Privacy Policy
Last updated 15 July 2026
This policy explains what personal data uptodate collects, why, and what rights you have under the EU General Data Protection Regulation (GDPR). uptodate is operated by an individual based in Germany, so German and EU data protection law applies.
1. Who is responsible
The controller responsible for your data is:
Meduard Krasniqi
Berlin, Germany (postal address in the Impressum)
Email: meduard.krasniqi@kozmos.tech
2. What data I collect and why
Account data
When you sign up I process your name, email address, and either a hashed password or, if you use Google sign-in, the basic profile information Google returns (name, email, account identifier). This is used to create and secure your account and to contact you about the service. Legal basis: performance of the contract with you (Art. 6(1)(b) GDPR).
Repository and documentation content
When you connect a repository, uptodate reads the code changes you merge and the documentation files in the folder you point it at. This content is processed to identify affected documentation and to draft edits, and relevant excerpts are sent to the AI provider named below. Documentation edits are written back to your repository only as a pull request. Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
Usage and analytics data
I collect product analytics such as pages visited, actions taken (for example signing up, connecting a project, or when a pull request is opened), and device and browser information. Analytics run in a cookieless mode that sets no cookies and stores nothing on your device. Visitors are counted using a temporary identifier derived on the server from technical signals, which is not used to track you across sites and is not stored in your browser. This helps me understand how the service is used and improve it. Legal basis: my legitimate interest in operating and improving the service (Art. 6(1)(f) GDPR). You can object to analytics at any time, see section 7.
3. How AI processing works
To draft documentation edits, code changes and documentation excerpts are sent to Anthropic, the provider of the Claude models, through its commercial API. Under Anthropic’s commercial terms, this data is not used to train its models and is retained only briefly for abuse monitoring before deletion. Your content is used only to generate the edits you requested.
4. Who I share data with
I do not sell your data. I share it only with service providers who process it on my behalf to run uptodate, under data processing agreements. These are:
- GitHub (Microsoft) — the repository, code changes, and pull requests the service operates on.
- Anthropic — AI processing that drafts documentation edits.
- Vercel — hosting of the application.
- Neon — the database that stores your account and project data.
- Google — sign-in, if you choose Google to authenticate.
- PostHog — product analytics.
- yourtraffic — website traffic analytics.
5. International transfers
Some of these providers are based in the United States or process data there. Where data leaves the European Economic Area, the transfer is protected by appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses or an equivalent mechanism such as the EU-US Data Privacy Framework where the provider is certified.
6. How long I keep data
I keep your account and project data for as long as your account is active. When you delete your account or ask me to, I delete or anonymize your personal data within a reasonable period, unless I am legally required to keep it for longer. Repository content is processed to produce edits and is not retained beyond what is needed to run an analysis and keep a record of the proposals shown in your dashboard. Analytics data is retained on an aggregated or pseudonymized basis.
7. Your rights
Under the GDPR you have the right to:
- access the personal data I hold about you;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to certain processing, including analytics;
- receive your data in a portable format;
- withdraw consent at any time, without affecting processing that already happened.
To exercise any of these, email meduard.krasniqi@kozmos.tech. You also have the right to complain to a supervisory authority. For Berlin this is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
8. Cookies and similar technologies
uptodate uses a cookie to keep you signed in, which is necessary for the service to work. This is the only cookie the service sets. My product analytics run in a cookieless mode, so they do not set cookies or store data on your device. You can block or delete the sign-in cookie in your browser, though doing so will sign you out.
9. Security
I take reasonable technical and organizational measures to protect your data, including encryption in transit, hashed passwords, scoped access tokens for GitHub, and access controls. No system is completely secure, so I cannot guarantee absolute security.
10. Children
uptodate is not intended for anyone under 18, and I do not knowingly collect data from children.
11. Changes to this policy
I may update this policy as the service develops. If a change is material I will give you reasonable notice. The date at the top shows when it was last updated.