Mesperlon LLC

Privacy Policy

Effective and last updated: July 28, 2026

The short version

Uplift keeps customer documents, prompts, search indexes, and AI outputs on the customer-hosted server. Mesperlon does not sell personal information or use advertising trackers. We do receive the limited account, payment, licensing, security, and delivery data needed to operate the service. Optional diagnostics are off by default.

1. Scope and product boundary

This policy covers mesperlon.com, Mesperlon accounts, the Uplift customer-hosted server, and Uplift client applications. Customer documents and the content submitted to Uplift are processed inside the customer-controlled environment. They are not intentionally transmitted to Mesperlon by the normal search, upload, or AI-processing workflow.

2. Information required to provide Uplift

Some information cannot be avoided while providing accounts, paid subscriptions, licensed downloads, and protection against abuse. Mesperlon processes:

  • Account data: name, email address, password hash, account identifiers, verification status, and account dates.
  • Billing data: plan, amount, currency, subscription and transaction identifiers, payment status, renewal and cancellation dates, and billing contact information. Stripe processes payment-card details; Mesperlon does not store complete card numbers.
  • License data: license key, subscription status, expiration date, and a hashed installation identifier used to bind a license to an authorized server.
  • Operational request data: software version, operating-system/platform description, request timestamp, and the IP address ordinarily visible to hosting and network providers.
  • Security records: failed authentication or license-validation reason, IP address, hashed installation identifier, and timestamp. Application-level failed-license records are retained for up to seven days.
  • Communications: messages sent to Mesperlon and transactional email delivery information needed to verify accounts, deliver licenses, and provide receipts or support.

Without this required operational data, Mesperlon could not create accounts, collect payment, deliver licenses, validate an active subscription, provide updates, prevent abuse, or investigate security incidents.

3. Optional diagnostics

Uplift diagnostics are off by default. An administrator may enable them in Uplift settings. When enabled, Uplift may send a daily health event, slow-request timing and endpoint name, file size, result limit, software/platform version, and a limited crash category and context. Mesperlon does not intentionally request document contents, prompts, AI outputs, filenames, file paths, or uploaded files in diagnostics. Diagnostic identifiers are pseudonymized before storage, diagnostic records are encrypted at rest, and they are retained for up to 90 days with a maximum of 500 recent events.

Diagnostic systems cannot guarantee that every unexpected error will be free of sensitive information. Customers should avoid putting secrets in filenames, metadata, or configuration values, and should leave diagnostics disabled when their policies prohibit external operational reporting.

4. Service providers and disclosures

Mesperlon does not sell or rent customer data. Limited information is disclosed to service providers acting on Mesperlon's behalf:

  • Vercel: website hosting, application execution, and release-file delivery.
  • Upstash/Redis: account, license, payment-state, security, rate-limit, and optional diagnostic storage.
  • Stripe: checkout, payment processing, subscriptions, refunds, fraud prevention, and legally required payment records.
  • Resend: account verification, receipts, license delivery, and other transactional email.
  • GitHub: build/release automation and release artifacts used to produce software downloads.

Information may also be disclosed when required by law, to protect customers or Mesperlon from fraud or security threats, or as part of a business transaction subject to appropriate confidentiality and legal safeguards.

5. Cookies and website logs

Mesperlon uses first-party, essential session cookies for account and administrative authentication. It does not use advertising cookies or cross-site behavioral tracking. Hosting, security, and network providers may necessarily process standard request information such as IP address, user agent, requested URL, timestamp, and response status to deliver and protect the website.

6. Retention and deletion

Mesperlon retains account and license records while an account or license is active and for a reasonable period afterward for support, security, dispute, and legal purposes. Payment and tax records may be kept for the period required by financial and tax law. Failed-license security records are retained for up to seven days, and optional diagnostics for up to 90 days. Backups and provider logs may persist for a limited period after deletion. Customer-hosted Uplift content is controlled and deleted by the customer.

7. Customer choices and requests

Customers can leave diagnostics disabled, change account information, cancel subscriptions, and delete eligible account information. Requests to access, correct, export, or delete personal information may be sent to legal@mesperlon.com. Mesperlon may verify the requester's identity and may retain information when required for billing, tax, fraud prevention, security, legal claims, or other legal obligations.

8. Security and policy changes

Mesperlon uses access controls, encrypted transport, password hashing, limited administrative access, and encryption for sensitive application records. No system can promise absolute security. Material policy changes will receive a new effective date and, when appropriate, notice through the website, account, or email. This page's date changes only when the policy changes.

Contact

Privacy questions and requests: legal@mesperlon.com. Security reports: security@mesperlon.com.