Overview and scope
Fyvie AI (“Fyvie”, “we”, “us”, “our”) researches, builds and operates artificial intelligence systems. This Privacy Policy explains how we collect, use, disclose, and otherwise process personal data.
This policy applies to:
- Our websites, including fyvie.ai, our documentation, research publications, careers pages, and other marketing or informational properties (the “Sites”);
- Any consumer-facing assistant offered by us on web, mobile, desktop or other platforms (the “Consumer Services”);
- Our developer platform, including the Fyvie AI API, developer console, SDKs, and related tooling (the “API Services”);
- Our business and enterprise offerings; and
- Our other interactions with you, including events, research collaborations, recruiting, support requests, and business communications.
We refer to all of the above collectively as the “Services”.
This policy does not apply to
- Personal data we process on behalf of a business customer as a processor or service provider. Where a business or enterprise customer uses the API Services or Business Services to process personal data about their own users, that customer is the controller and their privacy notice governs. Our handling of that data is set out in our Data Processing Addendum and Section 3 below.
- Third-party services that integrate with, link from, or are built on top of the Services. Those are governed by the third party’s own privacy notice.
- Model outputs as used by others. Where a developer builds an application on our API, that developer decides what the application does with our outputs.
If you do not agree with this policy, do not use the Services.
Who we are
Fyvie AI is a company registered in Scotland under company number SC893102, with its registered office at Suite 1.2, 8 Elliot Street, Skypark, Glasgow, United Kingdom, G3 8EP.
Fyvie AI is the controller of your personal data, wherever you are located and whichever Service you use. We do not operate through separate entities.
We are established in the United Kingdom and are subject to the UK GDPR and the Data Protection Act 2018. Where we offer the Services to individuals in the European Economic Area or monitor their behaviour there, we are also subject to the EU GDPR under Article 3(2).
Privacy contact. Questions about this policy, and requests to exercise your rights, should be directed to our privacy team at [email protected] or to the postal address above. We have not appointed a Data Protection Officer, as we are not currently required to do so under Article 37 of the UK or EU GDPR. We keep that assessment under review and will update this policy if the position changes.
Our role: controller and processor
Our role differs by Service, and this determines which parts of this policy apply to you.
We act as a controller (in US terms, a “business”) when we determine the purposes and means of processing. This is the case for:
- Visitors to our Sites;
- Individual users of the Consumer Services;
- Account, billing, and administrative contacts for API and Business Services customers;
- Job applicants, event attendees, and business contacts;
- Our own trust, safety, and security operations across all Services, including detection of prohibited uses.
We act as a processor (in US terms, a “service provider”) when a business customer submits personal data to the API Services or Business Services and we process it on their instructions. In that case:
- The customer is the controller and is responsible for having a lawful basis, providing notice to their end users, and honouring their end users’ rights;
- We process Customer Content only to provide the Services, as described in our Data Processing Addendum and Terms of Service, and for the limited safety and security purposes described in Section 5.3, which we perform as a controller;
- Requests from a customer’s end users should be directed to that customer. If we receive such a request directly, we will refer the individual to the relevant customer unless we are legally required to respond ourselves.
