Legal — privacy
Privacy Policy
Version 1.2 · Last updated September 21, 2026 · Owner: Cyphra
In brief
This policy explains what personal data Cyphra collects, why, how long we keep it, who we share it with, and your rights. US privacy law is our primary frame; EEA/UK rights appear as conditional sections. Read it together with our Terms & Conditions, Data Processing Addendum, and Cookie Policy.
1. Who we are and what this policy covers
1.1 Cyphra LLC ("Cyphra", "we", "us"), New Jersey, USA, operates the Platform: managed cloud instances of an AI agent runtime ("Agent Instances"). This policy applies to every surface on which we collect personal data: the browser chat interface ("Web Interface", including its use through mobile browsers), the instance management console ("Control Panel"), and the plans, orders, invoices, and payments portal ("Billing Portal").
1.2 For account, billing, and support data we act for our own purposes; for Customer Content we act on our customer's instructions. Section 4 explains this split.
1.3 This policy is governed by the State of New Jersey, without regard to conflict-of-laws principles; questions go to [email protected] (Section 15).
2. Summary of our data practices
2.1 The table below is a plain-English summary; the detailed sections control if they conflict.
| Data | Purpose | Lawful basis | Retention | Shared with |
|---|---|---|---|---|
| Account data (name, email, credentials) | Create and operate your account | Contract | Account life + 30 days | Subprocessors (hosting, support tooling) |
| Billing status data (plans, invoices, payment status) | Orders, invoices, renewals; taxes | Contract; legal obligation | As tax and accounting law requires — generally at least seven years for accounting records, or longer where the law sets it | Payment gateway; accounting subprocessors |
| Technical/usage data (logs, IPs, device info, push tokens) | Security, availability, troubleshooting, notifications | Legitimate interests (security and operation) | Up to 12 months; shorter where practicable | Hosting and CDN/security subprocessors |
| Support communications | Answer tickets and requests | Contract; legitimate interests | Ticket closure + up to 24 months | Support tooling subprocessors |
| Customer Content (prompts, uploads, agent memory/configuration, AI outputs) | Provide and operate your Agent Instance at your direction | Contract (as processor, on your instructions) | Account life; deleted within 30 days after termination | Upstream model providers if using Cyphra-provided model access (Section 5); Subprocessor List |
3. Data we collect
3.1 Account data. When you register through the Billing Portal or Control Panel, we collect your name, email address, account credentials, account identifiers, and account status records such as plan, order, invoice, and renewal data ("Customer Data").
3.2 Billing status data. We collect billing status data: what you ordered, what you were invoiced, whether a payment succeeded or failed, and related tax and accounting records. Full card numbers never touch Cyphra systems. Card data is collected and processed entirely by a third-party payment gateway inside a gateway-hosted checkout within the Billing Portal; Cyphra receives only payment status and gateway references. We make no PCI certification claim; card data is handled entirely by the gateway.
3.3 Technical and usage data. We collect infrastructure and service logs, IP addresses, device and browser information, session records, and crash reports needed to secure and operate the Platform. The Cookie Policy describes how web identifiers are managed.
3.4 Support communications. If you contact us at [email protected] or through in-product support, we collect your contact details, account identifiers, and the content of your messages, including attachments.
3.5 Customer Content. Your Customer Content — prompts, uploads, agent memory and configuration, and AI outputs stored in your Agent Instance — is stored and processed at your direction. You own it, and where features allow you can export it through the Web Interface at any time.
3.6 We do not collect sensitive categories of personal data (such as government identifiers or precise geolocation), except where you place such data in your own Customer Content, your responsibility under our Acceptable Use Policy.
3.7 Mobile information. If you opt in to service texts from your agent, we collect your mobile phone number solely to send the messages you consented to. We will not share your mobile information with third parties for marketing purposes.
4. Our dual role: controller for account data, processor for Customer Content
4.1 Controller. For Account Data (account and billing data), technical and usage data, and support communications, Cyphra is the data controller: we decide why and how that data is used.
4.2 Processor. For Customer Content, Cyphra is a data processor acting on our customer's documented instructions. When you place personal data in your Customer Content, you are responsible for having a lawful basis for it, and we process it only to provide and secure your Agent Instance. The detailed allocation of responsibilities — instructions, confidentiality, subprocessing, assistance, audit, and deletion — is set out in our Data Processing Addendum, which is incorporated into our Terms & Conditions and controls for processor-role matters.
4.3 As processor, we direct data-subject requests about Customer Content to the controlling customer and assist them in responding, as the DPA requires.
5. Model providers, BYOK, and Customer Content
5.1 Cyphra-provided model access. When you use model access provided by Cyphra, your prompts and resulting outputs are routed to and processed by upstream model providers to generate a response, under those providers' own privacy policies and terms, as disclosed in our AI & Model Provider Disclosures. The providers currently routed to are listed in our Subprocessor List. If we add or materially change a routed provider, we update the Subprocessor List and give notice as it describes, so that this section, the Subprocessor List, and our AI & Model Provider Disclosures stay consistent.
