Legal
Privacy Policy
Effective July 17, 2026
1. What we collect
When you sign in, we receive from GitHub or Google:
- Your email address
- Your display name and profile picture
- An OAuth account identifier
When you subscribe to a paid plan, Stripe handles payment processing. We store your Stripe customer ID and subscription ID, but never your card details.
We also store the projects, API keys, and feedback data you create or collect through the Service.
2. How we use it
We use the information we collect to:
- Authenticate you and maintain your session
- Provision and manage your projects and plan limits
- Send transactional emails (e.g. new feedback notifications) via Resend
- Process billing and manage your subscription via Stripe
- Measure usage to improve the Service
We do not sell your data to third parties or use it for advertising.
3. Third-party services
We use the following third-party services to operate Upstep:
- GitHub / Google: OAuth authentication
- Stripe: payment processing and subscription management
- Resend: transactional email delivery
- Railway / Neon: cloud infrastructure and database hosting
- OnRamp: optional product analytics on the hosted Upstep service
Each service has its own privacy policy governing how they handle data.
4. Cookies & sessions
We use a secure, HTTP-only session cookie to keep you signed in (managed by Auth.js). We also set an optional upstep_currency cookie to remember your preferred currency on the pricing page. No tracking or advertising cookies are used.
5. Data retention
Your data is retained for as long as your account is active. If you delete a project, its feedback data is permanently removed immediately. If you close your account, all data is deleted within 30 days.
6. Your rights
You can delete your projects and their data at any time from the dashboard. To request full account deletion or a copy of your data, email us at hello@upstep.dev. We’ll respond within 30 days.
7. Security
We use HTTPS for all data in transit. Database access is restricted and credentials are never stored in client-facing code. Private MCP keys are stored as one-way hashes. Publishable SDK keys are stored in a retrievable form because project owners must embed them in client applications. No security measure is perfect, and we encourage you to report vulnerabilities responsibly.
8. Changes to this policy
We may update this Privacy Policy occasionally. Material changes will be communicated by email or via a notice in the dashboard. The effective date at the top of this page reflects the latest revision.
9. Contact
Questions or concerns about your privacy? Reach us at hello@upstep.dev.