Privacy Policy
Last updated: 7 October 2026
OD "ALITAR" (Sarajevo, Bosnia and Herzegovina) is the controller of the personal data described here. Contact: dzano.catovic@gmail.com.
1. What we collect
- Account details: name, email address and the sign-in method (Google or email and password).
- Your content: the documents you upload, the text extracted from them (including text recognised from scans), your questions and the answers, and your thumbs up/down feedback.
- Usage counters (documents, storage, pages, questions) used to apply plan limits.
- Billing state: your plan and subscription status. Card details go to Paddle and never reach us.
- Product analytics: a few one-time milestones per account (sign-up, first upload, first question, upgrade), the days on which you use UpAsk, and your approximate country (looked up from your IP address with an offline database; the IP address itself is not kept for this), linked to your account ID and stored in our own database. No advertising trackers or analytics cookies are used.
- Messages you send through the feedback form or by email.
- Technical logs (request IDs, errors) and error reports needed to keep the service running.
- Account and safety records: which version of the Terms you accepted and when, your preferred language (for the emails we send you), whether your account is blocked, and a record of the actions we take on it.
2. How we use it
To provide the service: your documents are split into text passages, converted into embeddings for search, and the passages relevant to a question are sent to an AI model to write the answer. We also use data to apply plan limits, handle billing, prevent abuse, fix errors and answer support requests. We do not sell personal data and we do not use your documents to train our own models.
3. Isolation, storage and retention
Each workspace is private to its members; the service is built so that one customer's data is never used to answer another's questions. Files are kept in object storage and text and embeddings in our database until you delete them. Traffic between your browser and the service uses HTTPS.
- Deleting a document removes the file, its text and its search data.
- Deleting a workspace removes everything in it, including chats.
- Deleting your account removes your workspaces, chats, usage records and profile, and your sign-in account.
- Backups, if any, and payment records that we must keep by law may persist for a limited time afterwards.
You can export a workspace as a ZIP from its settings at any time.
Guests
You can try the service as a guest without an email address. A guest is an anonymous account with the Free plan limits but only 2 documents and 2 questions in total. Guest documents, chats and usage records are deleted automatically after 7 days without activity. If you create an account, your guest data moves to it. To limit abuse we store a keyed hash of your IP address when a guest account is created (see Preventing misuse below); the raw address is not stored.
On our Android app, guest accounts are also capped per device. We store a one-way hash of a device identifier for up to 30 days, used only to limit how many free trial accounts one device can start (fraud prevention). It is not used for advertising and is not shared with third parties.
Preventing misuse
To keep the service safe and the free plan fair (our legitimate interest, see section 4 of the Terms of Service), we:
- Ask Cloudflare Turnstile to check that a person, not a bot, is signing up or starting a guest session. Cloudflare receives your IP address and browser signals for this check.
- Store a keyed hash of the IP address an account or guest session is created from (never the raw address), to limit how many accounts one network can create per day and to block a network used for misuse. It is kept as long as the account exists; a network block is kept until we remove it.
- On our Android app, check with Google Play Integrity (through Firebase App Check) that requests come from the genuine app.
- Review automatic alerts about unusual activity, such as many accounts from one network or very high usage; an alert may include the email address of the accounts involved.
If we block an account under the Terms, we keep its data and a record of the decision (the rule broken and our reason) so we can handle an appeal, and we email the account holder. You can still ask us to delete the account and its data: write to dzano.catovic@gmail.com.
4. Sub-processors
We use these sub-processors to run UpAsk:
- Google (Gemini API): your document text and questions are sent to Google's Gemini API to create embeddings, recognise text in scans and generate answers. Google's own terms for the API apply to that processing.
- Google (Firebase Authentication and App Check): sign-in and account identity; on Android, a check that requests come from the genuine app (Play Integrity).
- Hosting and storage provider: runs the application, database and file storage.
- Sentry: error monitoring; reports may include technical details such as URLs and error messages.
- Paddle: payments, invoicing and taxes as merchant of record.
- Cloudflare (Turnstile and Web Analytics): the human check when you sign up or start a guest session, and cookieless, aggregated page-visit statistics (pages viewed, referring site, country, device type).
- Resend: sends our emails, such as workspace invites and account notices.
These providers may process data in countries outside your own.
5. Cookies
We only use essential cookies (your login session and language preference). See the Cookie Policy.
6. Your rights
Depending on where you live you may have the right to access, correct, export or delete your data, to object to or restrict processing, and to complain to your data-protection authority. Most of this you can do yourself in the app (export, delete); for anything else write to dzano.catovic@gmail.com.
7. Changes
We will update this page when our practices change and change the date above.
