MUModel Uplink
LEGAL · LAST UPDATED 4 SEPTEMBER 2026

Privacy policy

1. Controller

Oscar Rojas et al, Quartiersweg 7, 10829 Berlin, Germany. Email: contact@modeluplink.com.

2. Data we process

3. Inference content

Prompts, responses, images, embeddings, and other inference content are protected by endpoint TLS between your app and the Model Uplink agent on your machine. The endpoint's TLS private key is generated and stored on that machine and is not provided to the relay. In the deployed data path, our relay routes the connection using its destination hostname and forwards ciphertext; it does not terminate endpoint TLS or receive inference content, API authorization headers, or routes. The local agent validates the endpoint key using a one-way proof, applies the route allowlist, removes inbound authorization, cookie, hop-by-hop, and proxy headers, and then forwards the request to your local model. The control API receives the key identifier and one-way proof, not the reusable endpoint key or inference content. Like other HTTPS connections, clients rely on the public certificate and DNS ecosystem and the integrity of the software and control plane. Your connected model and any app you use may process content under their own terms.

4. Purposes and legal bases

5. Service providers and international transfers

We use service providers where needed to operate Model Uplink, including Amazon Web Services for hosting and email, Stripe for billing and tax, and Cloudflare for DNS, security, and edge delivery. These providers process data under their own data-protection terms and our agreements with them. Where data is transferred outside the European Economic Area, we rely on an adequacy decision or appropriate safeguards such as the European Commission's standard contractual clauses.

6. Retention

We keep account and endpoint records while your account is active and for the limited period needed to close it, resolve disputes, prevent fraud, and satisfy legal duties. Billing and tax records are retained for applicable statutory periods. Security and operational metadata is kept only as long as reasonably necessary for security, reliability, and abuse prevention, then deleted or anonymized. Revoked credential hashes may be retained where necessary to prevent reuse.

7. Website storage and cookies

The dashboard stores its session token in your browser's session storage. It is removed when you sign out or close the browser session. We do not currently use advertising cookies. If optional analytics or similar technologies are introduced, we will update this policy and request consent where required.

8. Your rights

Subject to the GDPR's conditions, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing. Contact contact@modeluplink.com to exercise these rights. You may also complain to a supervisory authority, including the Berlin Commissioner for Data Protection and Freedom of Information.

9. Security and changes

We use technical and organisational safeguards appropriate to the risk, including encryption in transit, scoped credentials, access controls, and content-minimising telemetry. No internet service is risk-free. We may update this policy as the service or law changes; the date above identifies the latest version.