Skip to content

Legal

Privacy Policy

Last updated

Sections

This Privacy Policy explains how Tensorant ("Tensorant", "we", "us" or "our") collects, uses and shares information when you use the Tensorant website, console, API and related services (the "Service"). It should be read together with our Terms of Service.

In short: we collect what we need to run your account, your organization and your bill. The content you train on and the prompts you send are yours. When you connect your own GPU cloud and storage, your content is stored in your accounts, not ours. We do not store the prompts or answers that pass through the API or the Playground, we do not sell personal data, and we do not use your content to train models.

1. Information we collect

Account information. Your name, email address and the sign-in method you choose (email and password, an email code, or a supported single sign-on provider). Passwords and sign-in sessions are handled by our authentication provider; we never see or store your password. If you answer the optional onboarding questions, we keep your answers (for example, what you came to Tensorant for and your role).

Organization information. Organization and project names, members, their roles, and invitations you send.

Billing information. Your plan, subscription status, billing email and organization name. Card and payment details are collected by our payment partner; we never receive your full card number.

Connection credentials. API keys and access keys you give us for your GPU cloud, storage, model hubs or text generation endpoints. They are encrypted at rest, used only to act on your instructions, and shown back only as their last four characters.

Your content. The documents, datasets, examples, images, evaluation results and model adapters you upload, import, create or train. See section 2 for where it is kept.

Usage and service data.

  • For each API key, model and day: counts of requests, errors, prompt and completion tokens, and response times. These numbers power your usage view and plan limits. We do not store the prompts or answers sent through the API or the Playground.
  • An audit trail of changes made in your organization (who did what, when, and from which IP address), which your organization's owners can see.
  • Records of jobs, training runs, deployments and their running time and cost, so you can follow and control them.

Product analytics. Which pages of the console and website are visited, and which features are used, linked to an account and organization ID. Event details are counts and yes/no values. Analytics never include your content, prompts, names or email addresses, and we remove query strings and sign-in or invitation tokens from addresses before they are recorded. We do not record sessions or keystrokes.

Cookies and similar technologies. See section 7.

2. Where your content lives

Where your content is kept depends on how your organization is connected:

  • Your own connections. When you connect your own GPU cloud and storage, your documents, examples, datasets, evaluation results, images, adapters and checkpoints are written to your storage, and training and serving run in your GPU cloud account. Our database keeps the information needed to organize and run that work: names, file names, review states, versions, settings, statuses, metric summaries and references to the stored files. Your content passes through our servers while it is imported, reviewed, trained or served, but it is not kept there.
  • Platform-provided connections. Where your plan or setup uses compute or storage that we provide, your content is stored on infrastructure we operate, and some text (for example examples and evaluation answers) may be stored in our database.

Content you choose to send to third parties, for example by importing from or publishing to a public model hub, or by using a text generation endpoint to create or judge examples, is handled by those services under their own terms.

3. How we use information

We use information to:

  • provide, operate and secure the Service, including signing you in, running the work you start and stopping resources when it ends;
  • show usage, enforce plan limits and process billing;
  • respond to support requests and send service messages, such as invitations, billing notices and important changes;
  • understand how the Service is used so we can improve it, using the product analytics described above;
  • detect, investigate and prevent abuse, fraud and security incidents; and
  • comply with legal obligations and enforce our Terms.

We do not sell personal information, we do not use it for targeted advertising, and we do not use your content to train our own models or models for anyone else.

Where the GDPR or similar laws apply, we rely on performance of our contract with you, our legitimate interests in running and improving a secure service, compliance with legal obligations, and your consent where it is required.

4. How we share information

We share information only as follows:

  • Service providers that process data for us under contractual obligations, for hosting and databases, authentication, payment processing, product analytics and email delivery. They may use the information only to provide their services to us.
  • Providers you connect, such as your GPU cloud and storage accounts, model hubs and text generation endpoints, as needed to carry out the work you request.
  • Your organization. Members of your organization can see the organization's projects and activity according to their roles. Owners can see the audit trail.
  • Legal reasons. When required by law or legal process, or when needed to protect the rights, property or safety of Tensorant, our customers or others.
  • Business transfers. As part of a merger, acquisition or sale of assets, subject to this Privacy Policy.

5. Retention

  • Account and organization data is kept while your account is active and deleted or anonymized after you ask us to close it, except where we must keep it for legal, tax, billing or security reasons.
  • Project content. When an owner deletes a project, its records are removed from our database at once and the files we can reach in connected storage are removed shortly after. Content already published to third parties, or kept in storage that is no longer connected, is not affected.
  • Usage counts and the audit trail are kept for as long as your organization exists, to support billing, security and your own records.
  • Backups of our database are kept for up to 90 days and then overwritten.
  • Content in your own Connected Providers stays under your control and is kept or deleted according to your settings with those providers.

6. Security

We protect information with access controls by organization and role, encryption in transit, encryption at rest of the credentials you give us, and audit logging of changes. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Keep your sign-in details and API keys safe, and contact us if you believe they were exposed.

7. Cookies and local storage

  • Essential cookies keep you signed in and protect sign-in. The Service does not work without them.
  • Preferences such as your theme, sidebar layout and Playground settings are kept in your browser's local storage. Playground conversations stay in your browser tab.
  • Analytics cookies help us understand how the website and console are used, as described in section 1.

You can block or delete cookies in your browser settings. Blocking essential cookies will prevent you from signing in.

8. International transfers

The Service is hosted in the United States. If you use the Service from another country, your information is transferred to and processed in the United States. Where required, we rely on appropriate safeguards, such as standard contractual clauses, for these transfers. Content you keep in your own Connected Providers stays in the regions you choose with them.

9. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. You can update your name and email in the console. To exercise any other right, email [email protected]. We will respond within the time required by law and will not discriminate against you for exercising your rights. You may also complain to your local data protection authority.

If your organization uses Tensorant to process personal data about other people, your organization decides how that data is used and is responsible for those people's requests. We will help where we can.

10. Children

The Service is not intended for anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has given us information, contact us and we will delete it.

11. Changes to this policy

We may update this Privacy Policy. If a change is material, we will notify you by email or in the console before it takes effect. The date at the top shows when it was last updated.

12. Contact

Questions or requests about privacy: [email protected].