Skip to content

Legal / Platform & API services

Privacy policy

How we handle your API request content, what is separate account metadata, and how to request erasure.

Last updated:

Aggregate website analytics

We count requests for public website pages in aggregate by page, day and referrer category, and by country only when a trusted proxy is configured. These aggregates are retained for 90 days, with hourly cleanup. We use no analytics cookies or visitor IDs and do not store raw IP addresses or full referrers in these analytics. Aggregate website analytics are separate from operational logs. We respect Do Not Track (DNT) and Global Privacy Control (GPC) signals by excluding those requests from analytics.

Campaign-tagged page requests are also aggregated separately by validated utm_source, utm_medium and utm_campaign labels. Labels are lowercased and limited to 64 ASCII letters, digits, hyphens or underscores, including at least one letter. Invalid or duplicate fields are ignored; we do not collect utm_term, utm_content, full URLs or full query strings in these analytics. We keep at most 100 distinct labels per field per day; additional labels are combined into an overflow bucket. These counts have the same 90-day retention and DNT/GPC exclusions. We do not associate tags with accounts or persist them across visits. Campaign links must not contain personal data or per-visitor identifiers; format validation cannot identify all personal data.

1. API inputs and outputs

Your prompts, code context and other inputs, together with the outputs generated in response, are processed transiently to serve API inference. We do not store request content as a prompt or completion history or log the content of requests.

We do not use your inputs or outputs to train, retrain, fine-tune or improve models. You retain your rights in your inputs; ownership of inputs and outputs is addressed in our terms.

Read the ownership terms

2. Account, billing and operational metadata

Account details and payment records are separate from API request content. Operational metadata includes standard server metrics such as timestamps, token counts and error codes.

These records may be processed for account administration, billing, security, abuse prevention and legal obligations. The treatment of API request content does not mean that account and billing records are deleted after each request.

3. EU inference hosting and data protection

Our API inference, including processing of inputs and outputs, is hosted within the European Union. This statement applies to API inference; it does not mean that payment or account services have no separate providers.

As described in our terms, where we process personal data on your behalf, the parties must put in place an appropriate data processing agreement under Article 28 GDPR before that processing. The terms do not themselves replace a DPA. Contact us to discuss data processing or data-subject requests.

Read the data-protection terms

4. Subscription cancellation

You may cancel renewal through the billing portal accessible from your account. Cancelling renewal does not immediately revoke access or delete your account. Your paid subscription continues until the end of the current billing period and does not renew, subject to the protective suspension rules in our terms.

Account deletion is separate from subscription cancellation. To request erasure, use the contact below.

Read the cancellation and suspension terms

5. Right to erasure and contact

You may request erasure of your account data by contacting us. We handle requests under applicable data-protection law, subject to legally required record retention. Account and billing metadata are separate from API request content.

For erasure requests, privacy questions and data-processing matters:

privacy@2ba.ai