Home/Legal & Policies/Privacy Policy
Inferel Privacy Policy
This Privacy Notice explains how Inferel AI Inc, and its affiliates and subsidiaries (collectively "Inferel", "we", "us" or "our") collects, uses, discloses, and otherwise processes personal data (as defined below) in connection with our website https://www.inferel.ai/ (the "Site"), and related content, services, products, and other functionalities offered on or through our services (collectively, the "Services"). This Privacy Notice is not a contract and does not create any legal obligations.
Please read this Policy carefully. By accessing or using our Services, you acknowledge and agree to the data collection and processing practices described herein. This Policy forms an integral part of, and is incorporated into, our Terms of Service.
1. Core Enterprise AI Data Commitments
To earn the trust of corporate tenants and open-source developers alike, Inferel adheres to the following principles regarding your inputs, prompts, and custom fine-tuned weights:
- No AI Training Without Your Opt-In: Inferel will not use your private User Content, API inputs, prompts, code, images, or resulting Outputs to train, retrain, improve, or evaluate Inferel's public base models or any third-party models without your explicit, opt-in consent. Unless you affirmatively elect to participate, your data is utilized solely to execute your real-time inference or requested fine-tuning jobs. Where you do opt in, you may withdraw that consent at any time, and the withdrawal will apply prospectively to data processed after the withdrawal takes effect.
- Workspace Isolation and Control: By default, your fine-tuning datasets and resulting Custom Model Weights are mathematically isolated, encrypted, and siloed within your dedicated workspace. You retain complete control over these assets and may download or permanently delete them via the platform console at any time.
- Transparency in Community Sharing: Your models and datasets remain strictly private unless you explicitly, voluntarily toggle their visibility settings to "Public" to contribute them to the Inferel open-source community repository.
Inferel as a Data Processor. In certain enterprise deployments, Inferel processes personal data solely on behalf of, and under the documented instructions of, a corporate customer — for example, when your employer or organization provisions your access to a workspace. In those situations, Inferel acts as a data processor (or "service provider") for that customer, the customer is the data controller, and this Policy does not govern that processing. We recommend you review the privacy policy of the relevant customer, which controls how your personal data is handled in that context. Where Inferel processes personal data on a customer's behalf, that processing is governed by a separate Data Processing Addendum (DPA) rather than by this Policy.
2. What Is Personal Data?
When we use the term "personal data" (or "personal information") in this Policy, we mean any data or information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular natural person or household. The categories of personal data we process are described in Section 3 below.
Where we process data that has been aggregated, anonymized, or de-identified such that it can no longer reasonably be used to infer information about, or be linked to, a particular individual or household, we maintain and use such data only in de-identified form and do not attempt to re-identify it, except where necessary to verify that our de-identification process satisfies the requirements of applicable law.
3. Information We Collect
We collect information that you provide to us, data generated automatically through your system interactions, core operational data related to AI service execution, and certain information obtained from other sources.
3.1 Information You Provide to Us
- Account and Authentication Data: When you create an account, build a corporate workspace, or provision Service Accounts, we collect your name, email address, corporate/organization name, job title, and cryptographic account credentials.
- Billing and Financial Data: If you utilize paid tier APIs, run fine-tuning jobs, or lease dedicated GPU instances, billing data (such as credit card metadata, billing address, and corporate tax identifiers) is processed through our third-party payment gateways (e.g., Stripe). We do not store full credit card numbers on our infrastructure.
3.2 Information Automatically Collected (System Logs & Telemetry)
When you log in or interact with our control panel, our systems log standard network activity data, including:
- Device and Browser Information: Internet Protocol (IP) address, browser type, operating system version, domain servers, and referring URLs.
- Session Security Telemetry: Authentication timestamps, session duration, clickstream data within the platform interface, and API token origin verifications.
3.3 AI Operational and Runtime Data
- User Content (Inputs) and Outputs: To process your real-time requests, our infrastructure temporarily handles the prompts, tokens, text, code, or data sheets you submit, along with the corresponding generated responses or model parameters.
- API Metadata: We record the metadata of every API transaction, including the targeted model identifier, input token volume, output token volume, transaction latency, HTTP error codes, and compute hours consumed.
