Introduction
When you use URIQA, you may trust us with project information, uploaded files, research materials, technical records, and personal information. This Privacy Policy is intended to help you understand what information Tupal LLC, doing business as URIQA, collects, why we process it, when it may be shared, and how you can manage, export, or delete it.
This Policy applies to uriqa.ai, URIQA accounts, Research and Professional workspaces, AI features, subscriptions, and related communications. It does not apply to third-party websites or services governed by their own privacy policies.
Information we collect
Information you provide
When you create an account, we may collect your name, email address, authentication information, organization or affiliation, selected workspace type, plan, and account preferences.
When you use URIQA, you may provide files, PDFs, images, charts, spreadsheets, datasets, project descriptions, notes, findings, plans, prompts, messages, drafts, reports, report-branding assets, and related information. The content you choose to submit may itself contain personal or sensitive information. URIQA does not control the information contained in your files, so you are responsible for ensuring that you are authorized to submit it.
Information URIQA creates from your content
URIQA may create extracted text, document summaries, tags, embeddings, table descriptions, figure descriptions, possible findings, relationships, drafts, classifications, and other derived information needed to provide AI-assisted features. URIQA may also retain conversations, model information, evaluations, ratings, and user feedback about AI output.
Information generated when you use the Service
We may collect technical and usage information such as your IP address, browser, device type, operating system, timestamps, referring page, authentication events, project counts, storage use, file operations, AI actions, model routes, errors, audit events, and approximate location inferred from an IP address. This information helps URIQA operate, secure, troubleshoot, and understand the Service.
Payment information
Payments may be processed by Stripe or another payment processor. URIQA may receive your billing identifier, plan, transaction amount, payment status, payment-method brand, and the last four digits of a payment method. URIQA generally does not receive or store a complete payment-card number.
Communications
We collect information you send when you contact support, request access, submit feedback, make a privacy request, report a security concern, or send a legal notice.
Cookies and local storage
URIQA uses cookies and browser storage only for essential purposes: authentication, session continuity, security, saved preferences, and core application functionality. We do not currently deploy third-party analytics, advertising, or session-replay trackers on the marketing site.
Why we process information
Providing URIQA
We process information to create and manage accounts, provide workspaces, store and retrieve files, analyze project information, generate AI output, create exports, process subscriptions, and deliver the features you request.
Maintaining and improving the Service
We use usage data, errors, feedback, model evaluations, and limited project context where appropriate to troubleshoot URIQA and improve its workflows, prompts, safety, usability, and performance. We do not use private project content for unrelated advertising, and we do not train foundation models on private User Content.
Security and legal obligations
We process information to authenticate users, enforce limits, detect abuse, investigate incidents, prevent fraud, protect URIQA and its users, comply with law, preserve records, and enforce agreements.
Communicating with you
We may use your contact information for account verification, transaction notices, billing information, material policy changes, security alerts, trial or subscription notices, and other Service-related messages.
How AI processing works
When you request an AI feature, URIQA may send relevant prompts, files, extracted text, images, spreadsheet data, project context, notes, findings, or drafts to an AI model provider.
URIQA currently relies on Lovable Cloud and the Lovable AI Gateway. Models may be supplied by Google, OpenAI, or other providers, depending on the feature, selected model route, availability, and configuration. The model used for a particular request may change as URIQA evaluates quality, cost, safety, and performance.
Do not assume that AI processing is confidential, privileged, zero-retention, limited to a particular country, or covered by a specialized regulated-data agreement unless URIQA confirms that protection in a separate written contract. URIQA does not sell project content to AI providers. Third-party providers process content in accordance with the arrangements and technical configuration applicable to their services.
When information is disclosed
Service providers
We disclose information to providers that perform services for URIQA. These providers may support hosting, storage, authentication, AI processing, document extraction, payments, email, monitoring, security, analytics, and customer communications. We provide information to these providers only as reasonably necessary for the applicable service, subject to their contractual terms and applicable law.
Organization administrators and sharing
If you use a workspace controlled by an organization, the organization's authorized administrators may be able to manage the workspace, users, permissions, and content according to the features offered. If you choose to share a project, report, export, or link, the people you authorize may access the information you share.
Legal and safety reasons
We may disclose information when we reasonably believe disclosure is necessary to comply with law, respond to valid legal process, protect rights or safety, investigate fraud or security incidents, enforce agreements, or respond to an emergency.
Business transactions
Information may be transferred as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of Tupal LLC. Any successor would remain subject to applicable law and the commitments governing the transferred information.
