UPEC legal

Privacy Policy

This policy describes categories of information used to operate UPEC.

Effective: 12 September 2026

Information processed

UPEC may process account and authentication data, organization and project data, compilation/history data, conversation and memory data, usage records, billing identifiers, provider-connection metadata and security/audit records.

Provider credentials

Provider credentials are supplied by the user under the BYOK model.

UPEC is designed to store provider credentials in encrypted form and not return the stored secret through the normal provider API.

Payments

Payment processing may be performed by third-party payment processors such as Stripe. UPEC does not treat provider API spending as UPEC subscription spending.

Security and legal obligations

Information may be processed as necessary to secure the Service, investigate abuse, maintain auditability, comply with law and enforce contractual rights.

Mandatory rights

Applicable privacy and data-protection rights remain available according to the law that applies to the user.

These policies are subject to mandatory law. Nothing on this page is intended to remove rights that cannot legally be excluded.