Privacy Policy
Last updated: January 7, 2026
This Privacy Policy describes Our policies and procedures on the collection, use, and disclosure of Your information when You use the Service and tells You about Your privacy rights and how the law protects You.
We use Your Personal Data to provide and improve the Service. By using the Service, You acknowledge that We will process Your Personal Data as described in this Privacy Policy.
Interpretation and Definitions
Interpretation
The words whose initial letters are capitalized have meanings defined under the following conditions. The following definitions shall have the same meaning regardless of whether they appear in singular or in plural.
Definitions
For the purposes of this Privacy Policy:
- Account means a unique account created for You to access our Service or parts of our Service.
- Affiliate means an entity that controls, is controlled by, or is under common control with a party, where "control" means ownership of 50% or more of the shares, equity interest or other securities entitled to vote for election of directors or other managing authority.
- Analysis means the AI-generated output produced when You submit a chart image to the Service, including directional assessments, confidence scores, and reasoning from multiple AI models.
- Company (referred to as either "the Company", "We", "Us" or "Our" in this Agreement) refers to the operator of upordown.ai.
- Cookies are small files that are placed on Your computer, mobile device or any other device by a website, containing the details of Your browsing history on that website among its many uses.
- Country refers to Germany.
- Credit means a unit of service entitling You to one chart Analysis.
- Device means any device that can access the Service such as a computer, a cell phone, or a digital tablet.
- Personal Data is any information that relates to an identified or identifiable individual.
- Service refers to the AI-powered chart analysis platform provided through the Website, which uses multiple artificial intelligence models to analyze user-uploaded chart images.
- Service Provider means any natural or legal person who processes the data on behalf of the Company. It refers to third-party companies or individuals employed by the Company to facilitate the Service, to provide the Service on behalf of the Company, to perform services related to the Service, or to assist the Company in analyzing how the Service is used.
- Usage Data refers to data collected automatically, either generated by the use of the Service or from the Service infrastructure itself (for example, the duration of a page visit).
- Website refers to upordown.ai, accessible from https://upordown.ai.
- You means the individual accessing or using the Service, or the company, or other legal entity on behalf of which such individual is accessing or using the Service, as applicable.
Collecting and Using Your Personal Data
We collect Personal Data directly from You, from Your use of the Service, and from our payment provider in connection with purchases.
Types of Data Collected
Account Data
When You create an Account, We collect Your email address and basic profile information through our authentication provider. This data is used to identify You and provide access to the Service.
Payment Data
When You purchase Credits, our payment processor collects payment information including Your email address, billing details, and transaction history. We do not store Your full payment card details on our servers.
Chart Images
When You use the Service, You upload chart images for analysis. These images are processed by third-party AI models to generate Analyses. We store these images to deliver the Service and maintain Your analysis history.
Please avoid uploading images that contain unnecessary personal data (e.g., Your name, account numbers, broker IDs, or other identifying information visible in the screenshot).
Analysis Data
We store the AI-generated Analyses associated with Your Account, including directional assessments, confidence scores, and reasoning provided by each AI model.
Usage Data
Usage Data is collected automatically when using the Service. Usage Data may include information such as Your Device's Internet Protocol address (e.g., IP address), browser type, browser version, the pages of our Service that You visit, the time and date of Your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.
Tracking Technologies and Cookies
We use Cookies and similar tracking technologies to track activity on Our Service and store certain information. The technologies We use may include:
- Essential Cookies: These Cookies are necessary for the Website to function and cannot be switched off. They are usually only set in response to actions made by You, such as logging in or filling in forms.
- Authentication Cookies: These Cookies help us identify You when You are logged in and maintain Your session.
- Preference Cookies: These Cookies allow us to remember choices You make, such as Your theme preference (light/dark mode).
You can instruct Your browser to refuse all Cookies or to indicate when a Cookie is being sent. However, if You do not accept Cookies, You may not be able to use some parts of our Service.
Third-Party Service Providers
We act as the controller for Personal Data processed in connection with the Service. Our vendors act as processors where they process data on our behalf. Some vendors (e.g., payment providers) may act as independent controllers for data they process for their own compliance purposes. We have not appointed a Data Protection Officer (DPO).
We use the following third-party Service Providers to operate and improve the Service. Each provider has access to certain data as necessary to perform their functions:
- Clerk - Authentication and user management. Processes Your email address and profile information. Privacy Policy
- Paddle - Payment processing. Processes Your payment information and billing details.Privacy Policy
- OpenRouter - AI model routing. Processes Your uploaded chart images to generate Analyses.Privacy Policy
- Langfuse - Server-side analytics and tracing. Processes usage data and analysis metadata to help us improve the Service. Does not set cookies in Your browser. Privacy Policy
- Umami - Privacy-focused website analytics. May be used to collect anonymous usage statistics such as page views and visitor counts. When enabled, Umami is configured to be cookie-less and does not track individual users across sites. Privacy Policy
We share Personal Data with service providers for authentication, payment processing, AI processing, analytics/logging, and customer support as described above.
Use of Your Personal Data
The Company may use Personal Data for the following purposes:
- To provide and maintain our Service, including to monitor the usage of our Service and deliver Analyses based on Your uploaded chart images.