Personal data we collect
4.1 Data you provide to us
| Category | Examples |
|---|---|
| Account data | Name, email address, username, password (stored as a hash), organization name, job title, country, phone number, and any profile information you add. |
| Authentication data | Credentials, single sign-on identifiers, multi-factor authentication tokens and recovery contacts. |
| Payment data | Billing name and address, tax identifiers, purchase history, and the last four digits and expiry of a payment card. Full card numbers are collected and stored by our payment processor, not by us. |
| Inputs | The prompts, files, images, audio, code, documents, and other content you submit to the Services, together with any personal data those materials happen to contain. |
| Outputs | The content our models generate in response to your Inputs. |
| Feedback | Ratings, flags, bug reports, survey responses, and any commentary you provide about Outputs or the Services. |
| Communications | Support tickets, sales and partnership correspondence, security disclosures, event registrations, newsletter subscriptions, and recruiting materials such as CVs. |
| Trust and safety data | Information you provide when appealing an enforcement decision, verifying your identity or age, or reporting abuse. |
4.2 Data we collect automatically
| Category | Examples |
|---|---|
| Usage data | Features used, session timestamps, model and endpoint invoked, request volume, token counts, latency, error codes, referring pages, and interaction events. |
| Device and connection data | IP address, browser type and version, operating system, device identifiers, screen and language settings, and approximate location derived from IP address. |
| API telemetry | API key identifiers, request and response metadata, rate-limit and quota state, SDK version, and organization and project identifiers. |
| Cookies and similar technologies | See Section 13. |
| Security and integrity signals | Authentication events, anomaly and fraud signals, abuse-detection classifier scores, and audit logs. |
4.3 Data from other sources
- Business customers, who provide contact and provisioning details for their authorized users.
- Identity and single sign-on providers, where you authenticate through them.
- Payment processors and fraud-prevention providers, for transaction verification.
- Publicly available and licensed sources — including data used to train our models. See Section 6.4.
- Business partners, resellers, and marketing providers, where permitted by law.
- Recruiting sources, including job boards, referrals, and background-check providers where lawful and disclosed separately.
4.4 Special category and sensitive data
We do not ask you to provide special category data (Art. 9 GDPR) or sensitive personal information under US state law, and we ask that you not submit it unnecessarily. If you choose to include such data in an Input, we process it as part of delivering the Service you requested. Where required, we rely on your explicit consent or another Art. 9 condition, and we do not use sensitive personal information for purposes other than those permitted by applicable law. Where we identify special category or sensitive data in content that would otherwise be used for model training, we filter or exclude it — see Section 6.2. See also Section 18.2.
How we use personal data
5.1 Providing and improving the Services
- Creating and administering accounts and organizations;
- Processing Inputs and returning Outputs;
- Providing memory, history, projects, and similar features where you have enabled them;
- Operating billing, metering, quotas, and rate limits;
- Providing support and responding to your requests;
- Diagnosing and fixing errors, testing changes, and improving performance, reliability, and usability of the Services. This is distinct from training models on your content — see Section 6.
5.2 Communications
- Sending service, security, and administrative notices, which you cannot opt out of while you hold an account;
- Sending product updates, research announcements, and marketing communications, subject to your consent where required and always with an unsubscribe option;
- Conducting surveys and research about the Services.
5.3 Trust, safety, and security
We review activity across the Services — including, where necessary, Inputs and Outputs — to:
- Detect and prevent violations of our Usage Policy and Terms of Service;
- Detect and respond to fraud, abuse, spam, scraping, credential stuffing, and other security incidents;
- Investigate and mitigate serious risks, including risks to physical safety, child safety, and critical infrastructure;
- Enforce rate limits, suspend or terminate accounts, and maintain the integrity of the Services.
We perform these activities as a controller, including in respect of Customer Content processed through the API Services and Business Services, because they are necessary for our own compliance and legitimate interests in operating a safe platform. We use automated classifiers for initial detection and apply human review before consequential enforcement decisions where practicable. See Section 14.
5.4 Legal and compliance
- Complying with applicable laws, regulations, and lawful requests from public authorities;
- Establishing, exercising, and defending legal claims;
- Conducting audits, and meeting export control, sanctions, and anti-money-laundering obligations;
- Evaluating, negotiating, or completing a corporate transaction. See Section 8.
5.5 Research and aggregate analysis
We produce aggregated and de-identified statistics about how the Services are used — for example, aggregate request volumes by region, feature adoption rates, common usage patterns, or peak usage hours. Once data is aggregated or de-identified such that it can no longer reasonably be associated with an individual, we may use, share, or sell it for research, safety publications, and business purposes. We commit not to attempt to re-identify such data except to test the effectiveness of our de-identification, and we require the same commitment from anyone we provide it to.
