Uplynx

Legal

Privacy Policy

Novos Publishing LLC · Last updated September 13, 2026

What Novos Publishing LLC collects when you use Uplynx, why, who else touches it, and what you can ask us to do about it.

1. Who is responsible for your data

Novos Publishing LLC, a Texas limited liability company, of 5900 Balcones Dr #100, Austin, TX 78731, United States, is the controller of the personal data described in this policy. This policy covers Uplynx — the web application, the MCP server, and the accounts and workspaces behind them.

Where we process content on your behalf as part of running a workspace for you, we act as a processor and you are the controller. Our Data Processing Addendum sets out those terms.

2. What we collect

Account data. When you sign up, our identity provider gives us your name, your email address and an account identifier. We store those so we can show you who you are, attribute your activity, and contact you about your account.

Workspace data. The name of each workspace you create or join, and which accounts are members of it.

Project content. Everything you or a client you have connected writes into the service — project names and descriptions, context entries, decisions, findings, tasks, session summaries and the append-only event record. We do not inspect this content, and we do not control what your client sends. It can contain personal data if you put personal data in it.

Usage records. Counts of activity per workspace per day, which we use for capacity, plan limits and diagnosis.

Technical data. Our hosting provider logs the ordinary technical detail of a web request — IP address, timestamp, user agent, the path requested and the response — and retains it for a limited period for security and operations.

Payment data. If you purchase a paid plan, our payment processor collects your billing details and payment method directly. We receive a record of the transaction, the plan and the billing contact. We never receive or store your full card number.

Integration data. If you choose to connect a code repository, we receive the repository events you have configured it to send us and store them alongside the project you connected it to.

Support correspondence. If you write to us, we keep the message and our reply.

3. What we do not do

We do not use your content or your personal data to train machine-learning models, ours or anyone else's.

We do not sell or share your personal information, and we have not in the preceding twelve months. We do not share it for cross-context behavioural advertising.

We do not run advertising, and we do not use advertising or analytics trackers that follow you to other sites.

We do not read your project content except where you specifically ask us to in order to help with a support request, or where we are compelled by law.

4. Why we process it

  • to provide the service — storing your projects and serving them back to the clients you connect
  • to authenticate you and keep accounts and workspaces separate from one another
  • to bill you, where you are on a paid plan, and to keep the records tax and accounting law requires
  • to keep the service secure — detecting abuse, investigating incidents, and enforcing our Terms
  • to support you when you ask
  • to operate and improve the service itself, which means diagnosing faults and understanding capacity — not training models on your content
  • to tell you about material changes to the service, the Terms or this policy

5. Legal bases, if you are in the EEA or the UK

  • Performance of a contract — providing the service you signed up for, and billing you for it.
  • Legitimate interests — keeping the service secure, preventing abuse, diagnosing faults, and defending legal claims. We balance these against your rights and do not rely on them where yours override.
  • Legal obligation — retaining financial records, and responding to lawful requests.
  • Consent — where we ask for it, for example before sending a message that is not about your account. You can withdraw consent at any time.

6. Who else processes it

We use a small number of infrastructure providers to run the service. They process your data only to provide their service to us, under contract, and they are not permitted to use it for their own purposes. The current list — who they are, what they do and where they process — is published on our Subprocessors page, which is part of this policy.

Beyond those providers, we disclose personal data only where we are legally required to, where it is necessary to establish or defend a legal claim, or where it is necessary to prevent harm. If we are compelled to disclose your data, we will tell you unless we are prohibited from doing so.

If the business is sold, merged or transferred, your data may transfer with it. This policy continues to apply until you are given notice of a replacement.

7. Where your data is processed

The service and every provider we use are hosted in the United States. If you are in the EEA, the UK or Switzerland, your data is transferred to and processed in the United States.

Those transfers are made under the European Commission's Standard Contractual Clauses, together with the UK Addendum where the UK GDPR applies, and we require the same of our providers. A copy of the clauses we rely on is available on request.

8. How long we keep it

We keep your account and project content for as long as your account is open.

If you delete a project it is removed from the live service at once — it no longer appears in your project lists, briefings or exports — and moves to a bin, where you can restore it for 90 days. After 90 days an automatic process destroys it permanently: the project, its documents, the files stored with them, and the record of what was done inside it. What remains is the fact that a project existed and was deleted, together with per-day counts of tool use, which are billing records and hold no part of your content.

If you close your account, you may export your content for 30 days, after which we delete it from live systems.

Deleted content can persist for a limited further period in encrypted database backups, which exist so that we can recover from a failure. Those backups age out automatically on a rolling schedule and are not used for any other purpose.

The event record inside a project is append-only: entries can be superseded by later entries but are not rewritten in place. That is a design property of the product, and it means correcting a past entry adds a correction rather than editing history. Deleting the project removes the record.

We keep invoices and other financial records for as long as tax and accounting law requires, and support correspondence for as long as it is useful to resolving the matter.

9. Your rights

Wherever you live, you can ask us to:

  • tell you what personal data we hold about you, and give you a copy
  • correct it if it is wrong
  • delete it
  • give it to you, or to someone else you nominate, in a portable form
  • restrict or object to a particular use of it

If you are in the EEA or the UK, those are your rights under the GDPR, and you can also complain to your local supervisory authority. If you are in California, the CCPA as amended gives you rights to know, delete, correct, and to opt out of sale or sharing — we do not sell or share, so there is nothing to opt out of — and we will not discriminate against you for exercising any of them. Other US state privacy laws give comparable rights and we apply the same process to all of them.

Write to zero2ceo.email@gmail.com from the address on your account and we will act within 30 days, or tell you why we need longer. We may need to verify who you are before we act, which for content inside a workspace can mean confirming with the workspace owner.

If you are a member of a workspace someone else owns, some of your requests are theirs to answer rather than ours, because the content belongs to their workspace. We will tell you if that is the case and pass the request on.

10. Cookies and local storage

We use cookies set by our identity provider to keep you signed in and to protect the sign-in flow. These are strictly necessary — without them the application cannot tell who you are.

We store your light or dark theme choice in your browser's local storage so the page does not flash the wrong theme before it loads. It never leaves your browser.

We do not set advertising cookies and we do not use third-party analytics that track you across sites.

11. Security

Data is encrypted in transit and at rest. Access is separated by workspace at the point of every query, and administrative access to production is limited to people who need it.

Please do not store credentials, API keys or payment card data inside project content. The service is not built to hold secrets and does not treat that content as secret.

No service is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and any regulator we are required to notify, without undue delay.

12. Children

The service is not for children. It is not directed at anyone under 18, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, write to us and we will delete it.

13. Changes to this policy

We will update this policy as the service changes. If a change materially affects how we handle your personal data, we will give you notice by email or in the application before it takes effect. The date at the top of this page is the date of the current version.

14. Contact

For anything in this policy, including a request about your data, write to zero2ceo.email@gmail.com, or by post to Novos Publishing LLC, 5900 Balcones Dr #100, Austin, TX 78731, United States.

Questions go to zero2ceo.email@gmail.com.

TermsPrivacySubprocessorsAddendum

© Novos Publishing LLC