TensorScale AI Privacy Policy
Key privacy commitments
- No AI training on your Customer Content without opt-in. We do not use Customer Content to train or fine-tune our generally available models unless you instruct us to do so, opt in, or otherwise provide written consent.
- Zero data retention for open-model inference by default. For hosted open-model inference, we do not log or persistently store prompts or generation Outputs unless you opt in to a feature that requires storage. We may retain Usage Data and other metadata needed to operate, secure, and bill for the Services.
- You control your Customer Content. As between you and TensorScale, you retain your rights in Customer Content. We process it to provide the Services as described in this Policy, our Terms of Service, and any Data Processing Addendum.
This Privacy Policy (this "Policy") describes how TensorScale AI, Inc. ("TensorScale," "we," "us," or "our") collects, uses, discloses, and otherwise processes personal information in connection with our websites (including tensorscale.io), hosted model inference services, console, sandbox, software, documentation, and related offerings (collectively, the "Services").
Capitalized terms used but not defined in this Policy have the meanings given in our Terms of Service (the "Terms"), including Customer Content, Inputs, Outputs, Fine-Tuning Data, Fine-Tuned Model, and Usage Data.
1. Scope and relationship to other terms
This Policy is a notice that describes our privacy practices. It is not a contract and does not by itself create contractual obligations. Your use of the Services is governed by the Terms and any other written agreement between you and TensorScale. If we process personal data on your behalf as a processor or service provider, that processing is governed by a data processing addendum ("DPA") when executed.
This Policy does not apply to third-party websites, products, or services that link to or from the Services. Those third parties’ privacy practices are governed by their own policies.
2. Controller and processor roles
2.1 When TensorScale is the controller
TensorScale acts as a business / controller for personal information about visitors to our websites and individuals who create TensorScale accounts, communicate with us, or otherwise interact with us directly (for example, account profile data, billing contact details, and marketing preferences). This Policy primarily describes that processing.
2.2 When TensorScale is the processor / service provider
If you are a Customer using the Services to process Inputs, Outputs, Fine-Tuning Data, or other Customer Content that includes personal information about your end users or other individuals, you are the controller (or business) for that personal information, and TensorScale processes it as a processor or service provider on your behalf to provide the Services. That Customer Content is not governed by this Policy in the same way as TensorScale’s own controller processing. Instead, it is governed by the Terms, your instructions, applicable law, and any DPA.
If you are an end user of a Customer Application built on TensorScale, please contact that Customer about their privacy practices. We will redirect end-user requests to the relevant Customer where appropriate.
Enterprise Customers may request a DPA by contacting legal@tensorscale.io.
3. Notice at collection (California)
For California residents, the following summarizes the categories of personal information we collect, the purposes for which we use it, the categories of recipients, and retention. Details appear in the sections that follow. This section is intended to satisfy California “notice at collection” requirements.
- Categories collected: Identifiers; customer records information; commercial information; internet or other electronic network activity; approximate geolocation; professional or employment-related information (if you provide it); inferences; and contents of Customer Content and Outputs (which may include any category of personal information depending on what you or your end users submit).
- Purposes: Providing, securing, billing for, and improving the Services; communicating with you; marketing and advertising (including targeted advertising where applicable); preventing fraud and abuse; complying with law; and the purposes in Section 5.
- Recipients: Service providers and contractors; advertising and analytics partners; professional advisors; affiliates; authorities; and parties to corporate transactions, as described in Section 9.
- Retention: As described in Section 12.
- Sale or sharing: We do not sell personal information for monetary consideration. Certain advertising and analytics technologies may constitute “sharing” or “selling” under the CCPA/CPRA or “targeted advertising” under other state laws. See Sections 10 and 15 to opt out.
4. Personal information we collect
The information we collect depends on how you use the Services.
4.1 Information you provide
- Account and contact information. Name, email address, password (stored in hashed form), organization name, phone number, and similar profile details.
- Payment and billing information. Billing address, tax information, invoice details, and payment method metadata. Payment card numbers are collected and processed by our third-party payment processor and are not stored on TensorScale systems. We may also process information needed for invoicing and wire or ACH payments.
- Communications. Support tickets, emails, form submissions, and other messages you send us.
- Customer Content. Inputs, Fine-Tuning Data, files, datasets, prompts, text, images, audio, video, and other content you submit to the Services, which may include personal information.
- Outputs. Content generated or returned by the Services in response to Inputs, together with associated parameters and metadata where storage applies.