Model training
6.1 Products that run locally
We never train our models on Inputs or Outputs from products that run locally on your device. Our local products process your content on your own hardware. That content is not transmitted to us, so it cannot enter a training corpus.
6.2 Online Services
Where you use our online Services, whether we train our models on your Inputs and Outputs depends on your plan:
- Free plans. We may use the Inputs you submit and the Outputs our models generate for you to train and improve our models. We tell you this when you sign up.
- Paid plans (other than enterprise plans). You can opt out of your Inputs and Outputs being used to train our models. If you opt out, we do not train on them, with three exceptions:
- We may ask you how our model is performing, or whether you found an Output helpful or unhelpful. If you answer, we use your answer to improve our models — that is the purpose of the question, and by answering it you give us explicit consent to record and use your response;
- You explicitly give us permission to use a specific Input or Output for training;
- You presented code, the product of code, or more broadly the product of our models to an audience at a public event, hackathon, code meetup or other educational event where coding or language-model use is a central element. This strictly excludes commercialisation events and instances with a clear commercialisation agenda.
- Enterprise plans and the API Services. We do not train our models on your raw Inputs and Outputs. We may train on de-identified data derived from your usage. Your contract with us may exclude the use of your data, or any derivative of it, for training entirely — where it does, the contract governs.
Where we identify special category or sensitive data in content that would otherwise be used for training, we filter or exclude it.
6.3 Feedback and safety signals
- Feedback you volunteer. If you affirmatively submit content to us for a specific purpose — for example by flagging an Output as harmful, participating in a research study, or opting into a red-teaming programme — we use that content for the purpose you were told about at the time, which may include model evaluation or safety training. We describe this at the point of collection and you can decline.
- Safety classifiers. We may use signals derived from abuse detection to improve the classifiers and filters that protect the Services. We do this using de-identified or aggregated data wherever feasible, and it does not involve training our general-purpose models on your content beyond what Section 6.2 permits.
6.4 Where our training data comes from
Our models are trained on data drawn from sources including:
- Publicly available information on the internet;
- Data licensed from third parties under agreements that permit this use;
- Data provided by contractors and workers we engage for annotation, evaluation, and preference data, who are informed of the purpose;
- Data we generate ourselves, including synthetic data;
- Data we physically acquire, including books, textbooks or other material that contains data we can use for training purposes;
- Data we purchase;
- User content, where Section 6.2 permits it.
Publicly available sources may incidentally contain personal data. Where we process personal data for training, we rely on our legitimate interests in developing beneficial AI systems (Art. 6(1)(f) GDPR), having conducted a balancing assessment; we apply filtering intended to reduce the volume of personal data and remove certain categories of sensitive content; and we take measures intended to reduce the likelihood that models reproduce personal data in their outputs.
6.5 Rights relating to training data
If you believe our models were trained on your personal data and you wish to object or request erasure, contact us at [email protected] with enough detail to locate the data. Please note the practical constraints: for data already incorporated into a trained model, we may not be able to isolate and remove an individual’s data from model weights, and we will explain what we can do — such as suppressing outputs, excluding the source from future training runs, and honouring your objection going forward.
Legal bases for processing (EEA/UK)
Where the GDPR or UK GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Services, account administration, billing, support (Section 5.1) | Performance of a contract (Art. 6(1)(b)) |
| Service and security notices | Performance of a contract; legitimate interests (Art. 6(1)(f)) |
| Marketing communications | Consent (Art. 6(1)(a)) where required; otherwise legitimate interests, subject to opt-out |
| Trust, safety, and security (Section 5.3) | Legitimate interests in operating a safe and secure platform and protecting users and third parties; legal obligation where applicable (Art. 6(1)(c)) |
| Analytics, service improvement, aggregate research (Sections 5.1, 5.5) | Legitimate interests in understanding and improving our Services |
| Training models on free-plan Inputs and Outputs, and on de-identified usage data (Section 6.2) | Legitimate interests in developing AI systems (Art. 6(1)(f)), with notice at sign-up; consent where required |
| Training models on publicly available and licensed data (Section 6.4) | Legitimate interests in developing AI systems (Art. 6(1)(f)) |
| Non-essential cookies and similar technologies | Consent |
| Legal compliance, claims, corporate transactions (Section 5.4) | Legal obligation; legitimate interests |
| Special category data appearing in Inputs | Explicit consent (Art. 9(2)(a)) or, where applicable, Art. 9(2)(g) or 9(2)(f) |
Where we rely on legitimate interests, we have carried out a balancing test weighing our interests against your rights and freedoms. You can request a summary of the relevant assessment, and you have the right to object — see Section 12.
