UpfynUpfyn
  • Events
  • Pricing
Upfyn Web

Legal · Thinqmesh Technologies Pvt Ltd

Security & privacy

Effective date: 17 August 2026

Upfyn runs on your own machine, which changes what is even possible to collect. This page sets out exactly what stays local, what is sent where, and what we can and cannot see — including the parts that are less flattering. It sits alongside our Privacy Policy, which is the binding document.

Terms of ServicePrivacy PolicyAcceptable UseRefund & CancellationCookie PolicySub-processors

1. What never leaves your computer

The desktop app does the work locally. These stay on your machine:

  • The full record of a conversation — every tool call, file edit, command and reasoning step — in a SQLite database at ~/.upfyn on your machine.
  • Your files and folders. The assistant reads and edits them through the desktop; the project is not automatically uploaded.
  • Your terminal. Commands run in a local shell on your computer.
  • Your API keys, when you bring your own. Stored locally and sent only to the provider you chose.

This is the part that matters most and it is not a policy promise — it is where the code runs. There is no version of Upfyn that uploads your project to run it.

2. What is sent to an AI model

An AI model has to see your question to answer it. Where that happens is your choice, and the three options genuinely differ:

If you use…Your prompt goes…
Your own API key (BYOK)Straight from your machine to that provider. Our servers are not in the path at all.
A local model (Ollama, LM Studio)Nothing leaves your computer. No network request is made.
UpfynAI creditsThrough our gateway to the model provider. We store the messages so a conversation can continue across turns and devices.

If you want no third party in the path at all, use a local model. That option is built in, it is free, and it works offline.

3. What we store, plainly

We would rather be specific than reassuring. Signed in to an Upfyn account, we hold:

  • Your account and billing record — name, email, plan, devices, invoices. Card details are handled by Razorpay and never reach us.
  • A text copy of your chats. While you are signed in, the readable text of each turn is synced to your account so a conversation can be picked up on the web or your phone. The full transcript — tool calls, file paths, reasoning — is not included and stays local.
  • Messages sent on UpfynAI credits. If you use our included credits rather than your own key, the gateway stores the message content to keep multi-turn conversations coherent. Using your own key or a local model avoids this entirely.

Stored text is held on managed infrastructure in our sub-processors' regions — see sub-processors. It is not sold, and it is not used to train anyone's model.

4. Can Upfyn staff read my conversations?

The honest answer has two halves, and we would rather give you both than the flattering one.

For projects you sync privately, no — by construction. Private sync seals every message on your device with AES-256-GCM before it is sent, using a key we never receive. Our servers hold ciphertext and nothing else. We hold an adversarial test in the codebase that simulates a hostile server and asserts it can recover neither the message body nor the folder names.

For everything else, treat it as readable by us. The chat text described in section 3 is stored in ordinary database columns. We restrict access internally and no admin tool exposes message content, but we are not going to tell you an engineer with database access is technically incapable of reading it. If a conversation is sensitive enough that this matters, use private sync, your own API key, or a local model.

5. Reaching your machine from your phone

When you open a session from the web or your phone, the traffic runs through a relay that is built not to understand it. Requests, headers, bodies and responses are sealed end-to-end between your devices; the relay forwards bytes it cannot interpret. As with private sync, this is covered by an adversarial test that simulates a malicious relay operator capturing every frame and asserts nothing readable is recoverable.

6. Nothing runs without your say-so

Every file write, edit and shell command is checked against a permission policy before it executes, in the same local process as the desktop assistant — not remotely. Writes, edits and shell commands default to asking. A prompt you never answer times out as a denial, never an approval, and a project can commit absolute denials that no per-session setting can override.

Analyst narrows its own writes to the active project's output folder. Developer exposes the full project and development tools while continuing to enforce the active permission policy.

7. The software itself

Desktop releases are code-signed and verified before they install, and the app updates itself from our own signed feed. We do not collect your source code, and there is no telemetry that reads file contents.

8. Reporting a vulnerability

If you find a security issue, email security@thinqmesh.com with enough detail to reproduce it. We will acknowledge it, keep you updated, and credit you if you would like. Please give us a reasonable chance to fix it before publishing.

For privacy questions or to exercise your rights under India's DPDP Act, our Grievance Officer is reachable at grievance@thinqmesh.com — see the Privacy Policy.

Thinqmesh Technologies Private Limited

Registered office: Gautam Buddh Nagar, Uttar Pradesh – 201014, India

General: legal@thinqmesh.com · Privacy: privacy@thinqmesh.com · Grievances: grievance@thinqmesh.com

Upfyn is a product of Thinqmesh Technologies Private Limited. Governed by the laws of India; courts at Gautam Buddh Nagar (Noida), Uttar Pradesh.

UpfynYour own AI assistant

© 2026 Thinqmesh Technologies Private Limited

Terms of UsePrivacy PolicyAcceptable Use PolicyRefundsCookies
Thinqmeshsupport@upfyn.com