5.2 BYOK. If you supply your own API keys ("BYOK"), requests go directly from your Agent Instance to the provider you chose: a direct relationship between you and that provider. Cyphra never sees your provider-side usage, your prompts and outputs remain your Customer Content, and you are responsible for that provider's terms and your keys. BYOK keys are encrypted at rest, never logged, and remain your property.
5.3 No model training. Cyphra does not train models on Customer Content: we do not use your prompts, uploads, memory, configuration, or outputs to train, fine-tune, distill, or improve any model of ours or any third party's, including when you use Cyphra-provided model access. How each upstream provider handles prompts and outputs is disclosed in our AI & Model Provider Disclosures, which we keep current as providers' terms change. We use only aggregated, non-identifying telemetry (uptime and capacity metrics) to operate the Platform; it is not Customer Content and is never used to train models.
6. How we use data and our lawful bases
6.1 We use Account Data, technical and usage data, and support communications to: create and operate your account; provision, patch, and operate your Agent Instance; process orders, invoices, renewals, and refunds; deliver service and security notifications; detect and prevent fraud, abuse, and security incidents; enforce our agreements, including our Acceptable Use Policy; respond to support and legal requests; comply with law, including tax, accounting, sanctions, and export-control obligations; and improve and secure the Platform.
6.2 If you are located in the EEA or the UK, our lawful bases for that processing are: (a) contract — processing needed to provide the Services under our Terms & Conditions (Art. 6(1)(b) GDPR); (b) legitimate interests — platform security, fraud and abuse prevention, enforcement of our agreements, and service improvement, balanced against your rights (Art. 6(1)(f) GDPR); (c) legal obligation — tax, accounting, sanctions, and law-enforcement compliance (Art. 6(1)(c) GDPR); and (d) consent — for optional processing where we ask for it (Art. 6(1)(a) GDPR). You may withdraw consent at any time via [email protected], without affecting processing already carried out. For Customer Content, our customer is the controller and we process on their instructions per Art. 28 GDPR.
6.3 For US users, we process personal data for the purposes above and, where a specific state law applies, per the rights in Section 7.
7. Your US privacy rights
7.1 California (CCPA/CPRA). If you are a California resident, you have the rights to know, delete, and correct personal information, and to opt out of its sale or sharing, per Cal. Civ. Code § 1798.100 et seq. We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We do not process consumers' personal information under 16 for such purposes without affirmative authorization, and we will not discriminate against you for exercising these rights. We have not performed a formal CCPA threshold analysis, so we do not assert whether that statute's applicability thresholds are met; the commitments in this section are extended to US residents as a matter of good practice, regardless of thresholds.
7.2 Other US states. Several US states have comprehensive consumer privacy statutes with comparable rights — to know/access, delete, correct, and port data, to opt out of targeted advertising or profiling in certain circumstances, and to appeal a denied request. We have not performed a state-by-state applicability analysis and do not claim this policy satisfies any specific statute. We honor these rights for US residents as good practice, and we will meet the specific requirements of any statute that applies to us as we scale. Because we do not sell or share personal information (Sections 7.1 and 11.4), the opt-out rights in these statutes do not change how we process your data.
7.3 New Jersey. The New Jersey Data Privacy Act applies to businesses above statutory consumer-volume thresholds; we have not performed an applicability analysis and do not claim it applies to us. We honor its operative rights — access, deletion, correction, portability, and opt-outs — for New Jersey residents as good practice. Our breach-notification commitments to New Jersey residents are in Section 10.2.
7.4 To exercise a US state right, contact [email protected] (Section 15). We verify requests via account identifiers and respond per Section 15. If we deny a request, we will explain why and, where the law provides one, how to appeal.
8. If you are located in the EEA or the UK
8.1 If you are located in the European Economic Area (EEA) or the United Kingdom (UK), you have the following rights under the EU GDPR and the UK GDPR, in the circumstances those laws provide: access — confirmation that we process your personal data and a copy of it (Arts. 15 and 21 GDPR equivalent); rectification — correction of incomplete or inaccurate data (Art. 16 GDPR equivalent); erasure — deletion where retention is no longer necessary or a ground applies (Art. 17 GDPR equivalent); restriction — restricted processing while a dispute about accuracy or grounds is resolved (Art. 18 GDPR equivalent); portability — data you gave us, on the basis of contract or consent, in a structured, commonly used, machine-readable format (Art. 20 GDPR equivalent); objection — to processing based on legitimate interests, on grounds relating to your situation, and to direct marketing at any time (Arts. 21 and 22 GDPR equivalent); and complaint — to your local supervisory authority, or in the UK the Information Commissioner's Office.
8.2 These rights are not absolute; exceptions apply, e.g. where processing is needed to comply with a legal obligation or defend legal claims. End-user requests about Customer Content are handled per Section 4.3.
8.3 Cyphra operates the Platform from New Jersey, USA; Section 12 describes the transfer safeguards applying to your data.
9. Retention
9.1 We keep personal data only as long as needed for the purposes in this policy, plus any longer period the law requires.
9.2 Account Data is kept for the life of your account; billing status data as long as tax and accounting law requires (Section 2); technical and usage data for the retention windows in Section 2; and support communications for the window in Section 2 so we can maintain a service history.
