Privacy Policy
Last updated: 15 September 2026
This policy explains what Inferray ("we", "us") does with data when you use our website, console, and API (together, the "Service"). It sits alongside our Terms of Service.
The short version
We do not train on your data, and we do not store your prompts or responses. Your requests pass through to the model provider that serves them and are not written to our storage. What we keep is the metadata we need to bill you and show you your usage — when a request was made, which model and project it used, how many tokens it consumed, how long it took, and what it cost.
We do not sell your personal information, and we do not share your prompts or responses with anyone other than the provider that serves the request.
What we collect
Account data. Your name and email address, and — if you sign in with GitHub or Google — the basic profile details that provider returns. Plus the organizations and projects you belong to, your role in them, and any invitations you send or accept.
Usage metadata. For every API request: the time, the model, the project and API key it was sent with, the request path, the HTTP status, the duration, the token counts reported by the provider, and the resulting cost. Not the prompt, the response, the system prompt, tool definitions, attachments, or any other request or response content — those are never written to our database.
Billing data. Your credit balance, top-up history, and auto top-up settings. Card details go directly to Stripe and are never seen or stored by us; we keep the customer and payment identifiers Stripe gives back, and the amount, currency, and status of each payment.
Session data. A session cookie that keeps you signed in, plus cookies that remember which organization and project you are currently working in. These are required for the console to function; we do not run third-party advertising or analytics trackers on the site.
Support correspondence. Anything you send us by email, for as long as we need it to answer you.
How we use it
To run the Service: authenticate you, route your requests, enforce your balance and rate limits, and show you your usage and invoices. To bill you, take payment, and keep the tax and accounting records we are required to keep. To keep the Service secure — investigating abuse, fraud, and attacks on the Service itself. To reply when you contact us, and to send service notices such as a failed payment or a material change to our terms. Marketing email, if we ever send any, is opt-in and unsubscribable.
We do not use your data — prompts, responses, or usage metadata — to train, fine-tune, or evaluate any model, ours or anyone else's.
Model providers
Serving a request means sending it to the provider that runs the model you chose. That provider necessarily receives your prompt and returns the response, and handles it under its own privacy policy and data-retention practices, which we do not control. Choosing a model is choosing its provider. If your data has handling requirements, review the provider's policy before you send it, and treat any provider-side retention as outside our control.
Who else sees your data
Only the service providers we need to operate, and only for that purpose:
- Stripe, to take payment and hold your card details.
- Our infrastructure and database providers, to host the Service and store the account, project, and usage metadata described above.
- Our email provider, to send sign-in, invitation, and billing notices.
- Model providers, as described above, to serve your requests.
We may also disclose data where the law requires it, or where it is necessary to establish or defend a legal claim — and we will resist a request that we believe is overbroad or unlawful. If the Service is ever transferred to another owner, your data may transfer with it, subject to this policy.
How long we keep it
Account, organization, and project records last as long as your account does. Individual request-metadata rows are deleted 90 days after they are made, once the usage on them has been billed. The aggregate usage figures behind your analytics — hourly totals per project, model, and key — are kept longer so your history does not vanish, and they contain no request content. Billing and payment records are kept for as long as tax and accounting law requires, which is longer than the rest, and outlives account deletion for that reason.
Security
API keys are stored hashed, never in a form we can read back to you or to anyone else. Traffic to and from the Service is encrypted in transit, access to production data is limited to the people who need it, and the fastest way to limit the damage from a leaked key is to rotate it in the console. No system is perfectly secure, and we do not claim otherwise.
Your rights
You can see and correct your account details and your usage in the console, and you can ask us to close your account at any time. Depending on where you live — in particular in the EU, UK, and California — you may also have the right to a copy of your personal data, to have it corrected or deleted, to object to or restrict certain processing, and to complain to your data protection authority. Email us and we will action it; we will not charge you for it or treat you differently for asking.
Deletion has one limit: we cannot delete billing records we are legally required to retain. Everything else goes.
International transfers
The Service runs on infrastructure in several countries, and your data may be processed outside the country you are in — including in the United States. Where we transfer personal data out of the EU or UK, we rely on the appropriate safeguards for that transfer, such as the European Commission's Standard Contractual Clauses.
Children
The Service is not for anyone under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, tell us and we will delete it.
Changes
We may update this policy. The date at the top always reflects the current version, and if a change is material we will give notice through the Service or by email before it takes effect.
Contact
Privacy questions, or a request about your data: support@inferray.com.