How we disclose personal data
We do not sell your personal data. We may sell or share aggregated or de-identified data that can no longer reasonably be associated with an individual, as described in Section 5.5. We disclose personal data in the following circumstances:
- Service providers and subprocessors. We use vendors for cloud hosting and compute, content delivery, payment processing, customer support tooling, communications, analytics, security monitoring, and data annotation. They act on our instructions under written contracts that restrict their use of the data. A current list of subprocessors for the API and Business Services is available on request from [email protected], and customers are notified of subprocessor changes as set out in our Data Processing Addendum.
- Affiliates. Members of our corporate group, for the purposes described in this policy.
- Business customers. If you use the Services through an account provisioned by your employer or another organization, that organization’s administrators may access your account information and, depending on the plan and configuration, your usage and content. Their policies govern that access.
- At your direction. Where you enable an integration, connector, or third-party tool, or share a conversation or artifact, we disclose the data necessary to fulfil that request.
- Legal and safety. We disclose personal data where we believe in good faith it is necessary to comply with law or legal process; to respond to lawful requests from public authorities; to enforce our terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Fyvie, our users, or the public. We assess requests from public authorities for validity, seek to narrow overbroad requests, and — where legally permitted — notify affected customers before disclosure.
- Corporate transactions. In connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to the acquirer honouring commitments materially consistent with this policy.
- Aggregated and de-identified data. As described in Section 5.5.
International data transfers
We are headquartered in the United Kingdom and operate infrastructure in multiple jurisdictions. Your personal data may be transferred to, stored in, and processed in countries whose data protection laws differ from those of your own. In particular, our analytics providers (see Section 13) process data on servers in the United States.
For transfers of personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards, including:
- The European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss adaptations, as applicable;
- Transfer impact assessments and supplementary technical, organizational, and contractual measures where required;
- Adequacy regulations and decisions of the UK Government and the European Commission, where they cover the destination country.
You can request a copy of the relevant safeguards by contacting [email protected].
Certain Business Services offer regional data residency. Where available and elected, we describe the applicable commitments in the relevant order form or documentation.
Data retention
We retain personal data for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law.
| Data | Indicative retention |
|---|---|
| Account and profile data | Duration of the account, then 90 days after deletion, subject to backup cycles |
| Inputs and Outputs (Consumer Services) | Until you delete them, or 365 days after account deletion, retained to meet audit and legal requirements. Deleted conversations are removed from your view immediately and from our systems within 90 days |
| Inputs and Outputs (API Services) | Up to 60 days for abuse monitoring, then deleted, unless the customer has enabled a feature requiring longer storage or a zero-retention configuration applies |
| Billing and tax records | 7 years, or as required by law |
| Trust and safety records and enforcement decisions | Up to 10 years, to prevent re-offending and defend appeals |
| Security and audit logs | 24 months |
| Support communications | 5 years after the ticket closes |
| Marketing contact data | Until you unsubscribe, plus a suppression record retained indefinitely so we do not contact you again |
| Job applicant data | 24 months after the process closes, or longer with your consent |
Where we are subject to a legal hold, we retain the affected data until the hold is lifted.
Security
We maintain a security programme with administrative, technical, and physical safeguards designed to protect personal data, including:
- Encryption of data in transit (TLS 1.2+) and at rest;
- Role-based access control, least-privilege access, and mandatory multi-factor authentication for employee access to production systems;
- Logging and monitoring of access to personal data;
- Vendor security review and contractual security obligations;
- Secure development practices, dependency scanning, and periodic penetration testing;
- An incident response programme, including breach notification to regulators and affected individuals where required by law.