4.2 Information we collect automatically
- Usage Data and device information. IP address, browser type, device identifiers, operating system, referring URLs, pages and features used, timestamps, API endpoints called, latency, error logs, model identifiers, token or compute metrics, and similar telemetry.
- Approximate location. Approximate location derived from IP address.
- Cookies and similar technologies. Information collected through cookies, pixels, SDKs, and similar technologies, as described in Section 10. This site may also use Google reCAPTCHA; Google’s privacy policy and terms apply to that service.
4.3 Information from other sources
- Single sign-on providers. If you log in with a third-party identity provider (for example, Google or GitHub), we receive information the provider shares with us, such as name, email address, and provider user identifiers, subject to your settings with that provider.
- Payment processors and fraud-prevention partners. Limited billing and risk signals needed to process payments and prevent abuse.
- Advertising and analytics partners. Information about your interactions with our ads or sites, as described in Section 10.
5. How we use personal information
We use personal information for the purposes below. Where the GDPR or UK GDPR applies, the relevant lawful bases are noted in parentheses.
- Provide the Services. Create and secure accounts, authenticate users, process payments and invoices, generate Outputs, run fine-tuning or customization jobs you request, and provide support (performance of a contract; legitimate interests).
- Operate, secure, and prevent abuse. Monitor integrity and availability, detect fraud and security incidents, enforce the Terms and Acceptable Use Policy, and comply with law (legitimate interests; legal obligation).
- Billing and account administration. Meter usage, issue invoices, collect Fees, and maintain business records (performance of a contract; legal obligation; legitimate interests).
- Improve the Services. Analyze Usage Data and aggregated or de-identified information to debug, capacity-plan, and improve features. “Improve” in this Policy does not mean training generally available models on Customer Content without opt-in (legitimate interests; consent where required).
- Marketing and advertising. Send product updates and promotional messages (with unsubscribe), and engage in analytics and targeted advertising as described in Section 10 (consent; legitimate interests).
- Corporate transactions and legal claims. Evaluate or complete a merger, financing, or sale of assets, and establish or defend legal claims (legitimate interests; legal obligation).
We may create aggregated or de-identified information that cannot reasonably be linked to you. We will maintain and use such information in de-identified form and will not attempt to re-identify it except as permitted by law.
6. AI services, Inputs, Outputs, and fine-tuning
6.1 Hosted inference
TensorScale provides hosted inference and related model services on infrastructure we operate or control, including open-source models. Unless we expressly state otherwise for a particular model or feature, we do not forward your Inputs to third-party model-provider APIs for inference by default. Subprocessors (such as cloud or GPU hosts) may process data as needed to provide the Services.
6.2 Zero data retention for open-model inference
For hosted open-model inference, prompts and generation Outputs exist to fulfill the request and are not logged or stored in persistent storage by default, unless you opt in to a feature that requires storage (for example, history, evaluation, or support tooling we expressly offer). We may retain Usage Data and metadata (such as timestamps, model identifiers, token or compute counts, latency, and error codes) to operate, secure, bill for, and improve the Services.
6.3 Safety, abuse, and legal review
We may use automated systems and, where appropriate, limited human review of Inputs or Outputs that are flagged by safety systems, reported by users, or required for security, Acceptable Use Policy enforcement, or legal compliance. Such review is limited to what is reasonably necessary for those purposes, is subject to access controls, and is not used to train generally available models. Ephemeral processing for a request is not the same as retaining a prompt history.
6.4 Fine-tuning and customization
If you use fine-tuning, evaluation, or model customization features, we process Fine-Tuning Data and related Customer Content as needed to perform those jobs. Fine-tuning necessarily involves storing datasets, intermediate artifacts, and Fine-Tuned Models for the duration needed to provide the feature and as otherwise agreed. That storage is separate from our default zero data retention posture for open-model inference. We do not use Fine-Tuning Data to train or improve generally available models for other customers unless you instruct us to do so, opt in, or provide written consent.
6.5 Accuracy and automated decisions
Outputs are probabilistic and may be inaccurate, incomplete, biased, or unsuitable for a particular purpose. TensorScale does not currently use personal information for fully automated decision-making that produces legal or similarly significant effects without meaningful human review. If that changes, we will provide required notices and choices.
7. Biometric information
The Services may process images, video, or audio that include faces, voices, or other characteristics that could be considered biometric identifiers or biometric information under laws such as the Illinois Biometric Information Privacy Act and similar state laws.
