Skip to content

Legal

Privacy Policy

Effective Date: August 5, 2026 · Last Updated: August 5, 2026


This policy explains what Privatae LLC ("Privatae," "we," "us") collects, why, and what you can do about it. It covers privatae.ai and the subscription service we operate for you.

It is written to be read. If anything here is unclear, email privacy@privatae.ai and we will explain it.

The Service is offered only to people in the United States. See §11.


1. The short version

  • We cannot read what is on your machine. Not by policy — by how the system is built. There is no support tool and no internal process that opens it.
  • We do not sell your data. Ever, to anyone, in any form.
  • We do not train models on your content. Not ours, not anyone's.
  • We collect what running the service requires — who you are, what you paid, how much machine you used, and what our systems log at the boundary.
  • You can see it, correct it, export it, and delete it, wherever you live.

2. The core point: your machine is closed to us

Your subscription gives you an isolated environment. Your files, data, conversations with the assistant, and the applications you build live inside it.

We have no read path into it. There is no administrative console that displays your data, no support workflow that opens your container, and no pipeline that copies its contents out for analysis, training, or product work.

Two honest limits, stated plainly because a privacy policy that only lists strengths is not trustworthy:

  1. We operate the machine. We can start, stop, migrate, and destroy it. Not reading it is not the same as not controlling it.
  2. Legal process reaches what we actually hold. We can be compelled to produce account and billing records, and we will comply with valid orders. We cannot produce container contents, because we do not have them. Where we are legally permitted, we will notify you before responding.

3. What we collect

3.1 Account information

Your email address, and a name if you give one. Authentication credentials — passwords are stored only as salted hashes; we never see the original, and where you use a passkey we hold only a public key. Your plan, and your account's status and history with us.

3.2 Billing information

What you paid, when, for what, and your prepaid balance and its transaction history.

We do not store your card number. Card details go directly to our payment processor (Stripe). We hold a token, the card brand, and the last four digits so you can tell your cards apart. If you sell through the marketplace, our processor collects the identity and tax information it needs to pay you and to meet its own reporting obligations.

3.3 Operational and usage data

Resource consumption — memory, storage, network volume, machine start and stop times. Metered usage records: which model provider handled a request, how many tokens it consumed, what it cost. The records are counts and costs, not the content of your requests.

3.4 Technical and security data

IP addresses, browser and device information, request timestamps and outcomes, authentication events, and security logs from the network boundary. We use these to run the service, diagnose faults, and detect abuse.

3.5 Network and domain data

Domains you connect or register, DNS records, certificate issuance records, and traffic metadata for sites you publish. If you publish a site, standard web logs for its visitors are generated in the course of serving it.

3.6 Support communications

If you contact us, we keep what you sent so we can help and so we have a record.

3.7 What we do not collect

We do not collect the contents of your machine. We do not run advertising trackers. We do not buy data about you from brokers. We do not build a behavioural profile of you, and we do not perform automated decision-making that produces legal or similarly significant effects.

4. Why we use it

We use the information above to:

  • give you the service you paid for and keep your machine running;
  • charge you correctly and show you what you spent;
  • authenticate you and protect your account;
  • detect, investigate, and stop abuse, fraud, and attacks;
  • send you service messages — billing, security, renewal reminders, changes to these terms;
  • meet legal and tax obligations; and
  • understand aggregate load so we can plan capacity.

We do not use it to advertise to you, to sell to third parties, or to train models.

5. Model providers — the part to read carefully

When you use the assistant, your request is routed to a third-party provider of language models. This is the one place where content leaves your machine, and it does so because you asked for an answer.

What this means:

  • The content of your request goes to that provider to be processed.
  • That provider's own terms and privacy practices apply to what they receive. They are not ours and we do not control them.
  • We pass through what the request requires. We do not attach your name, email, or billing identity to it.
  • You can bring your own provider account. If you connect your own key, your requests go to that provider under your own agreement with them, and we are only routing.
  • You can use models running on machines you control, in which case the content does not go to a third party at all.

Current providers are listed on the platform and may change. If you want a request never to reach a third party, use a local model or do not make the request.

6. Who else touches your data

We use a small number of service providers to run the business. They get only what their job requires, are bound by contract, and may not use it for their own purposes.