With your direction
We may disclose information when you direct us to do so or provide consent, such as when you request an integration, export, collaboration feature, or third-party connection.
Sale and targeted advertising
URIQA does not sell personal information. URIQA does not share personal information for cross-context behavioral advertising.
Your privacy controls
URIQA may provide account controls that allow you to:
- update profile information;
- delete projects or files;
- purge AI conversations;
- remove extracted text;
- export workspace information;
- request account deletion.
You may also send a privacy request to support@uriqa.ai with the subject "Privacy Request." Describe the request and identify the email associated with the account. Do not send passwords, private keys, complete payment details, or unnecessary sensitive project content.
We may verify your identity before completing a request. Verification helps prevent another person from accessing, changing, or deleting your information.
Depending on applicable law and the nature of your request, you may have the right to access, correct, delete, or receive a portable copy of personal information. You may also have the right to object to or limit certain uses or disclosures. We will not unlawfully discriminate against you for exercising an applicable privacy right.
Some information may be retained after a request where necessary for security, fraud prevention, billing, consent records, legal compliance, dispute resolution, or the exercise and defense of legal claims.
How long we retain information
We retain information for as long as reasonably necessary to provide URIQA, maintain accounts, complete transactions, comply with law, secure the Service, resolve disputes, and enforce agreements. Retention varies according to the type of information and the reason it is needed.
Account and User Content may generally remain while an account or workspace is active. Billing, consent, security, and audit records may remain longer where needed for legal or operational reasons. Deleted content may remain temporarily in backups or disaster-recovery systems. We do not guarantee instantaneous deletion from every backup.
Where available, retention settings may allow users to purge AI history or extracted text or select an automatic deletion period. Those settings do not necessarily remove minimal billing, security, audit, consent, or legal records.
How we protect information
URIQA uses technical, administrative, and organizational measures intended to reduce the risk of unauthorized access, loss, misuse, or alteration. Current measures may include authenticated accounts, private storage, row-level database policies, temporary signed file links, server-side secret handling, rate limits, audit records, and encrypted network connections supplied by infrastructure providers.
No internet or cloud system is completely secure. URIQA cannot guarantee that information will never be lost, accessed, disclosed, or altered without authorization. You can help protect information by using a unique password, enabling available multifactor authentication, securing your email account, reviewing workspace permissions, maintaining independent backups, and avoiding the submission of unnecessary sensitive information.
California privacy information
California privacy laws may provide residents with rights regarding the personal information collected by covered businesses. Depending on which laws apply to URIQA at a particular time, California residents may have rights to learn about collected information, request specific information, correct inaccurate information, request deletion, receive portable information, limit certain uses of sensitive information, opt out of sale or sharing, and avoid unlawful discrimination for exercising those rights.
URIQA does not currently sell personal information or share personal information for cross-context behavioral advertising. California residents may submit requests to support@uriqa.ai using the subject "California Privacy Request." Include the account email and a description of the request. We may require reasonable verification and may request proof of authority from an authorized agent.
If URIQA is subject to a statutory response deadline, it will respond within the period required by applicable law. No broader response-time commitment is made.
California's Shine the Light law permits certain residents to request information about disclosures made to third parties for their own direct marketing. URIQA does not currently make such disclosures. Questions may be sent to support@uriqa.ai with the subject "California Privacy Rights."
Global Privacy Control and Do Not Track
Browsers may send Do Not Track or Global Privacy Control signals. Because URIQA does not currently sell personal information or share it for cross-context behavioral advertising, those signals do not presently change URIQA's practices. If URIQA's practices or legal obligations change, it will honor legally required signals and update this Policy.
International use
URIQA is operated from the United States. Information may be processed in the United States and in other locations where our providers operate. Those locations may have privacy laws different from the laws where you live. By using URIQA, you understand that information may be processed in those locations, subject to applicable law.
URIQA does not currently promise European Union data residency, regional isolation, or a specific international transfer framework unless agreed in a separate written contract.
Children
URIQA is intended for people aged 18 or older. We do not knowingly collect personal information from children. If you believe that a minor has created an account or submitted personal information, contact support@uriqa.ai.
Changes to this Policy
We may update this Policy as URIQA, its providers, or applicable laws change. The revised Policy will show an updated date and version. When a change is material, we may provide notice by email, in-product message, renewed acknowledgment, or another appropriate method.
Contact
Privacy questions and requests may be sent to Tupal LLC, doing business as URIQA, at support@uriqa.ai. Use the subject "Privacy Request" or "California Privacy Request," as applicable.
Sending a request does not create a service-level or general response-time commitment. URIQA will comply with response periods that apply under applicable law.

