Early access · Paid API credit is live. New accounts still get free starter credit.
PricingDocsModelsFAQEarnBlogAboutSign in →

Privacy Policy

Last updated: July 14, 2026
Early access · paid API credit live · provider payouts rolling out

Draft, pending legal review. This is a good-faith draft written to reflect Umbra's actual alpha data flows; it has not yet been reviewed by counsel. Questions? Contact us.

Umbra's whole reason to exist is privacy. Your prompts and the model's responses are never logged, never written to disk, and never stored (not by us, and not by the machine owner running the model). This policy explains that guarantee and the limited account data we do keep to run the service.

Experimental alpha with real payments. Developers can buy prepaid inference credit through Stripe, and those card charges are real. Provider onboarding and cash-out are enabled through Stripe Connect for payout-ready Hong Kong connected accounts. Current availability is shown in the provider wallet; providers elsewhere cannot receive a payout through the current Stripe account. Promotional and purchased API credit cannot be withdrawn.

This is a draft, not legal advice. This document is a good-faith draft prepared for the operator and their counsel to review. It is not legal advice and does not create any attorney-client relationship. Bracketed placeholders are to be completed by counsel before any release.

1. Your prompts and outputs are never retained

When you send a request, it travels encrypted to a provider machine, is decrypted in memory only, used to generate a response, and then zeroized. The content is never persisted to a disk, a log, a database, or an analytics pipeline at any point.

2. What we do collect

To operate accounts, metering, and credit, we keep a minimal record:

3. Cookies and local storage

We use no advertising and no third-party tracking cookies.

For product analytics we use PostHog in a privacy-safe configuration: first-party localStorage only (no tracking cookies), no automatic capture of form fields, and privacy-masked session replay on public marketing and documentation pages. Replay masks all text and inputs and does not capture request headers, bodies, or console logs. We do not record sign-in, signup, password reset, verification, unsubscribe, wallet, playground, or authenticated console pages. Events are limited to page views, coarse attribution (UTMs / referrer domain), and content-free product milestones such as signup, API-key creation, and first successful inference. We identify accounts with an opaque account id only — never email — and we never send prompts, model outputs, API secrets, or raw IP addresses to PostHog. Analytics does not initialize when the browser sends Global Privacy Control or Do Not Track. For anonymous visitors, PostHog may create a person profile containing only a readable traffic label, traffic classification, acquisition source, landing path, broad device/browser/OS family, environment, and sign-in state. These profiles follow the PostHog project's configured retention and deletion rules.

4. Service providers

We rely on a small set of processors, each for a specific function:

5. Confidential computing and attestation

Our coordinator runs inside an AMD SEV-SNP confidential VM, and provider hardware is designed to be verified through Apple platform attestation. These are the technical mechanisms that keep your prompts private in transit and on the provider machine. You can inspect the live attestation from the console.

Accuracy note: production routing requires providers that pass Apple hardware attestation and an app-targeted running-code identity challenge. Attestation verifies the provider software and machine state; it does not warrant a model's accuracy or output.

6. Where your data is processed

Requests are processed in the United States (Google Cloud, us-central1) and via Cloudflare's global edge network. Account, wallet, API-key, and payout-account records are stored in managed PostgreSQL infrastructure in Canada. Creator model-hosting requests are stored in Cloudflare D1. Stripe processes payment, identity, tax, and bank data in the locations described by Stripe's own privacy terms. If you use Umbra from another country, your data may be transferred internationally.

7. Retention

8. Your choices and rights

You can stop using Umbra at any time and request deletion of your account data by contacting us (self-service account deletion is not yet available during the alpha). Depending on where you live, you may have rights to access, correct, export, or delete your personal data; contact us to exercise them.

9. Children

Umbra is not directed to, and may not be used by, anyone under 18. We do not knowingly collect data from children.

10. Security

We hash credentials and API keys, encrypt data in transit, and run the backend in a confidential VM. No system is perfectly secure, and Umbra is an early-stage alpha service, so please keep that in mind.

11. Changes

We may update this policy as the service evolves; the "Last updated" date above reflects the latest version. Material changes will be surfaced in the product.

12. Contact

Questions about privacy? Reach us at [email protected].