ProviderWhat they doWhat they get
StripePayments, subscriptions, marketplace payoutsCard and billing details, seller identity and tax data
Infrastructure and hosting providersRun the physical servers and networkEncrypted volumes, network traffic, operational telemetry
Content delivery and DNS providersServe the website, route traffic, issue certificatesRequest metadata, IP addresses, domain records
Email providerSend account, billing, and security emailYour email address and message contents
Model providersProcess assistant requestsRequest content, as described in §5

Beyond these, we share only: when you tell us to; when a valid legal order requires it (§2); to protect against imminent harm; and to a successor if the business is sold, in which case we will tell you first and this policy continues to apply until replaced on notice.

We have never sold personal information and we do not intend to.

7. How it is protected

Data is encrypted in transit and at rest. Machines are isolated from one another, and the boundary between them is enforced by the platform, not by convention. Network egress is default-deny. Administrative access to infrastructure is restricted, authenticated, and logged, and is confined to systems that operate the platform — it does not include a path into your machine.

Backups exist so that a failure does not lose your work; they are encrypted and expire on a schedule.

No system is perfectly secure, and we will not tell you otherwise. If a breach affects your personal information we will notify you and the relevant authorities as the law requires, without undue delay.

8. Where your data lives

Infrastructure is located in the United States. We do not replicate customer data to servers outside the US.

Third-party model providers may process requests on their own infrastructure, which may be located elsewhere — see §5.

9. Cookies

We use cookies that are necessary to make the site work: keeping you signed in, maintaining your session, and security protections such as CSRF tokens.

We do not use advertising cookies, third-party trackers, or cross-site analytics. There is no ad network on this site and no data broker receiving a feed from it.

Because we set no non-essential cookies, there is no consent banner. Blocking essential cookies will stop you being able to sign in.

10. How long we keep things

DataKept for
Account recordsWhile your account is open
Container contentsWhile your subscription is active; 90 days after cancellation or termination, then permanently deleted
Billing and tax records7 years, as tax law requires
Auto-renewal consent records3 years, or 1 year after termination, whichever is longer — as required by state auto-renewal law
Security and access logs12 months
Support correspondence3 years
BackupsUntil their scheduled expiry

After the 90-day window, container data is permanently and irrecoverably deleted. We cannot restore it, and neither can you. Export before then.

11. Availability — United States only

We offer the Service only to individuals and entities in the United States. We do not offer it in the European Union, the United Kingdom, or elsewhere, and this policy is written for US law. If you are outside the US, do not use the Service.

Because we do not serve the EU or UK, this policy contains no GDPR section, no EU representative, and no international transfer mechanism. We would rather say that plainly than publish a compliance posture we do not maintain.

12. Your rights

Twenty states now have comprehensive privacy laws, and their rights differ in detail. Rather than make you work out which applies to you, we give every customer the same rights, wherever you live:

  • Know what we hold about you and why.
  • Access a copy of it.
  • Correct anything inaccurate.
  • Delete it, subject to records we must keep by law (§10).
  • Port it — get it in a portable, machine-readable format.
  • Opt out of any sale or sharing of personal information for targeted advertising, and of profiling with significant effects. We do none of these things, so there is nothing to opt out of — but the right stands.
  • Not be retaliated against for exercising any of the above. We will not degrade your service or change your price because you asked.

12.1 How to exercise them

Email privacy@privatae.ai. We will verify you through your account email and respond within 45 days, extending once by a further 45 where a request is complex, and telling you if we do.

Much of this you can do yourself, immediately, from your account — export and deletion are controls, not requests.

An authorised agent may act for you with written permission we can verify.

12.2 Appeals

If we refuse a request, we will tell you why, and you may appeal by replying to that decision. We will respond to an appeal within 45 days. If we refuse again, we will tell you how to complain to your state Attorney General.

12.4 California

For California residents, the categories of personal information we collect are in §3, our purposes in §4, and recipients in §6. We have not sold or shared personal information in the preceding twelve months, and we do not collect personal information from anyone we know to be under 16. Sensitive personal information is used only to provide the service and never to infer characteristics about you.

13. Children

The Service is for adults 18 and over. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we will delete it and close the account. If you believe a child has given us information, email privacy@privatae.ai.

14. Your own visitors

If you publish a website or an application, you are its operator and the data you collect from your visitors is yours to govern. You need your own privacy policy and your own legal basis for what you collect. This policy covers our relationship with you, not your relationship with the people who use what you build.

Published sites are not search-indexed by default; turning that on is your decision, per site.

15. Changes

If we change this policy materially we will email you and post the change at least 30 days beforehand, unless a change must take effect sooner for legal reasons. The "Last Updated" date always reflects the current version, and we keep prior versions available.

16. Contact

Privatae LLC — Wyoming, USA

If you are unsatisfied with our response, you may complain to your state Attorney General.

Privacy Policy — Privatae