What we collect#
Account details, the record of each file (never its contents), usage logs, and billing handled by Stripe.
- Email address and name for your account
- File records: IDs, metadata, storage location and events — not the bytes
- API and usage logs for debugging, rate limiting and abuse prevention
- Payment details processed by Stripe and never stored by us
Account information
When you sign up we collect your email address (to identify the account and send important notices), your name (to address you) and a password, stored as a bcrypt hash we cannot reverse. If you sign in through a provider such as GitHub or Google we receive the identifier and email they share.
File records
For every file that passes through the API we keep a record: a stable file ID, the name, size and type you gave it, the storage target your policy chose, the bucket and key where the object landed, and an append-only log of events (uploaded, served, moved, deleted).
We do not keep the file's contents. Upload bodies stream through to the bucket you connected and are not retained once the write is confirmed. Reads are served from your storage with signed URLs and do not pass through Uplint.
Usage data
- Pages you visit in the dashboard and features you use
- API request logs — endpoint, status, timing, request ID, API key ID and the calling IP address
- Error logs when something goes wrong
- Browser and device type, so we can keep the dashboard working where you use it
Payment information
Payments are processed entirely by Stripe. We receive confirmation of payment and the billing details needed for an invoice; we never see or store card numbers.
Storage credentials
When you connect a bucket you give us a scoped credential for it. It is encrypted at rest, used only to act on your instructions, and can be rotated or revoked by you at any time — revocation ends our access immediately.