Privacy policy
This privacy policy explains, pursuant to Art. 13 and 14 GDPR, what personal data is processed on this website (www.ultraprompt.at), in the Ultraprompt web app (app.ultraprompt.at) and by its API (api.ultraprompt.at). Last updated: 3 October 2026.
Controller
Petar Beck
St.-Peter-Hauptstraße 229B
8042 Graz, Austria
E-mail: mail@ultraprompt.at
This website (www.ultraprompt.at)
This marketing website is a purely static page. It sets no cookies, uses no analytics or tracking services, no advertising networks and no social-media plugins. There are no forms here, and no input is stored.
All resources, including the fonts, are served directly from our own server. No third-party content (such as Google Fonts or CDNs) is embedded. The "Sign in" and "Create account" links on this site only take you to the web app described below; visiting this website by itself does not create an account or set a login cookie.
Hosting and server log files
When any of the three addresses above is accessed, the server automatically processes technically necessary access data: IP address, date and time of the request, the page or endpoint requested, the amount of data transferred, browser or client type and version, operating system and, for the website, the previously visited page (referrer).
This data is used solely for the technical operation, stability and security of the service (legal basis: Art. 6(1)(f) GDPR - legitimate interest). It is not merged with other data sources and is deleted as soon as it is no longer required for these purposes, unless a security-relevant incident requires longer retention.
Your account on the web app (app.ultraprompt.at)
Creating an account is optional and free of charge - Ultraprompt has no paid plans. If you do create one, we process:
- Account data: your e-mail address, display name, locale and a salted password hash (we never store your password itself)
- Content you enter: your projects, lanes, tasks, checklists and pipeline status - i.e. whatever you put on your board
- Session data: one record per signed-in device or browser, including device name, platform, browser/client version, a hashed (not plain-text) IP address, and timestamps for creation, last use and, where applicable, revocation
- Access tokens: personal API tokens (starting with "upat_") that you explicitly create for the /ultraprompt command-line harness, together with their name and scope
Purpose and legal basis
We process the data above to provide your account and your board in the web app, and to let the /ultraprompt harness act on your behalf (Art. 6(1)(b) GDPR - performance of a contract with you). We process session and log data additionally to keep the service secure: detecting abuse, rate-limiting and letting you revoke a device from your account (Art. 6(1)(f) GDPR - legitimate interest in a secure service).
The login cookie
Signing in to the web app sets exactly one cookie, "up_refresh". It is strictly necessary to keep you signed in - there is no way to use the web app without it - and carries no tracking or analytics purpose, so no consent banner is shown for it.
- Set only on api.ultraprompt.at (not on this website, and not on app.ultraprompt.at directly), and only after you sign in or register
- HttpOnly (invisible to page scripts), Secure (HTTPS only), SameSite=Strict, and sent only to the sign-in/session endpoints - not to the rest of the API
- Lifetime of up to 30 days, refreshed while you stay active; deleted immediately when you sign out
E-mails we send
The web app sends transactional e-mails only, triggered by an action you take: confirming a new account, resetting a forgotten password, and confirming a change of e-mail address. We do not send newsletters or marketing e-mail.
These e-mails are sent from noreply@ultraprompt.at; replies to them, and questions about your account, reach support@ultraprompt.at. The controller contact above (mail@ultraprompt.at) remains the address for everything else.
Retention
Account data (profile, board content, tokens) is kept for as long as your account exists. You can delete your account at any time from within the web app, which erases this data.
A session is deleted (not just marked revoked) 30 days after you sign out or revoke it. Server access logs are kept only as long as described under "Hosting and server log files" above.
Your rights
Under the GDPR you have, in particular, the following rights:
- Access to the data processed (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure (Art. 17 GDPR) - for an account, the quickest way is deleting it in the web app
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Objection to processing based on legitimate interests (Art. 21 GDPR)
Right to lodge a complaint
You also have the right to lodge a complaint with the Austrian Data Protection Authority: https://www.dsb.gv.at.
Changes to this policy
We adapt this privacy policy when the website, the web app or the legal situation changes. The version published here at the time applies.