Privacy Policy
What uplika collects, and what we do with it.
Last updated 2026-10-01
uplika publishes to social channels on your behalf, on instructions from you or from an AI agent you connected. This policy sets out what we receive, what we use it for, and who we pass it to.
We do not do what is not written here. If we ever need your data for a purpose not listed, we change this document first.
Who operates uplika
| Item | Detail |
|---|---|
| Business name | 이화 STRING |
| Representative | 표미선 |
| Business registration number | 226-04-37766 |
| Address | 402-1, 316 Tanjung-ro, Ilsandong-gu, Goyang-si, Gyeonggi-do, Republic of Korea |
| Contact | support@uplika.com |
Throughout this policy, "we" means the business above. It is the entity that decides why and how your personal data is processed.
What we collect
| Item | Category | Why |
|---|---|---|
| Email, name, profile image | Account | Taken at sign-up. From Google or GitHub if you sign up that way, from you if you use email. |
| Password | Account | Email sign-up only. Stored as a hash; we never keep the plaintext. |
| Phone number (sign-ups before 28 September 2026) | Identity | We no longer ask for a phone number at sign-up. Numbers we verified before that date are kept apart from your account and used for nothing. They go when you delete your account. Stored in international format (E.164). Never used for marketing. |
| IP address, browser | Session | Session management and spotting unusual sign-ins. |
| Sign-up country | Account | When you sign up we keep one country code (for example, KR) for where you connected from. Cloudflare estimates it from your IP address, and we do not store the IP address with it. We use it only to count which countries sign-ups come from. |
| Channel access token | Channel | Kept so we can publish on your behalf. Stored encrypted, destroyed when you disconnect the channel. |
| Channel profile | Channel | The username, display name, profile image URL and platform account id of the channel you connected, so the dashboard can show you which account it is posting to. |
| Posts and media you publish | Service | Kept to show your publishing history and why anything failed, along with the post id and permalink the platform returns. Deleting a post from the channel does not delete our record. That is what lets you still see how far it reached, and it goes when you delete your account. |
| Posts we open from your channel | Service | When you open one of your existing channel posts by link, we store its text, id and permalink so the reply, metrics and delete features have something to point at. Only for accounts you connected. |
| Post metrics | Service | Views, likes, replies, reposts, quotes and shares, snapshotted once a day. The platform does not backfill past numbers, so a trend line only exists if we record it. |
| API keys | Developer | Only the hash is stored. The plaintext is shown once, at creation. |
| Request logs | Operations | Incident tracing and abuse prevention. Deleted automatically after 30 days. |
| Keyword research records | Service | When you save a keyword research (in the market research screen, or through a connected agent), we keep the keywords you entered, the chosen set and the prompt built from it, so you can come back to it. Deleted with your account. |
| Support messages and attached images | Support | What you send through the Contact us window in the dashboard, with any images, so we can answer it. The page you sent it from and your account email are kept with it. Images are deleted after 90 days. |
| Subscription status | Billing | Whether you subscribe and when it renews. Card details never reach our servers. |
| Analytics cookie | Traffic | Google Analytics sets a cookie (_ga) that tells one visitor apart from another so we can count page views and where visits come from. It does not identify you and we do not store your IP address. It is not set on this page, the terms page, the data deletion page, or the upload page. |
Who we share with
| Recipient | What | Why |
|---|---|---|
| Google, GitHub | Sign-in | Email is exchanged when you sign up or sign in. |
| Google (Gmail) | Your address is used to send sign-up verification and password reset mail. | |
| Cloudflare | Network, image delivery | Requests to api.uplika.com pass through Cloudflare, which receives your IP and request details and uses them for DDoS protection and rate limiting. Images you attach are delivered through cdn.uplika.com. |
| Backblaze (B2) | Image storage | Images you attach to a post are stored here, because the channel needs a public URL to fetch them from. Images attached to a support message are stored here too. Deleted on the schedule below. |
| Google (YouTube Data API) | Search terms | The search terms you enter in the YouTube search research tool are sent to Google to fetch public video data. No account information goes with them, and the results are deleted after 90 days. |
| Polar | Payments | Your email and payment details are passed on to process the subscription. |
| The channels you connect | Publishing | Post text and media are delivered to Threads and any other channel you connected. This happens on your instruction. |
| Vercel, HostHatch | Hosting | Infrastructure the service runs on. Access logs are kept there. |
| Google (Analytics) | Page views, referrer, device, approximate location | Traffic analysis: which pages are read and where visits come from. Google Signals is switched off, so nothing here is used for ad personalisation or cross-device tracking. Workspace names, upload links and agent authorisation requests are removed from the address before it is sent. |
| Google (Gemini API) | The post text you wrote, reduced copies of images you attached, and the brand voice you saved | Only when you press Generate with AI in the composer. Nothing is sent before that. Google's terms for the API tier we use say whether prompts may be used to improve its models; we link them from the composer. |
| Naver (Search Ad, API HUB) | Search keywords you enter in the composer's keyword card, the market research screen, or through a connected agent or API key | Only when you ask to measure them. Keywords are public search terms, not your posts; the measured numbers are cached for seven days and shared between users. |
| Naver (autocomplete) | Seed keywords an agent or API key asks to expand | Only when a connected agent or an API key calls the keyword expansion, and only if that feature is switched on for the server (it is off by default). Our server sends the seed to Naver's autocomplete and keeps the words that come back for seven days. The dashboard's own expansion runs in your browser instead. |
| Naver (blog RSS) | The blog id you enter for a blog diagnosis | Only when you ask for a diagnosis, in the market research screen or through a connected agent. Our server reads that blog's public RSS feed (its latest post titles) and keeps the summary for 24 hours; it is public data and is not tied to your account. |
Cookies and how to refuse them
uplika sets two kinds of cookie. The first keeps you signed in and remembers your language and screen preferences (the AI model you picked, notices you dismissed); the service does not work without it. The second is the Google Analytics cookie described above, which only counts visits.