3.4 Information Collected From Other Sources
We may also obtain information about you from outside sources, including information we collect directly from third parties and information that third parties share with us. Such information includes:
- Authentication and SSO Services: If you log in through a third-party authentication or single sign-on provider (e.g., Okta), that service authenticates your identity and may share certain personal data with us, such as your name and email address, in accordance with that provider's policies and your settings.
- Your Employer or Organization: If you access the Services through your employer or organization (for example, via an enterprise login or workspace administrator), we may receive your information from that organization or its representatives in order to provision and administer your access.
- Service Providers and Business Partners: Our service providers and infrastructure partners may collect and share information with us in connection with operating, securing, and supporting the Services.
4. How We Use Your Information
We process your data for the following legitimate commercial and operational purposes:
- Service Provision and Execution: To maintain your account, authenticate API calls, route inference requests across our network, spin up dedicated GPU resources, and execute complex model fine-tuning commands.
- Billing, Accounting, and Metering: To accurately calculate consumption charges based on your input/output token usage or hardware allocation times, issue invoices, and prevent transaction fraud.
- Infrastructure Security and Debugging: To monitor technical logs for high-frequency abusive API calls (DDoS), investigate system errors or software bugs, prevent malicious reverse-engineering attempts, and optimize low-latency network performance.
- Community Management: To host, display, and distribute custom fine-tuned models, weights, or datasets that you voluntarily elect to publish to the public Inferel Community Repository.
- Communications: To send you service and transactional messages, respond to your inquiries and support tickets, and — where permitted by law and consistent with your preferences — share product updates, new features, or other information that may be of interest to you. You can control marketing communications as described in Section 13 below.
- Legal Compliance: To meet legal auditing requirements, respond to subpoena requests, or enforce our regulatory obligations.
5. Cookies and Other Tracking Technologies
We and our service providers use cookies and similar tracking technologies (such as web beacons, embedded scripts, and local storage) to operate, secure, and analyze the Services. We primarily use these technologies for strictly necessary functions — including authenticating your session, maintaining login state, enforcing security, and remembering your console preferences — and for first-party analytics that help us understand and improve platform performance.
Most browsers accept cookies automatically, but you may be able to control how your device permits the use of tracking technologies. You can block or delete cookies through your browser settings or limit cross-site tracking; however, blocking or deleting cookies may cause some features or general functionality of the Services to work incorrectly. To opt out of analytics collected through Google Analytics, you may use the opt-out tools made available by the relevant provider.
Our Services are designed for enterprise and developer use and do not serve interest-based or third-party behavioral advertising. We do not sell your personal data, and we do not share it with advertising networks for cross-context behavioral advertising. Because industry standards for "Do Not Track" signals are not yet uniform, our Services do not currently respond to such signals.
6. Data Retention Policy
Inferel retains your information for as long as is reasonably necessary to fulfil the purposes described in this Policy. When determining the appropriate retention period for any category of data, we consider the nature and sensitivity of the data, the purposes for which we process it, whether those purposes can reasonably be achieved by other means, and any applicable legal, regulatory, tax, accounting, billing, dispute-resolution, or security obligations to which we are subject.
By way of general guidance:
- Prompt and Output Content: The content of your prompts, inputs, and generated Outputs is processed to fulfil your request and is retained only for as long as reasonably necessary to provide the Services. The specific retention behavior for prompt and output content depends on the model and plan you use, and certain models and configurations retain little or no prompt or output content in persistent storage. Further detail is available in our technical documentation.
- Account Profile and Registration Data: Maintained for as long as your Inferel account remains active and thereafter for as long as reasonably necessary to satisfy our legal, financial, and record-keeping obligations, after which it is scrubbed or anonymized from our production environments.
- Private Fine-Tuning Assets: Uploaded training datasets and generated Custom Model Weights are retained within your secure workspace for as long as you maintain them there, and are deleted when you remove them via the dashboard or when reasonably necessary following termination of your subscription.
- Operational Logs and API Metadata: System network logs, IP login histories, and API metadata are retained for as long as reasonably necessary to facilitate billing dispute resolution, technical debugging, fraud prevention, and platform security auditing, after which the data is overwritten, purged, or irreversibly anonymized.
Account Deletion. Upon a verified account deletion request, Inferel will delete or irreversibly anonymize your personal data from our production systems within thirty (30) days, except for information we are required or permitted to retain for legal, tax, accounting, billing-dispute, fraud-prevention, or security purposes, which we retain only for as long as reasonably necessary for those purposes.