When such content appears in Customer Content, you (the Customer) are responsible for providing any required notices and obtaining any required consents from the relevant individuals, and for ensuring you have a lawful basis to submit that content. TensorScale processes that content as a processor/service provider to provide the Services you request, subject to the Terms and any DPA.
TensorScale does not, as a controller, enroll individuals into a TensorScale biometric identification database in the ordinary course of providing hosted inference. If we introduce a TensorScale-controlled feature that collects biometric information as a controller, we will provide a separate written notice describing the categories of biometric data, purposes, and retention period, and will obtain any required informed opt-in consent before collection.
8. Sensitive data and HIPAA
The Services are not designed for protected health information governed by HIPAA. TensorScale is not a HIPAA covered entity or business associate and does not enter into business associate agreements by default. Do not submit protected health information through the Services.
You should not submit special-category personal data (GDPR Article 9) or sensitive personal information (under U.S. state privacy laws) to the Services unless we have agreed in writing that the Services are suitable for that data and appropriate terms are in place. You are responsible for ensuring that any personal information you submit has been collected with appropriate notice and a valid lawful basis.
9. How we share personal information
We share personal information in the following circumstances:
- Service providers and subprocessors. Vendors that help us host and operate the Services, including cloud and GPU infrastructure, storage, payment processing, email and communications, customer support, security and fraud prevention, analytics, and professional advisors. These parties are engaged to process personal information for specified purposes on our behalf. We describe categories of subprocessors in this Policy; a current named list is available on request to legal@tensorscale.io.
- Advertising and analytics partners. As described in Section 10, which may constitute “sale,” “sharing,” or targeted advertising under applicable law.
- Affiliates. With affiliated entities for purposes consistent with this Policy, where applicable.
- Legal and safety. Where we believe disclosure is required by law, necessary to respond to lawful requests, enforce our agreements, or protect the rights, property, or safety of TensorScale, our users, or others.
- Corporate transactions. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality safeguards.
- With your direction or consent. When you ask us to share information or otherwise consent.
We may share aggregated or de-identified information that cannot reasonably identify you.
10. Cookies, advertising, and your privacy choices
We and our partners use cookies and similar technologies to operate the Services, remember preferences, measure analytics, and support marketing and advertising (including interest-based or targeted advertising on third-party sites and platforms).
Categories of cookies may include strictly necessary, functional, analytics, and advertising cookies. Where required by law, we obtain consent before placing non-essential cookies.
Depending on your jurisdiction, our use of advertising and analytics technologies may be considered a “sale,” “sharing,” or “targeted advertising.” You may opt out of sale, sharing, and targeted advertising as follows:
- Use the Your Privacy Choices controls linked from our website footer (when available), or follow the instructions on this page and contact us at legal@tensorscale.io with the subject line “Privacy Choices”;
- Enable a recognized universal opt-out signal such as the Global Privacy Control (GPC) in a supporting browser. We treat a GPC signal as a request to opt out of sale/sharing of personal information for that browser, consistent with applicable law; and
- Use industry tools such as the Digital Advertising Alliance’s choices at aboutads.info/choices or the Network Advertising Initiative at networkadvertising.org/choices.
You can also control cookies through your browser settings. Blocking cookies may affect some features of the Services. Opting out of targeted advertising does not mean you will see no ads; it means ads should not be based on that opted-out targeted interest profile from participating companies.
You may unsubscribe from promotional emails using the link in those emails. We may still send transactional or service messages.
11. International transfers
TensorScale is based in the United States. We and our service providers may process personal information in the United States and other countries that may have different data-protection laws than your country of residence.
Where we transfer personal information from the EEA, United Kingdom, or Switzerland to a country that has not been recognized as providing adequate protection, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and applicable Swiss transfer mechanisms. A copy of the relevant transfer mechanism is available on request to legal@tensorscale.io, typically in connection with a DPA.
12. Retention
Open-model inference Inputs and Outputs. As described in Section 6.2, we do not persistently store prompts or generation Outputs by default, unless you opt in to a storage-requiring feature or limited retention is needed for a safety, security, or legal review described in Section 6.3.
Fine-Tuning Data and Fine-Tuned Models. Retained as needed to provide the requested fine-tuning or customization features and as otherwise agreed, then deleted or returned according to the Terms, DPA, or your instructions where applicable.