You can refuse the analytics cookie in your browser settings by blocking cookies from google-analytics.com, or by installing Google's opt-out add-on. Refusing it does not limit anything you can do in uplika.
Google's own policy explains what it does with the data it receives.
What an agent is allowed to do
Connecting an AI agent issues that agent an access token. Before it is issued we show you exactly what it covers (read connected accounts, read publishing history, publish) and nothing is issued until you approve.
The agent never receives the channel's own access token. It asks us, and our server is what talks to the channel.
You can revoke an approval at any time from the MCP screen in the dashboard. That agent's token stops working immediately.
The Naver Blog browser extension
Naver Blog has no official publishing API. To publish there, uplika offers a Chrome extension that runs in your own browser and writes the post through Naver's editor while you are logged in to Naver. The extension does only the channel work you asked uplika for: it puts posts you asked uplika to publish on your Naver Blog, does the things a person does around posts when you ask (replying to a comment, liking, adding a neighbor), and, if you have turned on a comment-reply automation, reads that blog's comment management page every five minutes and reports new comments to uplika. Turn the automation off and it stops reading. If you have turned on a neighbor-post comment automation, it reads that account's neighbor feed every thirty minutes and its neighbor list every six hours, reports mutual neighbors' new posts to uplika, and reads each such post's body so that one AI-written comment, following the instructions you set, can be posted on it. Turn that automation off and it stops reading too. When you ask uplika for your Naver drafts, it reads the blog's draft box (titles and saved times) and loads the draft you picked in the editor to publish it as it is or to delete it. When you ask uplika about one of your own posts (to open it, list your posts, or read its comments or view counts), it reads that post's page. When you ask uplika to edit a post you wrote directly in Naver's editor, it opens that post's edit screen and reads its body, category, visibility and tags, so the edit keeps the parts you did not change.
The extension never asks for, reads or stores your Naver password, and it never sends your Naver cookies or login session to uplika or anyone else. Publishing happens inside your browser, using the login you already have there. What the extension sends to uplika is the result of the job: the post's Naver id, its address, and whether the images and tags landed. While a comment-reply automation is on, it also sends what it read from the comment management page: comment id, post id, the writer's id and nickname, the text and the time. Those are public comments on your own blog; uplika uses them to post the reply you configured and to keep the writer as a contact. While a neighbor-post comment automation is on, it also sends what it read from the neighbor feed and the neighbor list (the post owner's blog id and nickname, the post id, its title, address, time and visibility) and, for the post it is about to comment on, that post's body. Those are posts your mutual neighbors shared with their neighbors; uplika uses them to write the comment and to record which posts it commented on. When you ask uplika to publish one of your drafts, it also sends that draft's title, body, tags and category; those are your own drafts, and uplika keeps them as the publish record. What it receives from uplika is the post you asked to publish: title, body, images, category and tags.
When you run keyword research in the uplika dashboard, or your AI agent asks uplika to expand seed keywords for a blog post (the Naver keyword research tool, if you have turned it on for your agent), the extension looks up Naver's search suggestions for those keywords in the background, from your own internet connection. It sends Naver only the keywords you or your agent gave, attaches no cookies, opens no window or tab, and sends the suggestions back to the uplika page or to uplika for you. It uses the Naver permission described below; if the extension is off or that permission is missing, uplika's server looks them up instead, and if that is off too, your browser asks Naver directly as before.
Naver keeps only one account signed in at a time. So that each workspace publishes as the right account, the extension keeps your Naver sign-ins in this browser's extension storage and puts the right one back before it publishes. It reads and writes Naver's own cookies, only on this computer, and never sends them anywhere. The browser asks for this permission when you connect Naver Blog, not at install, and only then; if you use other channels only, it is never asked. Removing an account from the connection screen, or removing the extension, deletes the saved sign-ins. Treat them as the same level of protection as the cookies your browser already stores: anyone with access to this computer's browser profile could reach them, so do not connect Naver Blog on a shared machine.
