Privacy Policy

Last updated 2026-08-17. Data controller: Ellem's Towing and Transport Pty Ltd (ABN 59 667 788 892 / ACN 667 788 892). Director: Anthony Royce Ellem. Contact support@infrapriv.com for any privacy question or request.

Data we process

  • Account: email address, password hash (bcrypt), Terms acceptance timestamp and version, and the IP address from which your email address was verified
  • Google sign-in (if used): your Google account identifier and verified email address, received from Google
  • API keys: SHA-256 hash and a display prefix, never the raw key
  • Usage: model, token counts, cost, latency, status, timestamps, request ids
  • Billing: credit ledger; when you pay by card, Stripe customer, session and invoice references; for large card top-ups, Stripe Identity verification status and related session identifiers if that check is enabled
  • Support: ticket subjects and the message bodies you send us
  • Email verification and password reset tokens, which expire and are single-use
  • Diagnostics: server error records, which may include the account id associated with a failed request. These never contain prompt or response content

Data we do not store

API requests (chat completions, embeddings) are proxied to the inference backend and never written to our database. We keep only the resulting token counts, needed to bill you. Card numbers are handled by Stripe Checkout and never reach our servers.

Two features are deliberate exceptions, both under your control: the dashboard playground stores your conversation so you can resume it, and the Batch API stores queued job content until it runs. Both are deletable from your account and included in your data export.

Your IP address is used transiently, in memory, to rate limit sign-in and API requests, and is not written to our database, with one exception: we record the IP address from which your email address was verified (or from which you first signed in with Google), once, to help prevent fraud and to document account ownership if a payment is disputed. Our hosting provider keeps standard request logs.

Cookies and local storage

We use no analytics, advertising or tracking cookies, and load no third-party scripts. Visiting without signing in does not set cookies. Your browser may keep a local theme preference (ip-theme) so the page does not flash on reload; that value never leaves your device. Because the two cookies below are strictly necessary to provide a service you asked for, they do not require consent under the ePrivacy Directive, and we therefore show no cookie banner.

  • ip_session — keeps you signed in. HttpOnly, Secure, SameSite=Lax. Expires 30 days after it is issued, or immediately when you log out
  • ip_oauth_state — set only during Google sign-in to prevent request forgery. Expires after 10 minutes and is deleted as soon as sign-in completes

Signed in, your browser also stores small interface preferences locally (whether you dismissed the setup guide, which language tab you last used in the docs). These stay on your device, are never sent to us, and clearing your browser data removes them.

Why we process it, and our legal basis

  • To provide the service — authenticating you, metering usage, billing, and support. Legal basis: performance of our contract with you (GDPR Art. 6(1)(b))
  • To keep the service safe — rate limiting, abuse and fraud prevention, diagnosing errors. Legal basis: our legitimate interests in operating a secure service (Art. 6(1)(f))
  • To meet legal duties — tax, accounting and financial record keeping. Legal basis: legal obligation (Art. 6(1)(c))

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train models.

Subprocessors

  • Railway: application hosting and PostgreSQL database (United States)
  • Stripe: payment processing, invoices, receipts, tax ID collection, and (for card top-ups of US$1,000 or more, when that check is enabled) identity document verification via Stripe Identity — only once card payments are switched on
  • Resend: transactional and support notification email
  • Google: sign-in identity, only if you choose to sign in with Google
  • GitHub: optional encrypted off-site database dumps, when that job is configured. Dumps are encrypted with a key GitHub does not hold, and are retained for 30 days
  • Operator-controlled GPU hosts: inference compute

Retention

Account and usage data are kept while your account is active. When you delete your account, conversation and queued batch content is erased, and personal identifiers are removed from the remaining records. Financial records are retained in anonymised form to meet applicable tax and accounting obligations. Where encrypted off-site dumps are configured, they age out after 30 days, so a deletion propagates fully within that window.

Your rights

From your dashboard you can export all of your data as JSON and delete your account yourself, at any time, without contacting us. You may also email support@infrapriv.com to access, correct, or delete your information, or to object to or restrict processing.

If you are in Australia, you may complain to the Office of the Australian Information Commissioner (OAIC). If you are in the EEA or UK, you additionally have the right to data portability and to lodge a complaint with your local supervisory authority. If you are in California, you have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for exercising those rights; as noted above we do not sell or share personal information. You may also complain to a relevant privacy or data-protection regulator if you are unsatisfied with our response.

Data breaches

If a breach of personal information occurs that is likely to result in serious harm, we will notify affected individuals and any regulator we are obliged to notify.

International transfers

The operator and subprocessors may run in more than one region. Where personal data is transferred out of the EEA or UK, that transfer relies on the standard contractual clauses offered by the subprocessor. If you need a signed data processing agreement, contact support@infrapriv.com.

Changes

We will update the date at the top of this page when this policy changes, and will notify account holders by email of any change that materially affects your rights. Governing law references: Queensland, Australia.

Related: Security, Terms.