Privacy Policy
Last updated: July 3, 2026
1. Overview
This Privacy Policy describes how WebUplink ("WebUplink", "we", "us") collects, uses, and protects information when you use our API service. WebUplink is the data controller for the information described below.
2. Information We Collect
Account Information
When you sign up, we collect your name, email address, and payment information (handled entirely by our payment processor — card numbers never touch WebUplink's systems). This is used for account management, billing, and support communication.
API Usage Data
We collect the following operational data for each API request:
- Timestamp and request ID
- API key prefix (first 8 characters, for logging)
- Target URL domain (not full URL)
- Action count and billing metrics
- Response status codes and latency
What We Do NOT Collect
- Page content — Browsed page content is not stored beyond the active session
- Credentials — Passwords, tokens, or other authentication data passed as tool parameters are not logged or stored
- Personal data from browsed sites — We do not extract or store PII from websites your agent visits
- Full API keys — Only the prefix is logged; the full key is hashed (SHA-256) for lookup
3. Browser Sessions
WebUplink runs browser sessions on managed browser infrastructure operated by a specialist provider (US). Each browser session:
- Expires after 2 minutes of inactivity or 15 minutes total
- Runs in an isolated browser context — no data shared between sessions
- Is fully destroyed on expiration — all cookies, local storage, and session state are deleted
4. Data Retention
- Account data: Retained while your account is active, deleted within 30 days of account closure
- Usage metrics: Aggregated billing data retained for 12 months for accounting purposes
- Request logs: Retained for 30 days for debugging and support, then deleted
- Browser sessions: No retention — destroyed on expiration
5. Service Providers (Subprocessors)
We use a small set of third-party service providers to deliver the Service, each bound by data-processing terms. By category:
- Cloud infrastructure & data hosting (US) — application hosting and encrypted storage of account and usage data
- Managed browser infrastructure (US) — runs the isolated, ephemeral browser sessions; session recording and session logs are disabled
- AI model provider (US)— page perception; inputs are not retained or used for model training per the provider's API terms
- Payment processor (US, PCI-DSS Level 1)— billing; card data never touches WebUplink's systems
- Authentication provider (US) — sign-in and session management
- Managed cache & rate-limiting service (US) — distributed rate limiting; processes no page content
- Error-monitoring service (US) — exception reports with sensitive fields redacted
- Product & web analytics services (US) — usage analytics with first-party cookies only (see Section 6)
- Transactional email service (US) — account and billing notifications
The named subprocessor list — each provider's identity, role, location, and data-transfer mechanism — is available to customers on request at privacy@webuplink.aiand is provided with every executed Data Processing Agreement. DPA customers receive 30 days' advance notice of any subprocessor addition or replacement, with the right to object.
6. Cookies & Analytics
We use essential, encrypted HttpOnly session cookies (SameSite=Lax, Secure) to keep you signed in — these are required for the dashboard to function. Our product-analytics service sets first-party cookies (ph_*) for visitor recognition and session continuity; it does not track you across other websites. Our web-analytics service sets standard first-party measurement cookies (_ga, _ga_*); we do not use advertising features. We do not use third-party advertising or cross-site tracking cookies.
7. Security
API keys are hashed with SHA-256 before storage. All API traffic is encrypted via TLS. Access to production infrastructure requires IAM-authenticated credentials.
8. Your Rights
You may:
- Request a copy of your account and usage data
- Request deletion of your account and associated data
- Revoke API keys at any time through the dashboard
9. Changes to This Policy
We will notify you of material changes via email. Continued use of the Service after changes constitutes acceptance.
10. Contact
For privacy inquiries, contact us at privacy@webuplink.ai.