Borrow Tokens

Privacy Policy

Effective: [DATE] · Status: Private Beta

⚠️ TEMPLATE — requires attorney review before general availability. Working draft prepared without legal counsel.
1. What we collect
CategoryExamplesWhy
Account dataEmail, hashed API keys, invite provenanceAuthentication, abuse prevention
Billing recordsJob/session durations, GPU class, integer-microdollar amounts, spend capsCash billing, payouts, reconciliation. Append-only ledger — retained for accounting.
Operational logsAPI request logs (with request IDs), job lifecycle events, node heartbeats, container logs you emitDebugging, reliability metrics, incident response
Workload trafficPrompts/requests sent to your workspace endpoint transit our relay tunnelsRouting your traffic to your session
Host dataNode hardware specs (GPU model, VRAM), reliability history, payout recordsScheduling, quarantine, payouts

We do not sell personal data, run ads, or use your workload content to train models.

2. Where your workload content goes

Workspace traffic is relayed through our ingress to the machine serving your session — typically an independent contributor's ("Host's") GPU. See the Terms of Service §5 trust disclosure: content that reaches a Host's machine is technically observable by that Host despite contractual prohibitions.

We do not persist prompt/response bodies on our servers beyond transient relay buffers; container logs (which may include whatever your workload prints) are persisted for you to retrieve.

3. Retention
  • Billing and payout ledgers: retained for [7 years] (append-only by design; required for accounting and tax).
  • Job/session logs: retained [90 days] or until job deletion, whichever is first.
  • API request logs: [30 days].
  • Account data: until account deletion, then removed except where retention is legally required.
4. Third parties
  • Cloud fallback: jobs routed to Vast.ai run under Vast.ai's terms.
  • Infrastructure: hosting on Microsoft Azure; optional object storage on [Cloudflare R2 / S3-compatible provider].
  • No analytics/ad networks are embedded in the beta UI.
5. Security

API keys are stored hashed; session tokens are hashed and revocable; all public traffic is TLS-terminated; databases are not exposed publicly. Report vulnerabilities to [SECURITY EMAIL].

6. Your rights

Email [PRIVACY EMAIL] to access, correct, or delete your account data. Beta accounts are invite-only and presumed to be business users; if you are in a jurisdiction granting statutory rights (GDPR/CCPA), we will honor verified requests within the statutory window.

7. Contact

[OPERATOR LEGAL ENTITY NAME] · [ADDRESS] · [PRIVACY EMAIL]

See also: Terms of Service · Host Agreement