How we handle your API request content, what is separate account metadata, and how to request erasure.
Last updated:
Aggregate website analytics
We count requests for public website pages in aggregate by page, day and referrer category, and by country only when a trusted proxy is configured. These aggregates are retained for 90 days, with hourly cleanup. We use no analytics cookies or visitor IDs and do not store raw IP addresses or full referrers in these analytics. Aggregate website analytics are separate from operational logs. We respect Do Not Track (DNT) and Global Privacy Control (GPC) signals by excluding those requests from analytics.
Campaign-tagged page requests are also aggregated separately by validated utm_source, utm_medium and utm_campaign labels. Labels are lowercased and limited to 64 ASCII letters, digits, hyphens or underscores, including at least one letter. Invalid or duplicate fields are ignored; we do not collect utm_term, utm_content, full URLs or full query strings in these analytics. We keep at most 100 distinct labels per field per day; additional labels are combined into an overflow bucket. These counts have the same 90-day retention and DNT/GPC exclusions. We do not associate tags with accounts or persist them across visits. Campaign links must not contain personal data or per-visitor identifiers; format validation cannot identify all personal data.
Proxied web-chat completions are counted in the same aggregate store by day and country (same 90-day retention, same trusted-proxy country rule). These counts record only that a completion ran successfully — no prompts, outputs, user IDs, or per-visitor journeys. Chat quota enforcement uses a separate per-user daily counter; the back office can show each account's chat-call totals from that counter. The aggregate chat counts start at deployment with no historical backfill.
Referral attribution and payouts
Following a valid referral link can store a signed first-party cookie named 2ba_ref for 30 days. It contains a referrer code and expiry, not a visitor identifier. The first valid referral is attached when a new account signs up. This is separate from aggregate website analytics and UTM tags.
We store referral relationships, agreed commission terms, invoice-based earnings, adjustments and payout records as account and payment metadata. Referrers see aggregate counts and their own earnings; we do not disclose referred customers’ identities to them. Stripe processes customer subscription payments. 2BA pays referral earnings by manual bank transfer and records the amount, date, bank reference and responsible administrator. Bank details are arranged directly with the referrer outside the referral dashboard; the dashboard does not collect or store them. These records follow the account, payment-record and erasure provisions below.
1. API inputs and outputs
Your prompts, code context and other inputs, together with the outputs generated in response, are processed transiently to serve API inference. We do not store request content as a prompt or completion history or log the content of requests.
We do not use your inputs or outputs to train, retrain, fine-tune or improve models. You retain your rights in your inputs; ownership of inputs and outputs is addressed in our terms.
Account details and payment records are separate from API request content. Operational metadata includes standard server metrics such as timestamps, token counts and error codes.
These records may be processed for account administration, billing, security, abuse prevention and legal obligations. The treatment of API request content does not mean that account and billing records are deleted after each request.
3. EU inference hosting and data protection
Our API inference, including processing of inputs and outputs, is hosted within the European Union. This statement applies to API inference; it does not mean that payment or account services have no separate providers.
As described in our terms, where we process personal data on your behalf, the parties must put in place an appropriate data processing agreement under Article 28 GDPR before that processing. The terms do not themselves replace a DPA. Contact us to discuss data processing or data-subject requests.
You may cancel renewal through the billing portal accessible from your account. Cancelling renewal does not immediately revoke access or delete your account. Your paid subscription continues until the end of the current billing period and does not renew, subject to the protective suspension rules in our terms.
Account deletion is separate from subscription cancellation. To request erasure, use the contact below.
You may request erasure of your account data by contacting us. We handle requests under applicable data-protection law, subject to legally required record retention. Account and billing metadata are separate from API request content.
For erasure requests, privacy questions and data-processing matters: