Legal
Privacy Policy
Effective Date: August 5, 2026 · Last Updated: August 5, 2026
This policy explains what Privatae LLC ("Privatae," "we," "us") collects, why, and what you can do about it. It covers privatae.ai and the subscription service we operate for you.
It is written to be read. If anything here is unclear, email privacy@privatae.ai and we will explain it.
The Service is offered only to people in the United States. See §11.
1. The short version
- We cannot read what is on your machine. Not by policy — by how the system is built. There is no support tool and no internal process that opens it.
- We do not sell your data. Ever, to anyone, in any form.
- We do not train models on your content. Not ours, not anyone's.
- We collect what running the service requires — who you are, what you paid, how much machine you used, and what our systems log at the boundary.
- You can see it, correct it, export it, and delete it, wherever you live.
2. The core point: your machine is closed to us
Your subscription gives you an isolated environment. Your files, data, conversations with the assistant, and the applications you build live inside it.
We have no read path into it. There is no administrative console that displays your data, no support workflow that opens your container, and no pipeline that copies its contents out for analysis, training, or product work.
Two honest limits, stated plainly because a privacy policy that only lists strengths is not trustworthy:
- We operate the machine. We can start, stop, migrate, and destroy it. Not reading it is not the same as not controlling it.
- Legal process reaches what we actually hold. We can be compelled to produce account and billing records, and we will comply with valid orders. We cannot produce container contents, because we do not have them. Where we are legally permitted, we will notify you before responding.
3. What we collect
3.1 Account information
Your email address, and a name if you give one. Authentication credentials — passwords are stored only as salted hashes; we never see the original, and where you use a passkey we hold only a public key. Your plan, and your account's status and history with us.
3.2 Billing information
What you paid, when, for what, and your prepaid balance and its transaction history.
We do not store your card number. Card details go directly to our payment processor (Stripe). We hold a token, the card brand, and the last four digits so you can tell your cards apart. If you sell through the marketplace, our processor collects the identity and tax information it needs to pay you and to meet its own reporting obligations.
3.3 Operational and usage data
Resource consumption — memory, storage, network volume, machine start and stop times. Metered usage records: which model provider handled a request, how many tokens it consumed, what it cost. The records are counts and costs, not the content of your requests.
3.4 Technical and security data
IP addresses, browser and device information, request timestamps and outcomes, authentication events, and security logs from the network boundary. We use these to run the service, diagnose faults, and detect abuse.
3.5 Network and domain data
Domains you connect or register, DNS records, certificate issuance records, and traffic metadata for sites you publish. If you publish a site, standard web logs for its visitors are generated in the course of serving it.
3.6 Support communications
If you contact us, we keep what you sent so we can help and so we have a record.
3.7 What we do not collect
We do not collect the contents of your machine. We do not run advertising trackers. We do not buy data about you from brokers. We do not build a behavioural profile of you, and we do not perform automated decision-making that produces legal or similarly significant effects.
4. Why we use it
We use the information above to:
- give you the service you paid for and keep your machine running;
- charge you correctly and show you what you spent;
- authenticate you and protect your account;
- detect, investigate, and stop abuse, fraud, and attacks;
- send you service messages — billing, security, renewal reminders, changes to these terms;
- meet legal and tax obligations; and
- understand aggregate load so we can plan capacity.
We do not use it to advertise to you, to sell to third parties, or to train models.
5. Model providers — the part to read carefully
When you use the assistant, your request is routed to a third-party provider of language models. This is the one place where content leaves your machine, and it does so because you asked for an answer.
What this means:
- The content of your request goes to that provider to be processed.
- That provider's own terms and privacy practices apply to what they receive. They are not ours and we do not control them.
- We pass through what the request requires. We do not attach your name, email, or billing identity to it.
- You can bring your own provider account. If you connect your own key, your requests go to that provider under your own agreement with them, and we are only routing.
- You can use models running on machines you control, in which case the content does not go to a third party at all.
Current providers are listed on the platform and may change. If you want a request never to reach a third party, use a local model or do not make the request.
6. Who else touches your data
We use a small number of service providers to run the business. They get only what their job requires, are bound by contract, and may not use it for their own purposes.
| Provider | What they do | What they get |
|---|---|---|
| Stripe | Payments, subscriptions, marketplace payouts | Card and billing details, seller identity and tax data |
| Infrastructure and hosting providers | Run the physical servers and network | Encrypted volumes, network traffic, operational telemetry |
| Content delivery and DNS providers | Serve the website, route traffic, issue certificates | Request metadata, IP addresses, domain records |
| Email provider | Send account, billing, and security email | Your email address and message contents |
| Model providers | Process assistant requests | Request content, as described in §5 |
Beyond these, we share only: when you tell us to; when a valid legal order requires it (§2); to protect against imminent harm; and to a successor if the business is sold, in which case we will tell you first and this policy continues to apply until replaced on notice.
We have never sold personal information and we do not intend to.
7. How it is protected
Data is encrypted in transit and at rest. Machines are isolated from one another, and the boundary between them is enforced by the platform, not by convention. Network egress is default-deny. Administrative access to infrastructure is restricted, authenticated, and logged, and is confined to systems that operate the platform — it does not include a path into your machine.
Backups exist so that a failure does not lose your work; they are encrypted and expire on a schedule.
No system is perfectly secure, and we will not tell you otherwise. If a breach affects your personal information we will notify you and the relevant authorities as the law requires, without undue delay.
8. Where your data lives
Infrastructure is located in the United States. We do not replicate customer data to servers outside the US.
Third-party model providers may process requests on their own infrastructure, which may be located elsewhere — see §5.
9. Cookies
We use cookies that are necessary to make the site work: keeping you signed in, maintaining your session, and security protections such as CSRF tokens.
We do not use advertising cookies, third-party trackers, or cross-site analytics. There is no ad network on this site and no data broker receiving a feed from it.
Because we set no non-essential cookies, there is no consent banner. Blocking essential cookies will stop you being able to sign in.
10. How long we keep things
| Data | Kept for |
|---|---|
| Account records | While your account is open |
| Container contents | While your subscription is active; 90 days after cancellation or termination, then permanently deleted |
| Billing and tax records | 7 years, as tax law requires |
| Auto-renewal consent records | 3 years, or 1 year after termination, whichever is longer — as required by state auto-renewal law |
| Security and access logs | 12 months |
| Support correspondence | 3 years |
| Backups | Until their scheduled expiry |
After the 90-day window, container data is permanently and irrecoverably deleted. We cannot restore it, and neither can you. Export before then.
11. Availability — United States only
We offer the Service only to individuals and entities in the United States. We do not offer it in the European Union, the United Kingdom, or elsewhere, and this policy is written for US law. If you are outside the US, do not use the Service.
Because we do not serve the EU or UK, this policy contains no GDPR section, no EU representative, and no international transfer mechanism. We would rather say that plainly than publish a compliance posture we do not maintain.
12. Your rights
Twenty states now have comprehensive privacy laws, and their rights differ in detail. Rather than make you work out which applies to you, we give every customer the same rights, wherever you live:
- Know what we hold about you and why.
- Access a copy of it.
- Correct anything inaccurate.
- Delete it, subject to records we must keep by law (§10).
- Port it — get it in a portable, machine-readable format.
- Opt out of any sale or sharing of personal information for targeted advertising, and of profiling with significant effects. We do none of these things, so there is nothing to opt out of — but the right stands.
- Not be retaliated against for exercising any of the above. We will not degrade your service or change your price because you asked.
12.1 How to exercise them
Email privacy@privatae.ai. We will verify you through your account email and respond within 45 days, extending once by a further 45 where a request is complex, and telling you if we do.
Much of this you can do yourself, immediately, from your account — export and deletion are controls, not requests.
An authorised agent may act for you with written permission we can verify.
12.2 Appeals
If we refuse a request, we will tell you why, and you may appeal by replying to that decision. We will respond to an appeal within 45 days. If we refuse again, we will tell you how to complain to your state Attorney General.
12.4 California
For California residents, the categories of personal information we collect are in §3, our purposes in §4, and recipients in §6. We have not sold or shared personal information in the preceding twelve months, and we do not collect personal information from anyone we know to be under 16. Sensitive personal information is used only to provide the service and never to infer characteristics about you.
13. Children
The Service is for adults 18 and over. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it and close the account. If you believe a child has given us information, email privacy@privatae.ai.
14. Your own visitors
If you publish a website or an application, you are its operator and the data you collect from your visitors is yours to govern. You need your own privacy policy and your own legal basis for what you collect. This policy covers our relationship with you, not your relationship with the people who use what you build.
Published sites are not search-indexed by default; turning that on is your decision, per site.
15. Changes
If we change this policy materially we will email you and post the change at least 30 days beforehand, unless a change must take effect sooner for legal reasons. The "Last Updated" date always reflects the current version, and we keep prior versions available.
16. Contact
Privatae LLC — Wyoming, USA
- Privacy: privacy@privatae.ai
- Security: security@privatae.ai
- Legal: legal@privatae.ai
If you are unsatisfied with our response, you may complain to your state Attorney General.