Where we are no longer permitted to process your information, we will either delete it or de-identify it so that it can no longer be associated with you.
7. Data Sharing and Disclosure
Inferel does not sell, rent, or trade your personal data or AI content to third parties. We disclose data only under the following limited conditions:
- Authorized Service Providers: We share data with third-party vendors who provide fundamental infrastructure operations, including cloud hosting providers (e.g., AWS, GCP), identity verification providers, automated transaction email handlers, and financial gateways (e.g., Stripe). These sub-processors are legally bound to protect your data under confidentiality standards equivalent to this Policy.
- Community Publication: If you explicitly configure a fine-tuned model or dataset as "Public" within the platform, that asset along with your username and description parameters will be visible and downloadable to all global users within the Inferel Open Community.
- Transparent Routing Layer Execution: When you invoke external open-source or commercial third-party models via our platform, native safety or content checks built into those models by their original creators (e.g., Llama Guard) execute automatically. We act as a pass-through layer and do not transmit your data to third-party providers for their model training.
- Corporate Transactions: If Inferel is involved in a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, your information may be disclosed or transferred to the counterparties and their advisors as part of that transaction, subject to confidentiality protections and applicable law.
- Legal and Safety Mandates: We may disclose information if required to do so by law, or in the good-faith belief that such action is necessary to comply with legal processes, protect the personal safety of users, or defend the intellectual property rights and assets of Inferel.
8. International Data Transfers
Inferel's compute infrastructure and data repositories are primarily located in the United States. If you are accessing our Services from jurisdictions outside the United States (such as the European Union, the United Kingdom, Taiwan, or other regions), please note that the information we collect will be transferred to and processed in the US. We utilize appropriate cross-border data transfer mechanisms, such as the Standard Contractual Clauses (SCCs) and any equivalent safeguards required by the relevant authority, to guarantee that your data receives a comparable level of regulatory protection.
9. Data Security and Infrastructure Safeguards
We implement industry-leading technical and organizational security controls to shield your information:
- Encryption Architectures: All data is securely encrypted both in transit (using TLS 1.3/HTTPS protocols) and at rest (utilizing enterprise-grade AES-256 encryption keys).
- Multi-Tenant Logical Isolation: Your private custom models, weights, and workspace configurations are strictly separated at the cloud infrastructure and data storage level, preventing data bleeding or cross-tenant visibility.
- Internal Access Controls: We enforce the Principle of Least Privilege. Inferel engineering and maintenance staff are barred from accessing your private text prompts, inputs, or generated weights unless explicitly authorized by you in writing to resolve a specialized support ticket.
Despite these measures, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and should notify us promptly if you believe your account has been compromised.
10. Children's Personal Data
Our Services are intended for enterprises, developers, and other professional users and are not directed to children. We do not knowingly collect or solicit personal data from children under the age of 16 (or under the age of 13 where that lower threshold applies under local law). If a child below the applicable age has provided personal data to us, we encourage the child's parent or guardian to contact us. If we learn that we have collected personal data from a child below the applicable age without verified parental consent, we will promptly delete that information from our systems.
11. Notice for U.S. State Residents
This section supplements the rest of this Policy and applies to residents of California and other U.S. states that have enacted comprehensive privacy laws (such as the California Consumer Privacy Act, as amended by the CPRA). For purposes of this section, references to "personal information" include "sensitive personal information" as defined under applicable law.
11.1 Categories Collected and Disclosed
In the preceding 12 months, we have collected and, for the business purposes described in this Policy, disclosed the following categories of personal information:
- Identifiers, such as name, email address, and IP address;
- Customer records information, such as billing address and corporate tax identifiers;
- Commercial information, such as records of services purchased and usage history;
- Internet or network activity, such as system logs, API metadata, and clickstream data;
- Geolocation data inferred from IP address;
- Professional or employment-related information, such as job title and organization; and
- Account access credentials (treated as sensitive personal information).
The sources of this information and the purposes for which we use and disclose it are described in Sections 3, 4, and 7 above.
11.2 No Sale or Sharing of Personal Information
We do not "sell" or "share" (as those terms are defined under applicable U.S. state privacy laws) your personal information, and we have not done so in the preceding 12 months. We do not knowingly sell or share the personal information of individuals under 16 years of age.