Other personal information. We retain account, billing, support, security, marketing, and Usage Data for as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, comply with legal and tax obligations, resolve disputes, enforce agreements, and maintain security. When determining retention, we consider the amount, nature, and sensitivity of the information, potential risk of harm from unauthorized use or disclosure, the purposes of processing, and applicable legal requirements.
When we no longer need personal information, we delete, anonymize, or aggregate it, except where longer retention is required or permitted by law.
13. Security and breach notification
We maintain reasonable administrative, technical, and physical safeguards designed to protect personal information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a personal data breach affecting your personal information, we will notify you and regulators as required by applicable law.
14. Children’s privacy
The Services are intended for users who are at least 18 years old (or the age of majority in their jurisdiction, if higher). We do not knowingly collect personal information from children under 18 in connection with the Services, and we do not knowingly collect personal information from children under 13.
If we learn that we have collected personal information from a child under 13 (or under the applicable digital-consent age under the GDPR), we will take steps to delete it promptly. Parents or guardians may contact legal@tensorscale.io with concerns.
We do not knowingly sell or share the personal information of consumers under 16.
15. Your privacy rights (U.S. states)
If you reside in California or another U.S. state that provides similar consumer privacy rights, you may have some or all of the following rights, subject to legal exceptions:
- Know / access personal information we collect about you, including in a portable format;
- Delete personal information;
- Correct inaccurate personal information;
- Opt out of sale, sharing, or targeted advertising;
- Limit use and disclosure of sensitive personal information, where applicable; and
- Nondiscrimination for exercising privacy rights.
15.1 Categories (CCPA/CPRA)
In the preceding 12 months, we may have collected the categories listed in Section 3 and disclosed them for business purposes to the recipient categories in Section 9. We do not sell personal information for monetary consideration. We may “share” personal information for cross-context behavioral advertising or engage in targeted advertising through advertising and analytics partners as described in Section 10.
| Category of personal information | Examples of recipients for advertising / analytics |
|---|---|
| Identifiers (e.g., cookie IDs, IP address, email if hashed for ads) | Advertising networks, social media platforms, analytics providers |
| Internet or other electronic network activity | Advertising networks, analytics providers |
15.2 How to exercise rights
To exercise access, deletion, correction, or related rights, email legal@tensorscale.io. We may need to verify your identity. You may use an authorized agent where permitted by law; we may require proof of authorization and may verify the request with you directly.
To opt out of sale, sharing, or targeted advertising, use the methods in Section 10 (including GPC).
If we deny a request, you may appeal by replying to our decision email or contacting legal@tensorscale.io with the subject line “Privacy Appeal.” If your appeal is denied, you may contact your state attorney general where applicable.
15.3 Other state laws
Residents of other states with consumer privacy laws (including, where applicable, states such as Texas, Colorado, Virginia, and others) may have similar rights to access, delete, correct, or opt out of targeted advertising or certain profiling. We will process requests in accordance with applicable law. Nevada residents may request information about our data sharing practices by contacting us at the email above; we do not sell covered information as defined under Nevada law in exchange for monetary consideration.
16. Additional information for Europe (EEA/UK/Switzerland)
If you are located in the EEA, United Kingdom, or Switzerland, this section applies to TensorScale’s controller processing of your personal data.
- Lawful bases. See Section 5.
- Transfers. See Section 11.
- Your rights. You may have rights to access, rectify, erase, restrict, or object to certain processing, and to data portability. Where processing is based on consent, you may withdraw consent at any time without affecting prior processing. To exercise these rights, contact legal@tensorscale.io.
- Complaints. You may lodge a complaint with your local supervisory authority. EEA contacts are listed by the European Data Protection Board; UK residents may contact the ICO; Swiss residents may contact the FDPIC.
Processor processing of Customer Content is addressed in the Terms and DPA, not solely in this Policy.
17. Changes to this Policy
We may update this Policy from time to time. We will post the updated Policy with a revised “Last Updated” date. If we make material changes to the way we use or disclose personal information, we will provide additional notice as appropriate, such as by email to the address associated with your account or a notice through the Services, consistent with applicable law.
Your continued use of the Services after the effective date of an updated Policy means you have seen the updated notice. If you do not agree with the changes, stop using the Services and, where applicable, close your account.
18. Contact us
Questions about this Policy, privacy rights requests, Privacy Choices, or DPA requests may be sent to legal@tensorscale.io.