On this computer the extension keeps a pairing token that ties it to your uplika workspace, the workspace name, and the blog id it found. That is stored in the browser's extension storage and nowhere else. Removing the extension deletes it. You can also disconnect a workspace from the extension's popup, or revoke the pairing from the uplika dashboard, and the extension stops receiving jobs at once.
While the extension is paired, uplika stores the blog id, the blog's category list and a record of each job (what was requested, what happened, when). That is the same kind of publishing history we keep for every channel and it follows the retention rules below.
YouTube and your Google data
uplika uses YouTube API Services. When you connect a YouTube channel, we reach it through the YouTube Data API, and only on your instruction or that of an agent you authorized.
What we hold is listed in the tables above: the channel's access and refresh tokens, its profile and upload playlist id, the videos you publish through us, the comments on the videos you point us at, and the daily metric snapshots. We do not sell it and we do not use it for advertising.
Disconnecting the channel in uplika deletes the stored tokens. Separately from that, you can revoke our access from your Google Account at any time, which cuts us off even if you never open uplika again.
TikTok
When you connect a TikTok account, uplika signs you in through TikTok Login Kit and posts through the TikTok Content Posting API, only on your instruction or that of an agent you authorized.
From TikTok we receive and keep the account's id, display name, username and profile picture, and its access and refresh tokens, sealed as described below. We keep the videos and photos you publish through us, the settings you chose for each post (who can see it, whether comments, Duet and Stitch are allowed, and any commercial content disclosure) and the post id TikTok returns. Before each post we ask TikTok what the account can post right now (its visibility options, interaction settings and maximum video length) and show that to you; we do not keep that answer. When you ask for a post's numbers, we read its public view, like, comment and share counts. We do not sell any of it and we do not use it for advertising.
We never post without your instruction, and we never add watermarks, logos or promotional text to your content. Disconnecting the account in uplika deletes the stored tokens. You can also remove uplika's access from the TikTok app at any time.
How we protect your data
Everything moves over TLS. uplika.com and api.uplika.com are served over HTTPS only, and requests to the API pass through Cloudflare before they reach the origin server.
Channel access and refresh tokens, including the Google and YouTube tokens described above, are sealed with AES-256-GCM before they are written to the database. Each record carries its own initialization vector and an authentication tag, so a tampered value fails on read instead of passing silently. The key lives in the server's environment and never in the database, so a copy of the database on its own does not yield a usable token.
Anything we never need to read back is stored as a hash rather than as text: your password, your API keys, and the tokens we issue to agents you connect. An API key's plaintext is shown once, at creation, and cannot be retrieved afterwards.
The database is not reachable from the internet. Only the application server connects to it, and administrative access to that server is by SSH key, with password login disabled. Access to production data is limited to the operator named above.
No security measure is absolute. If a breach ever affects your personal data, we notify you and the relevant authority as the law requires.
How long we keep things
| What | How long |
|---|---|
| Account, sessions, workspace, identity records, channel connections, publishing history | Deleted the moment you delete your account |
| Images attached to a post | Deleted automatically 24 hours after the post settles |
| Uploads never attached to a post | Deleted automatically after 48 hours |
| Images attached to a support message | Deleted automatically after 90 days |
| Posts you deleted from the channel, and their daily metric snapshots | Kept until you delete your account. Deleting a post removes it from the channel, not from your history |
| Request logs | Deleted automatically after 30 days |
| Sign-ups that never finished verification | Deleted automatically after 24 hours |
| Keyword research records | Kept until you delete your account, then deleted immediately |
| Public statistics caches (blog diagnosis 24 hours, keyword autocomplete 7 days, keyword measurement history 400 days) | Not tied to any account; purged on that schedule |
| Analytics data at Google | 14 months. The _ga cookie itself expires after 2 years |
Where Korean law requires a longer retention period, we follow it: contract and withdrawal records for 5 years, payment records for 5 years, and consumer complaint and dispute records for 3 years. No such records exist during the beta because nothing is charged.
Your rights
You can ask to see, correct, delete or restrict processing of your data at any time. You can delete your account yourself from the dashboard settings, and if you cannot sign in, follow the steps on the data deletion page.
Children
uplika is not intended for children under 14. We do not knowingly collect their data, and we delete an account as soon as we find one.
Data protection officer
| Item | Detail |
|---|---|
| Officer | 표미선 |
| support@uplika.com | |
| Phone | 010-8230-5513 |
Write to us about anything concerning your personal data and we answer without delay.
Changes
If this policy changes we announce it inside the service. Last updated 2026-10-01.