Uma Back to the website

Short version: This website does not require an account and does not contain advertising trackers, contact forms or payment tools. Uma's core filtering engine is designed to run locally. Services you choose to connect, including hosting platforms and LLM providers, operate under their own privacy terms.

1. Scope of this policy

This Privacy Policy explains how the Uma open-source project handles information in connection with this website and the Uma context optimization software. In this policy, “Uma,” “we,” “us” or “our” refers to the maintainers of the Uma project.

This policy applies to this website and to project-controlled processing in the Uma software. It does not govern third-party websites, package indexes, source-code hosts, model repositories, cloud hosts or AI providers. Those services publish their own privacy policies and control their own processing.

2. Information handled by the website

Information you provide

The current website does not provide user accounts, contact forms, comments, purchases or direct file uploads. As a result, the website does not ask you to submit your name, email address, payment details or prompt content directly to Uma.

Basic technical information

The website is hosted by Vercel. When you request a page, Vercel and ordinary internet infrastructure may automatically process technical information needed to deliver and secure the site. This may include your IP address, browser type, device type, requested URL, approximate location derived from an IP address, referring page, timestamps and diagnostic or security events.

Uma does not receive a live dashboard of personal prompt content through this static website. Hosting logs may be retained by Vercel under its own settings and policies.

Cookies and analytics

The current website does not intentionally set advertising cookies and does not include a project-operated behavioral advertising system. Vercel or another service involved in delivering the website may use essential technologies for security, reliability or abuse prevention. If analytics or additional cookies are introduced later, this policy will be updated to describe them.

3. Information handled by the Uma software

Uma is an open-source developer tool. Its core filtering engine evaluates a query against supplied context using a locally running cross-encoder. The query, context and resulting filtered text are processed in the environment where the user runs Uma. The project maintainers do not automatically receive that content through the core local filtering operation.

The software may create temporary in-memory values or local output needed to produce relevance scores, filtering metrics and optimized context. How long those values remain available depends on the user's own application, runtime, logging choices and storage configuration.

Optional integrations

Some optional workflows can connect to an LLM provider or another service selected by the user. When a user enables one of those workflows, the content submitted to that provider is handled under the provider's privacy policy, contractual terms and account settings. Users are responsible for deciding what information to send and for configuring their providers appropriately.

Model and dependency downloads

Installing or running Uma may cause package managers, model hosts or software repositories to receive standard request information while delivering dependencies or model files. Those third parties operate independently from Uma.

4. How information may be used

To the extent the project maintainers receive limited technical or support information, it may be used to:

  • deliver the website and maintain its availability;
  • protect the website or project against abuse and security threats;
  • diagnose errors and improve reliability;
  • respond to project questions, bug reports or privacy requests;
  • comply with applicable law or enforce project rights.

Uma does not sell personal information. The project does not use information submitted through the local filtering engine for cross-context behavioral advertising.

5. When information may be disclosed

Limited information may be disclosed to service providers that help host, secure or distribute the website and software. Information may also be disclosed when reasonably necessary to comply with law, respond to valid legal process, protect users or investigate abuse. If the project is reorganized or transferred, relevant information may be transferred with it, subject to applicable law.

Public contributions, issues or discussions submitted to an open-source repository are public by design. Do not include private prompts, API keys, confidential documents or sensitive personal information in a public issue.

6. Retention

The project seeks to keep personal information only for as long as reasonably necessary for the purpose for which it was received, including security, support or legal compliance. The current static website does not maintain project-operated user profiles or a project database of visitor submissions.

Third-party services may retain logs or account information according to their own policies. Users of the Uma package control retention inside their own applications and environments.

7. Security

Reasonable measures are used to protect project-controlled information. No website, package or transmission method can be guaranteed completely secure. Users should avoid placing secrets in source code, public repositories or public support messages. API keys should be stored through appropriate environment-variable or secret-management systems.

If you believe you have discovered a security issue, contact the maintainers privately when a private reporting channel is available rather than publishing exploit details in a public issue.

8. Your choices and privacy rights

Depending on where you live, you may have rights to request access, correction, deletion or a copy of personal information maintained about you. You may also have the right to object to or restrict certain processing. These rights can be subject to exceptions under applicable law.

Because the current website does not operate user accounts or a visitor-submission database, Uma may have little or no project-controlled personal information that can be associated with a request. We may need enough information to understand and verify a request without collecting unnecessary additional data.

California residents may have rights under applicable California privacy laws. Uma does not sell or share personal information for cross-context behavioral advertising as those terms are commonly used in those laws. Visitors may also use browser controls to limit cookies or clear locally stored data.

9. Children's privacy

Uma is a general-purpose developer tool and is not directed to children under 13. The website does not knowingly collect personal information directly from children through accounts or forms. If a parent or guardian believes a child has provided personal information to the project, they may contact the maintainers so the situation can be reviewed.

10. International use

The website may be accessed from different countries. Hosting providers and other services may process information in locations outside the visitor's country. Those locations may have different data-protection laws. Users who deploy Uma within an organization are responsible for their own legal obligations, data locations and provider agreements.

11. Third-party services and links

The website links to services such as GitHub and PyPI. The Uma software may also interact with package repositories, model hosts or providers selected by the user. A link or integration does not mean Uma controls that third party's practices. Review the relevant third-party terms before submitting information.

12. Changes to this policy

This policy may change as the website or software evolves. Material changes will be reflected by updating the “Last updated” date on this page. Continued use after an update is subject to the revised policy to the extent permitted by law.

13. Contact

Questions or privacy requests may be directed to the Uma maintainers through the project's GitHub repository. Do not place sensitive personal information in a public issue. If the repository provides a private security or maintainer contact, use that channel for confidential matters.