- To manage Your Account, including Your registration, Credits balance, and analysis history.
- To process transactions, including Credit purchases and refunds.
- To contact You by email for service-related communications, including:
- Account notifications (registration confirmation, password resets)
- Purchase confirmations and Credit balance updates
- Security alerts and important service announcements
- Responses to Your support inquiries
- To improve the Service through data analysis, identifying usage trends, and evaluating the effectiveness of our AI models.
- For business transfers, in connection with any merger, sale of Company assets, or acquisition.
Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), We rely on the following legal bases for processing Your Personal Data:
- Contract (Art. 6(1)(b)): Processing necessary for account creation, providing Analyses, storing Your analysis history, processing Credit purchases, and responding to support requests.
- Legal Obligation (Art. 6(1)(c)): Processing necessary to comply with tax and accounting requirements (e.g., payment records).
- Legitimate Interests (Art. 6(1)(f)): Processing for security logging, abuse prevention, service improvement, and anonymous analytics. Our legitimate interests do not override Your fundamental rights and freedoms.
- Consent (Art. 6(1)(a)): Where applicable, for marketing emails (opt-in only) and any non-essential cookies or analytics that require consent.
Data Retention
The Company will retain Your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy:
- Account Data: Retained for the lifetime of Your Account and deleted upon Account deletion.
- Chart Images: Retained until Account deletion, unless You request earlier deletion.
- Analysis Data: Retained until Account deletion, unless You request earlier deletion.
- Payment Records: Retained as required by applicable tax and accounting laws (typically 7-10 years).
- Usage Data: Aggregated and anonymized after 90 days; raw logs deleted after 30 days.
Transfer of Your Personal Data
Your information, including Personal Data, may be transferred to and maintained on computers located outside of Your jurisdiction where data protection laws may differ. In particular, our Service Providers may process data in the United States and other countries outside the European Economic Area (EEA).
For transfers of Personal Data from the EEA to countries not recognized as providing an adequate level of data protection, We rely on Standard Contractual Clauses (SCCs) approved by the European Commission, along with supplementary measures where appropriate, to ensure Your data is protected. You may request a copy of the applicable safeguards by contacting Us at support@upordown.ai.
Your Rights Under GDPR
If You are a resident of the European Economic Area (EEA), You have certain data protection rights under the General Data Protection Regulation (GDPR):
- Right to Access: You have the right to request copies of Your Personal Data.
- Right to Rectification: You have the right to request that We correct any information You believe is inaccurate or complete information You believe is incomplete.
- Right to Erasure: You have the right to request that We erase Your Personal Data, under certain conditions.
- Right to Restrict Processing: You have the right to request that We restrict the processing of Your Personal Data, under certain conditions.
- Right to Data Portability: You have the right to request that We transfer the data We have collected to another organization, or directly to You, under certain conditions.
- Right to Object: You have the right to object to Our processing of Your Personal Data, under certain conditions.
- Right to Withdraw Consent: Where We rely on Your consent to process Your Personal Data, You have the right to withdraw that consent at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority, in particular in Your place of residence, place of work, or where an alleged infringement occurred.
To exercise any of these rights, please contact Us at support@upordown.ai. We will respond to Your request within 30 days.
Automated Decision-Making
We do not use automated decision-making, including profiling, that produces legal or similarly significant effects concerning You. While our Service uses AI models to generate Analyses, these outputs are for informational purposes only and do not constitute automated decisions affecting Your legal rights.
Delete Your Personal Data
You have the right to delete or request that We assist in deleting the Personal Data that We have collected about You.
You may delete Your Account and associated data by contacting Us. Please note that We may need to retain certain information when we have a legal obligation or lawful basis to do so (such as payment records for tax purposes).
Disclosure of Your Personal Data
Business Transactions
If the Company is involved in a merger, acquisition, or asset sale, Your Personal Data may be transferred. We will provide notice before Your Personal Data is transferred and becomes subject to a different Privacy Policy.
Law Enforcement
Under certain circumstances, the Company may be required to disclose Your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency).
Other Legal Requirements
The Company may disclose Your Personal Data in the good faith belief that such action is necessary to:
- Comply with a legal obligation
- Protect and defend the rights or property of the Company
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of Users of the Service or the public
- Protect against legal liability
Security of Your Personal Data
The security of Your Personal Data is important to Us. We implement industry-standard technical and organizational measures to protect Your data, including encryption in transit (HTTPS). Access to Personal Data is restricted to authorized personnel and service providers on a need-to-know basis. However, no method of transmission over the Internet or method of electronic storage is 100% secure, and We cannot guarantee absolute security.
Children's Privacy
Our Service is not intended for anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under 18. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under 18 without verification of parental consent, We take steps to remove that information from Our servers.
Links to Other Websites
Our Service may contain links to other websites that are not operated by Us. If You click on a third-party link, You will be directed to that third party's site. We strongly advise You to review the Privacy Policy of every site You visit.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Changes to this Privacy Policy
We may update Our Privacy Policy from time to time. We will notify You of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date at the top.
For material changes, We will notify You via email and/or a prominent notice on Our Service prior to the change becoming effective.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise Your data protection rights, You can contact us:
By email: support@upordown.ai
For information about our terms of use, please see our Terms of Service.