11.3 Exercising Your Rights
Subject to the limits of applicable law, U.S. state residents may exercise the rights described in Section 12 below. We will not discriminate against you for exercising these rights. You may use an authorized agent to submit a request, in which case we may require proof of authorization and may still ask you to verify your identity directly.
11.4 Protection of Children's Privacy
The Company is committed to protecting the privacy of children. The Site is not directed to children under the age of 13, and we do not knowingly collect personal information from children under the age of 13. If we become aware that we have inadvertently collected personal information from a child under 13 years of age, we will take prompt steps to delete such information from our records.
12. Your Privacy Rights and Choices
Depending on your geographic location and local data protection regulations (such as the GDPR, UK GDPR, or U.S. state privacy laws), you may possess some or all of the following rights regarding your personal information. These rights are not absolute, and in certain cases we may decline a request as permitted by law.
- Right of Access / Know: You may request access to the personal information we hold about you, or information about how we collect, use, and disclose it. You can also view and audit much of this directly via your account management dashboard.
- Right to Rectification / Correction: You may request that we correct inaccurate or incomplete personal information we maintain about you, and you can update many registration settings yourself in the dashboard.
- Right to Erasure (Right to be Forgotten): You may request the permanent deletion of your profile, private datasets, and account footprint by initiating an account closure request.
- Right to Data Portability: You may request a copy of the personal information you have provided to us in a structured, commonly used format, and, where technically feasible, request that we transmit it to another controller.
- Right to Restrict Processing: You may request that we restrict or suspend the processing of your personal information in certain circumstances. You may also withdraw authorization for public community sharing at any time; once a model is marked private or deleted, it will be removed from our repository interface (though we cannot alter or retrieve copies previously downloaded by downstream community users prior to your removal).
- Right to Object: You may object to certain processing of your personal information, including processing carried out on the basis of our legitimate interests.
- Right to Withdraw Consent: Where we rely on your consent (including any opt-in to model training), you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, please contact our Privacy Team using the details in Section 17. We may need to verify your identity before responding, for example by confirming control of your registered email address. If we decline your request, you may appeal that decision by contacting us using the same details.
13. Communications and Marketing Preferences
We may send you two categories of communications, and you can control them as follows:
- Service and Transactional Communications: Messages that are necessary to operate the Services — such as account verification, security and login alerts, billing and invoice notices, support responses, and notices of material changes to this Policy or our Terms of Service. Because these communications are necessary to provide the Services, you cannot opt out of them while you maintain an active account.
- Product and Marketing Communications: Where permitted by applicable law, and subject to your consent where required, we may occasionally send you information about new features, products, or services that may be of interest. You can opt out of these communications at any time by using the "unsubscribe" link in the relevant email, adjusting the notification settings in your developer console, or contacting our Privacy Team. Opting out of marketing communications will not affect service or transactional communications.
Because our Services are built for enterprise and developer use and do not deliver interest-based or third-party behavioral advertising, there are no advertising-tracking preferences for you to manage. For information about cookies and analytics, see Section 5 (Cookies and Other Tracking Technologies).
14. Links to Third-Party Websites and Services
Our Services may contain links to, or integrations with, third-party websites, models, plug-ins, and applications that we do not own or operate. We are not responsible for the privacy practices or content of those third parties. This Policy does not apply to your interactions with any third-party website or service, which are governed by that third party's own terms and policies. We encourage you to review those policies before providing any personal data.
15. Complaints
If you have a complaint about how we process your personal information, please contact our Privacy Team using the details in Section 17, and we will endeavour to resolve it. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with a data protection authority, you also have the right to lodge a complaint with your local supervisory authority. We would, however, appreciate the opportunity to address your concerns directly before you approach the regulator.
16. Amendments to this Privacy Policy
Inferel reserves the right to modify or update this Privacy Policy at its discretion. When material changes occur, we will update the "Last Updated" date above and provide conspicuous notice — for example, within our developer console, by presenting a click-to-accept prompt upon your next platform login, or by sending an update to your registered email address. Your continued interaction with the Services following the effective date of the updated Policy constitutes your acknowledgement and acceptance of those modifications.
17. Contact Information
If you have questions, feedback, or data privacy complaints regarding this Policy or our data management operations, please reach out to us at: support@inferel.ai