No system is perfectly secure. You are responsible for safeguarding your credentials and API keys, rotating keys promptly if they may have been exposed, and configuring the Services appropriately for the sensitivity of the data you submit. Report suspected vulnerabilities to [email protected].
Your privacy rights
Subject to applicable law and verification of your identity, you may have the right to:
- Access the personal data we hold about you and receive information about how we process it;
- Correct inaccurate or incomplete personal data;
- Delete your personal data;
- Port personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interests, including profiling, and to object to direct marketing at any time;
- Withdraw consent where processing is based on consent, without affecting the lawfulness of prior processing;
- Not be discriminated against for exercising your rights;
- Opt out of the sale or sharing of personal data, of targeted advertising, and of certain profiling, as described in Section 18.2 — noting that we do not sell or share personal data as those terms are defined under US state law;
- Lodge a complaint with your supervisory authority. In the UK this is the Information Commissioner’s Office (ico.org.uk); in the EEA it is the authority in your country of residence, work, or the place of the alleged infringement. Our supervisory authority is the UK Information Commissioner’s Office. We would appreciate the chance to address your concern first.
How to exercise your rights. Contact us at [email protected]. We respond within the timeframe required by law — generally one month under the GDPR (extendable by two further months for complex requests) and 45 days under US state laws (extendable by 45 days). We may ask for information to verify your identity, and we will not use that information for any other purpose.
Authorized agents. You may designate an agent to submit requests on your behalf. We require proof of the agent’s authority and may ask you to verify your identity directly.
Appeals. If we decline your request, our response will explain why and how to appeal. To appeal, contact [email protected] with the subject line “Privacy Request Appeal”. If we deny your appeal, you may contact your state attorney general or supervisory authority.
End users of business customers. If you interact with an application built by one of our customers, direct your request to that customer.
Cookies and similar technologies
We use cookies, local storage, SDKs, pixels, and similar technologies to:
- Operate the Services — authentication, session management, load balancing, security, and preference storage. These are strictly necessary and cannot be disabled;
- Measure performance and usage — analytics that help us understand feature adoption and diagnose problems. We use third-party analytics providers for this, currently Google Analytics and PostHog, which set their own cookies and process usage and device data on our behalf, including on servers in the United States (see Section 9);
- Support marketing — measuring the effectiveness of our campaigns on our public Sites, using the same analytics tools.
We do not use advertising cookies on our Sites or within the product experience.
Your choices. Where required, we obtain consent through our cookie banner before setting non-essential cookies, including analytics cookies, and you can change your preferences at any time through the cookie controls on our Sites. You can also control cookies through your browser settings, though blocking essential cookies will break parts of the Services.
Global Privacy Control. We treat a GPC signal received from your browser as a valid request to opt out of the sale or sharing of personal data and of targeted advertising for that browser.
Do Not Track. There is no common industry standard for responding to DNT browser signals, and we do not currently respond to them. We do honour GPC as described above.
The categories above are the full set of cookies we currently use. If we add new categories, we will update this section and refresh consent before they are set.
Automated decision-making
We use automated systems to detect potential violations of our Usage Policy and to protect the Services — for example, classifiers that flag likely abuse, fraud, or attempts to elicit prohibited content. These systems may result in content being blocked, rate limits being applied, or an account being suspended.
Where an automated decision produces legal or similarly significant effects, we provide meaningful human review before the decision becomes final where practicable, and in all cases you may request human review, express your point of view, and contest the decision by contacting [email protected].
Model Outputs themselves are generated automatically and may be inaccurate. Outputs are not a decision about you, and you should not rely on them as a substitute for professional advice. Our Usage Policy restricts the use of our models for certain consequential decisions about individuals.
