Privacy
Alma Mater PLC (India) is the data controller. This page covers the Digital Personal Data Protection Act 2023 in India and the GDPR where it applies.
What we hold
Your email address. It is how you sign in. There is no password — you get a link by email — so there is no password of yours for anyone to steal from us.
Your requests and the answers to them, along with the record of which model contributed what. This is your run history, and it is the thing you are paying for.
Your workspace and billing status — which plan you are on and how many runs you have used this period.
Counters for rate limiting. Keyed on your user id, and on a salted one-way hash of your IP address. We do not store IP addresses. The hash uses a secret key held only on our servers, so the hash cannot be turned back into an address.
What we do not hold
Card numbers. Those go to Razorpay directly and never touch our servers.
Raw IP addresses, as above.
Error reports
When something breaks, an error report goes to Sentry in Germany. It carries the error type and the line of code. It does not carry your request text, your email, or anything about your account balance — the report is stripped to a fixed list of allowed fields before it is sent, and anything not on that list is dropped rather than reviewed.
Who else sees your data
The companies on the sub-processors page, and no one else. That page says what each one receives and which country it processes it in. Your requests are processed in the United States by the model providers, and stored in Singapore.
We make no claim about whether model providers train on your text. Their terms differ per model and change, so we will not promise something we cannot keep true.
How long
Your runs stay until you delete them or close your account. Rate-limit counters expire within thirty days. Backups age out on their own schedule.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it — by email, at the address on the contact page. Deleting a run deletes it properly; there is no soft-delete flag anywhere in the database.
Under DPDP you may also nominate someone to exercise these rights if you cannot. Under GDPR, if you are in the EU or UK, you may complain to your supervisory authority.
Children
This is a paid business product and is not intended for anyone under 18.