UPEC legal
Privacy Policy
This policy describes categories of information used to operate UPEC.
Effective: 12 September 2026
Information processed
UPEC may process account and authentication data, organization and project data, compilation/history data, conversation and memory data, usage records, billing identifiers, provider-connection metadata and security/audit records.
Provider credentials
Provider credentials are supplied by the user under the BYOK model.
UPEC is designed to store provider credentials in encrypted form and not return the stored secret through the normal provider API.
Payments
Payment processing may be performed by third-party payment processors such as Stripe. UPEC does not treat provider API spending as UPEC subscription spending.
Security and legal obligations
Information may be processed as necessary to secure the Service, investigate abuse, maintain auditability, comply with law and enforce contractual rights.
Mandatory rights
Applicable privacy and data-protection rights remain available according to the law that applies to the user.