Ultraform – Privacy Policy

Who we are: (“Ultraform”, “we”, “us”, or “our”)

Ultraform lets users design, configure, and publish Large Language Model (“LLM”) agents. Other users can subscribe to published agents’ outputs or run those agents using their own input data. This Privacy Policy explains what we collect, how we use and share it, and the choices you have. This Policy applies to your use of Ultraform websites, apps, APIs, and related services (collectively, the “Services”).

1) Information We Collect

A. Account & Identity Data

  • Name, email address, password (hashed), profile details, workspace or organization affiliation, role/permissions.
  • Authentication and security data (e.g., session tokens, multi-factor indicators).

B. Agent & Project Data

  • Agent definitions and configurations (e.g., system prompts, step prompts, variables, tools/connectors, schedules, DAGs).
  • Agent versions, titles, descriptions, tags, and publication status (private, unlisted, public).
  • Gallery/Directory metadata if you publish agents.

C. Run & Content Data

  • Inputs you or your subscribers provide to agents (text, files, URLs, structured fields).
  • Outputs generated by agents, run results, intermediate artifacts if enabled, and run-time logs (timestamps, status, cost/usage).
  • Settings about privacy/visibility of runs (e.g., whether outputs are visible to subscribers only, owners only, or publicly).

We do not collect or store sensitive input content unless you choose to provide it to an agent or explicitly save it. You control whether to save, publish, or share outputs.

D. Usage, Device & Technical Data

  • App interactions, feature usage, crash reports, diagnostics.
  • IP address, device/browser info, language, timezone, cookies and similar technologies.

E. Payment & Billing Data

  • Processed by our payment processor (e.g., Stripe). We receive limited billing metadata; we do not store full card numbers.

F. Communications

  • Support messages, feedback forms, and notification preferences.

2) How We Use Your Information

  • Provide and improve the Services: account management, agent creation/publishing, runs, delivering results, Gallery/Directory, subscriptions, usage/costs.
  • Personalize and optimize: UI, recommendations, performance measurement, quality improvements.
  • Security and integrity: authentication, fraud/abuse prevention, acceptable use and license enforcement.
  • Communicate with you: service updates, billing notices, feature announcements, support responses.
  • Compliance and legal: satisfy legal obligations, resolve disputes, enforce agreements.

We will not use your personal data for unrelated purposes without your consent, unless required by law.

3) When We Share Information

With other users, according to your settings

  • If you publish an agent (public/unlisted), its metadata (e.g., name, description, author) is visible in the Gallery/Directory.
  • Subscribers to your agent may receive outputs you choose to expose to them (e.g., scheduled reports, run results).
  • If you run another user’s agent, the agent owner may see aggregated usage stats and, depending on configuration, selected run metadata or outputs you consent to share.

With model and infrastructure providers

To execute runs, inputs/outputs may be sent to AI/LLM providers and cloud infrastructure. Where supported, we disable provider-side training on customer content or offer opt-out controls. Provider terms may apply to content processed through them.

With service providers (processors)

Hosting, analytics, logging, error monitoring, email delivery, in-app messaging, customer support, payment processing, and similar vendors under contract.

For legal reasons

To comply with law or valid legal process; to protect rights, privacy, safety, or property; to detect or prevent fraud, security, or technical issues.

Business transfers

In a merger, acquisition, financing, or asset sale, data may be transferred consistent with this Policy.

We do not sell your personal information.

4) Your Choices & Controls

  • Agent visibility & sharing: private, unlisted, or public; control outputs shared with subscribers and what run metadata owners can see.
  • Content saving: decide what to save, publish, or delete (agent versions, outputs, prompt history).
  • Model provider settings: where available, opt out of provider data retention or training on your content.
  • Communications: manage email preferences; essential service emails may still be sent.
  • Access, correction, deletion: update your profile and settings; request account/data deletion (subject to legal/operational retention).
  • Export: request export of your data in a commonly used format, where required by law.

Contact us at info@ultraform.com for data rights requests.

5) Data Retention

We retain data only as long as necessary to provide the Services, comply with legal obligations, resolve disputes, maintain security, and enforce agreements.

  • Account/workspace records: for your active subscription and a reasonable period afterward.
  • Agent definitions/versions and published metadata: while your account is active or until you remove them.
  • Run data and logs: for troubleshooting, cost reconciliation, and audit; retention windows may be configurable or set by request.
  • Billing/transactional records: per tax/accounting requirements.

When retention ends, we delete or anonymize data.

6) Security

  • Encryption in transit and at rest (where applicable).
  • Role-based access controls and least-privilege practices.
  • Network segmentation, monitoring, and audit logging.
  • Vendor due diligence and data processing agreements.

No method of transmission or storage is 100% secure; we continuously improve our safeguards.

7) International Data Transfers

We may process and store data in countries other than where you live. Where required, we use lawful transfer mechanisms (e.g., Standard Contractual Clauses) and implement additional safeguards.

8) Cookies & Similar Technologies

We use cookies, local storage, and similar technologies for authentication, preferences, analytics, and performance. You can control cookies via your browser settings; some features may not function without them.

9) Children’s Privacy

The Services are not directed to children under the age of 13 (or 16 where applicable). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us to request deletion.

11) Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated via the Services or email. Your continued use after the effective date means you accept the updated Policy.

Model Provider Notice (Transparency Addendum)

To run agents, Ultraform may transmit your inputs, agent instructions/prompts, and resulting outputs to selected AI/LLM providers and infrastructure vendors strictly to perform the requested processing. Where the provider supports it, we set controls to prevent training on your content by default. Some providers may retain logs for abuse detection or legal compliance; review the provider’s privacy policy for details. You can review or change an agent’s provider and data-handling preferences in settings before running or publishing.