Children
The Services are not directed to children. You must be at least 13 years old to use the Services, or older where the law of your country sets a higher minimum age for a child to consent to the processing of their personal data — for example, 16 in some EEA member states. We do not offer a parental-consent route below these ages.
We do not knowingly collect personal data from children below the applicable age. If we learn that we have, we delete it and terminate the account. If you believe a child has provided us with personal data, contact [email protected].
Business customers are responsible for ensuring that applications they build on our API comply with laws protecting children, including COPPA and applicable age-appropriate design codes.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above. If the changes are material, we will provide additional notice — for example by email or an in-product notice — before they take effect, and where required by law we will seek your consent.
Contact us
| Privacy enquiries and rights requests | [email protected] |
|---|---|
| Enforcement appeals | [email protected] |
| Security disclosures | [email protected] |
| Postal address | Fyvie AI, Suite 1.2, 8 Elliot Street, Skypark, Glasgow, United Kingdom, G3 8EP |
General enquiries, which are not privacy requests, go to [email protected].
Region-specific disclosures
18.1 European Economic Area, United Kingdom, and Switzerland
The disclosures required by Articles 13 and 14 of the GDPR are set out above: our identity and contact details (Sections 2 and 17); the purposes and legal bases (Sections 5, 6, and 7); the categories of personal data and their sources (Section 4); recipients (Section 8); transfers and safeguards (Section 9); retention (Section 10); your rights (Section 12); and automated decision-making (Section 14).
Providing account and billing data is necessary to enter into a contract with us; without it we cannot provide the Services. Providing Inputs is voluntary, but the Services cannot function without them.
Swiss residents may also lodge a complaint with the Federal Data Protection and Information Commissioner.
18.2 California
This section supplements the rest of this policy for California residents and is provided under the California Consumer Privacy Act as amended by the CPRA.
Categories of personal information collected in the preceding 12 months.
| CCPA category | Collected | Examples | Sources | Business purposes | Disclosed to |
|---|---|---|---|---|---|
| Identifiers | Yes | Name, email, account ID, IP address, device ID | You; automatic collection; business customers; SSO providers | Service delivery, security, support, billing, communications | Service providers, affiliates, legal recipients |
| Customer records (Cal. Civ. Code §1798.80) | Yes | Name, billing address, payment information | You; payment processors | Billing, fraud prevention | Payment and fraud-prevention providers |
| Commercial information | Yes | Plan, subscription and purchase history, usage volume | You; automatic collection | Billing, support, analytics | Service providers, affiliates |
| Internet or network activity | Yes | Usage logs, API telemetry, pages viewed, interaction events | Automatic collection; cookies | Service delivery, security, analytics | Service providers, analytics providers |
| Geolocation data (approximate) | Yes | Coarse location inferred from IP | Automatic collection | Security, fraud prevention, localization, export compliance | Service providers |
| Audio, electronic, visual, or similar information | Yes | Inputs and Outputs, including any files, images, or audio you submit; support recordings | You | Service delivery, support, trust and safety | Service providers, affiliates |
| Professional or employment information | Yes | Job title, employer, CV | You; recruiting sources | Account administration, recruiting | Service providers, recruiting vendors |
| Education information | Yes, for applicants | Academic history | You; recruiting sources | Recruiting | Recruiting vendors |
| Sensitive personal information | Limited — see below | Account credentials; contents of communications; any sensitive data you choose to include in Inputs | You | Service delivery, security | Service providers |
| Inferences | Yes | Preferences and usage patterns derived from how you use the Services | Automatic collection | Service improvement, personalization | Service providers |
Sensitive personal information. We collect account log-in credentials and process the contents of your communications with our models. Any other sensitive personal information we hold is that which you choose to include in Inputs. We use sensitive personal information only for the purposes permitted by CCPA §7027(m) — performing the Service, security and integrity, and short-term transient use — and not to infer characteristics about you. Accordingly, we do not offer a separate right to limit its use, but you may exercise your other rights under Section 12.
