Privacy Policy

What uplika collects, and what we do with it.

Last updated 2026-08-10

uplika publishes to social channels on your behalf, on instructions from you or from an AI agent you connected. This policy sets out what we receive, what we use it for, and who we pass it to.

We do not do what is not written here. If we ever need your data for a purpose not listed, we change this document first.

Who operates uplika

ItemDetail
Business name์ดํ™” STRING
Representativeํ‘œ๋ฏธ์„ 
Business registration number226-04-37766
Address402-1, 316 Tanjung-ro, Ilsandong-gu, Goyang-si, Gyeonggi-do, Republic of Korea
Contactsupport@uplika.com

Throughout this policy, "we" means the business above. It is the entity that decides why and how your personal data is processed.

What we collect

ItemCategoryWhy
Email, name, profile imageAccountTaken at sign-up. From Google or GitHub if you sign up that way, from you if you use email.
PasswordAccountEmail sign-up only. Stored as a hash; we never keep the plaintext.
Phone numberIdentityUsed only to confirm one account per person and to stop free-plan abuse. Stored in international format (E.164). Never used for marketing.
Verification codeIdentityOnly the hash is stored. The six digits we texted you are not kept.
IP address, browserSessionSession management and spotting unusual sign-ins.
Channel access tokenChannelKept so we can publish on your behalf. Stored encrypted, destroyed when you disconnect the channel.
Channel profileChannelThe username, display name, profile image URL and platform account id of the channel you connected, so the dashboard can show you which account it is posting to.
Posts and media you publishServiceKept to show your publishing history and why anything failed, along with the post id and permalink the platform returns. Deleting a post from the channel does not delete our record. That is what lets you still see how far it reached, and it goes when you delete your account.
Posts we open from your channelServiceWhen you open one of your existing channel posts by link, we store its text, id and permalink so the reply, metrics and delete features have something to point at. Only for accounts you connected.
Post metricsServiceViews, likes, replies, reposts, quotes and shares, snapshotted once a day. The platform does not backfill past numbers, so a trend line only exists if we record it.
API keysDeveloperOnly the hash is stored. The plaintext is shown once, at creation.
Request logsOperationsIncident tracing and abuse prevention. Deleted automatically after 30 days.
Subscription statusBillingWhether you subscribe and when it renews. Card details never reach our servers.

Who we share with

RecipientWhatWhy
Google, GitHubSign-inEmail is exchanged when you sign up or sign in.
SOLAPISMSYour phone number is passed on to send the verification text. International numbers go through an overseas route.
Google (Gmail)EmailYour address is used to send sign-up verification and password reset mail.
CloudflareNetwork, image deliveryRequests to api.uplika.com pass through Cloudflare, which receives your IP and request details and uses them for DDoS protection and rate limiting. Images you attach are delivered through cdn.uplika.com.
Backblaze (B2)Image storageImages you attach to a post are stored here, because the channel needs a public URL to fetch them from. Deleted on the schedule below.
PolarPaymentsYour email and payment details are passed on to process the subscription.
The channels you connectPublishingPost text and media are delivered to Threads and any other channel you connected. This happens on your instruction.
Vercel, HostHatchHostingInfrastructure the service runs on. Access logs are kept there.

What an agent is allowed to do

Connecting an AI agent issues that agent an access token. Before it is issued we show you exactly what it covers (read connected accounts, read publishing history, publish) and nothing is issued until you approve.

The agent never receives the channel's own access token. It asks us, and our server is what talks to the channel.

You can revoke an approval at any time from the MCP screen in the dashboard. That agent's token stops working immediately.

How long we keep things

WhatHow long
Account, sessions, workspace, identity records, channel connections, publishing historyDeleted the moment you delete your account
Images attached to a postDeleted automatically 24 hours after the post settles
Uploads never attached to a postDeleted automatically after 48 hours
Posts you deleted from the channel, and their daily metric snapshotsKept until you delete your account. Deleting a post removes it from the channel, not from your history
Request logsDeleted automatically after 30 days
Sign-ups that never finished verificationDeleted automatically after 24 hours

Where Korean law requires a longer retention period, we follow it: contract and withdrawal records for 5 years, payment records for 5 years, and consumer complaint and dispute records for 3 years. No such records exist during the beta because nothing is charged.

Your rights

You can ask to see, correct, delete or restrict processing of your data at any time. You can delete your account yourself from the dashboard settings, and if you cannot sign in, follow the steps on the data deletion page.

Children

uplika is not intended for children under 14. We do not knowingly collect their data, and we delete an account as soon as we find one.

Data protection officer

ItemDetail
Officerํ‘œ๋ฏธ์„ 
Emailsupport@uplika.com
Phone010-8230-5513

Write to us about anything concerning your personal data and we answer without delay.

Changes

If this policy changes we announce it inside the service. Last updated 2026-08-10.