9.3 Customer Content is kept for your account life. After termination it is deleted within 30 days, and backups containing it purged within 14 days of the last backup cycle. This matches the deletion and backup mechanics in Sections 12.1–12.2 of our Terms & Conditions.
10. Security
10.1 We maintain reasonable and appropriate administrative, technical, and physical safeguards to protect personal data, including: TLS in transit; encryption at rest for stored data and customer BYOK keys; need-to-know access controls on production data; administrative-access logging; and a documented incident-response process. We offer these safeguards as a matter of good practice and of the security expectations applicable US state laws set for businesses like ours.
10.2 Breach notification. If a security incident compromises the personal data of New Jersey residents, we will disclose that breach in the most expedient time possible and without unreasonable delay, consistent with New Jersey's breach-notification law. If a law-enforcement agency determines that notification would impede a criminal investigation, we will delay notice while that determination stands and notify affected individuals as soon as notice no longer poses that risk. More broadly, we will notify affected individuals in every US state without unreasonable delay as applicable state breach-notification law requires, and we will coordinate with law enforcement where appropriate. For EEA/UK customers, we will notify the competent supervisory authority and, where required, affected individuals under Arts. 33–34 GDPR and the UK GDPR. Where we act as processor, we notify the controlling customer without undue delay per our Data Processing Addendum and cooperate with the customer's downstream notification duties.
11. Sharing
11.1 Subprocessors. We share personal data with subprocessors that host, secure, and support the Platform — hosting and CDN/security providers, the payment gateway, support tooling, and upstream model providers where you use Cyphra-provided model access. The current list is in our Subprocessor List, which also describes how we notify you of additions.
11.2 Payment gateway. Billing Portal checkout is gateway-hosted; card data is handled by the gateway under its own policies (see Section 3.2 and our Cookie Policy).
11.3 Legal requests. We may disclose personal data where we in good faith believe it necessary to comply with a legal obligation, court order, or valid law-enforcement request; to enforce our agreements; or to prevent imminent, serious harm. Where lawful and not prohibited, we redirect Customer Content requests to the controlling customer and notify affected customers of legal demands.
11.4 No sale of data. We do not sell personal information or share it for cross-context behavioral advertising (Section 7.1).
11.5 Mobile information. We will not share your mobile information with third parties for marketing purposes. Opt-out is available at any time by replying STOP to any service text from your agent.
12. International transfers
12.1 This section applies if you are located in the EEA or the UK. Cyphra operates the Platform from New Jersey, USA and our data region is the United States: your personal data is transferred to and processed in the United States. Because the United States is not recognized as providing an adequate level of protection, those transfers rely on contractual safeguards.
12.2 For transfers of EEA personal data to us, we rely on the standard contractual clauses adopted by the European Commission in 2021, in the module matching our role for the processing (controller-to-processor or processor-to-processor). For UK personal data, we rely on the UK International Data Transfer Addendum to those clauses. We assess the risks of these transfers as the law requires, document the safeguard applied to each transfer, and make that documentation available on request to [email protected]. Where a subprocessor processes your EEA or UK personal data outside the EEA or UK, an equivalent safeguard applies (Section 4.3 of our Data Processing Addendum).
13. Children
13.1 The Platform is not directed at children under 13, and we do not knowingly collect their personal data, consistent with COPPA (16 C.F.R. Part 312). Where local law sets a higher digital-consent age (such as 16 in parts of the EEA and UK), we require verifiable parental consent for accounts at or above 13 and below that age. If you believe a child has created an account, contact [email protected] and we will delete it.
15. Exercising your rights; how to contact us
15.1 To exercise any right in this policy, write to [email protected], or to Cyphra LLC at 31 Gloucester Road, Summit, NJ 07901, USA, including enough detail for us to verify your identity and locate the data (typically your account email and identifiers).
15.2 We acknowledge privacy requests within 5 business days and substantively respond within 30 calendar days of a verifiable request. That commitment sits within the response windows the applicable statutes set — for example, CCPA/CPRA's 45-day window, extendable once by a further 45 days — and we will meet any shorter period the law requires. If we need more time or information, we will tell you why. Requests are free unless manifestly unfounded or excessive, as the law allows. If we deny a request, we will explain why and describe any appeal right the law provides.
15.3 Changes to this policy. We may update this Privacy Policy as the Platform or the law evolves. Material changes will be communicated in accordance with our Terms & Conditions, and the version history below records each change. Continued use after an update constitutes acceptance to the extent the law allows.
Version history
| Version | Date | Summary |
|---|---|---|
| 1.0 | September 6, 2026 | Initial publication. |
| 1.1 | September 15, 2026 | Updated surface descriptions: browser-based Web Interface on desktop and mobile; no companion mobile app. |
| 1.2 | September 21, 2026 | Added mobile-information and SMS consent disclosures: collection limited to consented service texts; mobile information is never shared with third parties for marketing purposes. |
Contact us
- Privacy requests and complaints: [email protected]
- General support: [email protected]
- Legal matters, appeals, and copyright notices: [email protected]
- Cyphra LLC, 31 Gloucester Road, Summit, NJ 07901, USA