Sale and sharing. We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined by the CCPA. We have not sold or shared the personal information of consumers under 16. We may sell or share aggregated or de-identified information that is not personal information under the CCPA; we maintain and use such information only in de-identified form and do not attempt to re-identify it, as described in Section 5.5.
Retention. We retain each category for the periods described in Section 10.
Your California rights. You have the rights to know, delete, correct, opt out of sale/sharing, limit the use of sensitive personal information, and not to be retaliated against. Exercise them as described in Section 12.
Shine the Light. California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures.
18.3 Other US states
Residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — among others, as further state laws take effect — have rights to access, correct, delete, and obtain a portable copy of their personal data, and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions producing legal or similarly significant effects. We do not sell personal data, engage in targeted advertising within the product, or conduct such profiling.
Consent is required before we process sensitive data in these states; where you include sensitive data in an Input, we treat your submission as your instruction to process it for the purpose of delivering the Service. We filter or exclude sensitive data from model-training datasets where we identify it — see Section 6.2.
Most of these states provide a right to appeal a denied request — see Section 12. Residents of Colorado, Connecticut, Montana, New Jersey, Oregon, and Texas may recognize universal opt-out mechanisms; we honour GPC as described in Section 13.
Consumer health data. The Services are not designed to collect or process “consumer health data” as defined by the Washington My Health My Data Act, Nevada SB 370, or similar laws, and we do not collect, share, or sell such data. Any health information you choose to include in an Input is processed only to deliver the Service you requested.
Nevada residents may submit a request not to have covered information sold at [email protected]. We do not sell covered information.
18.4 Other jurisdictions
Brazil. We process personal data of Brazilian residents under the Lei Geral de Proteção de Dados (LGPD), relying on legal bases equivalent to those in Section 7. You have rights to confirmation of processing, access, correction, anonymisation, deletion, portability, and information about the entities we share data with, exercisable via [email protected], which also serves as the channel to our person in charge (encarregado). You may lodge complaints with the Autoridade Nacional de Proteção de Dados (ANPD). International transfers are protected as described in Section 9.
Canada. We handle personal information of Canadian residents in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws. We obtain consent where required, and you may withdraw it subject to legal or contractual restrictions. You have rights to access and correct your personal information, and to challenge our compliance by contacting [email protected] and, if unresolved, the Office of the Privacy Commissioner of Canada. Your data may be processed outside Canada as described in Section 9.
Australia. We handle personal information of Australian residents in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). You may request access to and correction of your personal information via [email protected]. If you are dissatisfied with our response to a complaint, you may contact the Office of the Australian Information Commissioner (OAIC). We disclose personal information overseas as described in Section 9 and take reasonable steps to ensure recipients handle it consistently with the APPs.
New Zealand. We handle personal information of New Zealand residents in accordance with the Privacy Act 2020. You have rights to access and correct your personal information, exercisable via [email protected], and may complain to the Office of the Privacy Commissioner. Where we disclose personal information overseas, we rely on the safeguards described in Section 9.
Japan. We handle personal information of individuals in Japan in accordance with the Act on the Protection of Personal Information (APPI). You may request disclosure, correction, cessation of use, or deletion of retained personal data via [email protected]. We provide personal data to third parties and transfer it outside Japan only as described in this policy, implementing the measures and, where required, obtaining the consent that the APPI prescribes for cross-border transfers.
South Korea. We handle personal information of individuals in South Korea in accordance with the Personal Information Protection Act (PIPA). You have rights to access, correct, delete, and suspend the processing of your personal information, exercisable via [email protected]. Details of overseas transfer — the items transferred, destination countries, recipients, and purposes — are as described in Sections 4, 8, and 9. You may lodge complaints with the Personal Information Protection Commission (PIPC).
India. We process digital personal data of individuals in India in accordance with the Digital Personal Data Protection Act 2023. You have rights to access a summary of your personal data and its processing, to correction and erasure, to grievance redressal, and to nominate another individual to exercise your rights. Contact [email protected] in the first instance; if your grievance is not resolved, you may approach the Data Protection Board of India.