Privacy
Effective August 12, 2026 · Version 1.0
Who handles your data
The data controller for UIKora is JINHANGBIN, an individual developer operating in the People's Republic of China. This policy covers the UIKora website, component delivery, CLI, MCP, Agent access, account pages, billing, and support. UIKora has not appointed a data-protection officer. Contact privacy@uikora.com for privacy questions or requests.
Data we receive
We receive account identifiers and an optional email snapshot from Clerk; subscription, order, refund, and webhook identifiers from Waffo; and request information such as component, version, delivery channel, decision, outcome, configuration hash, timestamp, IP-derived security signals, and errors. We also retain messages you send to support.
Data we do not keep
UIKora does not store full payment-card numbers. Access-token plaintext is shown once; only a cryptographic hash and token metadata are retained. Current Web, CLI, and MCP delivery does not upload or retain your project files, Agent prompts, generated code, or raw component parameter payloads. UIKora does not use customer content to train machine-learning models.
How we use data
We use data to authenticate accounts, deliver components, enforce the shared daily allowance and paid access, process and reconcile subscriptions, prevent abuse, investigate failed requests, provide exports and deletion, answer support requests, comply with law, and improve reliability. We do not sell personal information or use it for third-party behavioral advertising.
Service providers
Clerk provides authentication. Cloudflare provides Workers, D1, R2, networking, security, and operational logs. Waffo Pancake is UIKora's hosted checkout and payment processor and provides subscription, refund, and webhook services. Payment-card data is processed by Waffo Pancake and is never stored on UIKora servers. These providers process data under their own terms and may operate in more than one country.
Retention
Account data is kept while the account is active. An accepted deletion request immediately revokes UIKora access and tokens and removes the local email snapshot. Our default targets are: request, delivery, and security records for up to 12 months; revoked-token metadata for up to 12 months after revocation; support correspondence for up to 24 months after closure; and payment, refund, tax, fraud, and accounting records for up to seven years or the shorter period permitted by applicable law. Deleted primary data may remain in protected backups for up to 30 days. We may retain a record longer when reasonably required for a dispute, security incident, legal hold, or statutory duty.
Your choices and rights
The account pages provide a portable data export, token revocation, subscription cancellation, and an account-deletion request. Depending on where you live, you may request information, access, correction, deletion, portability, restriction, or objection, and may withdraw consent where processing depends on consent. Email privacy@uikora.com; identity verification may be required. We aim to respond within 30 calendar days, subject to any lawful extension. You may also complain to the data-protection authority where you live.
Cookies and transfers
UIKora currently uses authentication and security cookies needed to operate the service and does not run third-party advertising cookies. Data may be processed outside your country by the providers above. Where required, we rely on provider contractual safeguards or another lawful transfer mechanism.
Security and children
We use encrypted transport, restricted operator access, hashed access credentials, private source storage, rate limits, and audit records. No system is completely secure. Where legally required, we will notify affected people and regulators without undue delay and, where the applicable rule requires it, within 72 hours after becoming aware of a qualifying breach. UIKora is not directed to anyone under 18; contact us if you believe a minor supplied personal information.
Changes
We will update the effective date and provide a prominent service or account-email notice at least 14 days before material changes take effect where reasonably possible. Privacy requests go to privacy@uikora.com; general support goes to support@uikora.com.