Privacy policy
This policy explains how Model Uplink handles personal data when you visit the website, create an account, connect an endpoint, or use the service.
1. Controller
Oscar Rojas et al, Quartiersweg 7, 10829 Berlin, Germany. Email: contact@modeluplink.com.
2. Data we process
- Account and access data: email address, session and device-login records, and security events.
- Endpoint data: endpoint name, engine, selected region, connection presence, and scoped API-key identifiers. Secret API keys are displayed once and stored only in hashed form.
- Billing data: customer, subscription, invoice, payment status, and tax information received from Stripe. We do not store full card details.
- Operational metadata: endpoint identifier, selected region, connection timing and encrypted byte counts, plus ordinary security and server logs. The relay cannot read inference routes or request contents.
- Support data: information you send us when requesting help.
3. Inference content
Prompts, responses, images, embeddings, and other inference content are protected by endpoint TLS between your app and the Model Uplink agent on your machine. The endpoint's TLS private key is generated and stored on that machine and is not provided to the relay. In the deployed data path, our relay routes the connection using its destination hostname and forwards ciphertext; it does not terminate endpoint TLS or receive inference content, API authorization headers, or routes. The local agent validates the endpoint key using a one-way proof, applies the route allowlist, removes inbound authorization, cookie, hop-by-hop, and proxy headers, and then forwards the request to your local model. The control API receives the key identifier and one-way proof, not the reusable endpoint key or inference content. Like other HTTPS connections, clients rely on the public certificate and DNS ecosystem and the integrity of the software and control plane. Your connected model and any app you use may process content under their own terms.
4. Purposes and legal bases
- To create and perform your service contract, authenticate you, connect endpoints, and provide support (Article 6(1)(b) GDPR).
- To bill for the service and meet tax, accounting, and other legal duties (Article 6(1)(b) and (c) GDPR).
- To secure, operate, debug, and improve service reliability, prevent abuse, and enforce fair-use limits (Article 6(1)(f) GDPR). Our legitimate interests are a secure and dependable service.
- Where we ask for optional consent, on the basis of Article 6(1)(a) GDPR. You may withdraw consent at any time.
5. Service providers and international transfers
We use service providers where needed to operate Model Uplink, including Amazon Web Services for hosting and email, Stripe for billing and tax, and Cloudflare for DNS, security, and edge delivery. These providers process data under their own data-protection terms and our agreements with them. Where data is transferred outside the European Economic Area, we rely on an adequacy decision or appropriate safeguards such as the European Commission's standard contractual clauses.
6. Retention
We keep account and endpoint records while your account is active and for the limited period needed to close it, resolve disputes, prevent fraud, and satisfy legal duties. Billing and tax records are retained for applicable statutory periods. Security and operational metadata is kept only as long as reasonably necessary for security, reliability, and abuse prevention, then deleted or anonymized. Revoked credential hashes may be retained where necessary to prevent reuse.
7. Website storage and cookies
The dashboard stores its session token in your browser's session storage. It is removed when you sign out or close the browser session. We do not currently use advertising cookies. If optional analytics or similar technologies are introduced, we will update this policy and request consent where required.
8. Your rights
Subject to the GDPR's conditions, you may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent without affecting earlier lawful processing. Contact contact@modeluplink.com to exercise these rights. You may also complain to a supervisory authority, including the Berlin Commissioner for Data Protection and Freedom of Information.
9. Security and changes
We use technical and organisational safeguards appropriate to the risk, including encryption in transit, scoped credentials, access controls, and content-minimising telemetry. No internet service is risk-free. We may update this policy as the service or law changes; the date above identifies the latest version.