. (United States)Voice calls for on-call pagingOnly when the server operator configures it and a person adds a phone number
Resend (United States)Delivers the message you write in the contact form of this websiteOnly when you send that form

There is no advertising network, no analytics vendor and no data broker anywhere in HopMango, and we never sell or rent data. If this list changes, the date at the top of this page changes with it.

How long we keep it

Retention is set per data type so that cost and privacy stay predictable. These are the defaults of the hosted service; a self-hosted installation sets its own.

DataKept for
State transitions (events)30 days hot, compressed up to 90 days, then deleted
Per-minute aggregates7 days
5-minute aggregates30 days
Hourly aggregates13 months
Synthetic results90 days
RUM aggregates13 months
Notification and page attempts90 days
Mango AI conversations and messages90 days
Mango AI usage ledger (counts and cost, no content)For the life of the organization
Audit logFor the life of the organization: it is the record of who changed what
Sessions and single-use tokensPurged one week after expiring or being used
Account (e-mail, name, password hash)Until you delete it yourself in Settings → Account, see below
Website access logsAt most 30 days

When an organization is deleted, everything it owns is deleted with it, by cascade in the database. Backups age out on their own schedule of at most 30 days.

Legal bases (GDPR)

Where the General Data Protection Regulation applies, we rely on:

  • Performance of a contract for your account, sessions, on-call contact methods and everything needed to deliver the service you or your organization asked for.
  • Legitimate interest for security: access logs, rate limiting, the audit log and abuse investigation. The interest is keeping the service and every customer's data safe.
  • Consent for push notifications on your phone, which you give through iOS and can withdraw there, and for Mango AI, which an owner of your organization turns on explicitly.

Your rights

You can ask us to access, correct, export, restrict or delete the personal data we hold about you, and to object to processing based on legitimate interest. Write to hello@hopmango.com with Privacy in the subject, from the e-mail address of your account so we can verify it is you. We answer within 30 days.

Most of what we hold about you is visible in the portal: your profile, your memberships and your sessions. Ending the account is there too, under Settings → Account. Owners of an organization can export its monitoring data through the API at any time; the portal is optional and every operation exists in the API.

If you believe we are handling your data unlawfully you can complain to a supervisory authority. In the European Union and the United Kingdom that is the data protection authority of the country you live in. In the United States, where we are based, there is no single one: the Federal Trade Commission (ftc.gov) and the attorney general of your state take these complaints.

Deleting your account and your data

There are three levels, and you choose the one you need:

  1. Sign out of a device. In the app, Settings → Sign out. The session is revoked on the server and the token is removed from the device's Keychain. Push notifications to that device stop.
  2. Leave an organization. Any owner of the organization can remove you from the portal, from the API (DELETE /v1/org/members/{userId}) or through an MCP assistant. Your sessions there are revoked immediately.
  3. Delete your account. Sign in at app.hopmango.com, open Settings → Account and type your own e-mail address to confirm. Your e-mail, your name and your password hash are removed and every session is revoked there and then. Any organization where you are the only person is deleted with the account, and what it held goes on the schedule in the retention table above. If you are the only owner of an organization that still has other people or hosts in it, deletion is refused until you promote another owner or delete that organization on purpose, so no organization is ever left without anyone who can run it. Audit-log entries keep a record that a change was made, under an internal identifier that no longer resolves to you. If you cannot sign in, because you have lost the address or no longer have a password, write to hello@hopmango.com with Delete my account in the subject, from your account's address: we do it and confirm by reply within 30 days.

An organization is deleted by any of its owners from the portal or the API, and it goes with the account of the last person left in it. The iOS app creates no accounts, so it deletes none either: the account ends where it lives, in the portal.

Security

Every table in the database carries the organization it belongs to and is protected by row-level security enforced by the database itself, not by application code; a test in our continuous integration tries to read another organization's data from every table and demands zero rows. Passwords are argon2id hashes. Webhook URLs and origin secrets are encrypted at rest. Secrets never appear in logs, API responses or the context sent to a model: that is a build-blocking test, not a policy. All traffic is HTTPS.

Children

HopMango is a tool for people who operate servers. It is not directed at anyone under 16 and we do not knowingly hold data about them. If you think we do, write to us and we will delete it.

Changes to this policy

When we change this page we update the date and the version number at the top. Material changes, such as a new subprocessor, are also announced to organization owners in the portal before they take effect.

Previous versions of this page are kept in the public repository of the website, so the history of what we promised is always readable.