Security is an ongoing practice, not a badge. This page describes the controls implemented in Allyup and avoids claims the product has not independently certified.
Sign-in and sessions
Allyup uses Sign in with Apple and Google Sign-In rather than creating a separate Allyup password. Session credentials are stored in the iOS Keychain on your device. Access tokens are short-lived, while refresh credentials are rotated by the Allyup service.
Data in transit
Communication between the app, Allyup’s Convex backend, and media services uses HTTPS or secure real-time connections. This encrypts data while it travels over the network.
Crew access
Allyup’s product model scopes habit activity to crews. Check-ins are displayed to members of the groups you share them with. Invite links should be treated as invitations: only send them to people you intend to include.
Photos, videos, and comments
Photos and videos are uploaded directly to Cloudinary using server-signed upload parameters. Secret signing credentials remain on the server rather than being embedded in the iOS app. User-written captions and comments pass through server-side screening before they are posted.
Service providers
Allyup relies on specialized providers for the service to work: Convex for application data and real-time sync, Cloudinary for media storage and delivery, Firebase for notifications and diagnostics, and Apple or Google for sign-in. See the Privacy Policy for the data categories involved.
Your controls
- Choose which crews receive a check-in;
- Report a moment from its actions menu or report a comment by touching and holding it; reported content is hidden from you immediately;
- Block another account from the same menus and manage blocked accounts from Profile;
- Manage notification permissions in iOS Settings and category preferences in Allyup;
- Delete content you posted;
- Permanently delete your account from the Profile screen.
What we do not claim
Allyup does not currently claim end-to-end encryption, a formal compliance certification, or a completed independent security audit. HTTPS protects data in transit, but members of a crew can see content shared with that crew.
Report a concern
Use Allyup’s in-app report action for objectionable moments or comments so the report reaches the moderation queue with the correct content attached. For a vulnerability or an account-safety issue that is not tied to one post, email support@allyup.club. Include the affected feature, steps to reproduce, and any screenshots that do not expose someone else’s private information.