Privacy Policy
Last updated: July 17, 2026. What Project Ares collects, why, and what control you have.
What we collect
- Account data: email, display name, password hash (never the password), and — if you use social sign-in — the identifier the sign-in provider shares.
- Usage metering: for every model request we record the model, token counts, service tier, cost, latency, timestamp, the key/account it billed to, and the requesting IP. This is the basis of your bill and our abuse prevention.
- Message content: your prompts and the model's outputs are processed transiently to generate the response and are not stored by the gateway. They are transmitted to the model host that serves your request — solely to produce the response. We do not use your content to train models.
- Billing data: handled by our payment processor. Card numbers never touch Project Ares servers; we store only a reference, the card brand, and the last four digits.
- Security telemetry: sign-in attempts, session/device records, an append-only audit log of sensitive actions, and network events (IP, route, status) for abuse detection.
- Cookies: one httpOnly session cookie to keep you signed in. No advertising or cross-site tracking cookies.
How we use it
To run and bill the service, to secure it (fraud/abuse prevention, anomaly flags), to send transactional email (verification, receipts, invoices, payment issues, invitations), and to comply with law. We do not sell personal data and do not use your data for advertising.
Who processes it
We rely on service providers acting on our instructions: cloud hosting, a payment processor, a transactional email provider, and the model hosts that generate responses. Each receives only what the task requires. A current subprocessor list is available on request.
Retention
Account data lives while the account does. Financial records (ledger, invoices, usage metering) are retained as bookkeeping requires even after account deletion. Security telemetry is retained on a rolling basis. Message content is not retained by the gateway at all.
Your controls
- Edit your profile, revoke sessions and devices, and revoke or roll API keys — any time, in Settings.
- Choose where billing email goes and which notifications you receive.
- Delete your account self-serve from Settings (last-owner protection applies to organizations you solely own). Deletion removes your user record, sessions, keys, and memberships; financial records are retained as required.
- For access or portability requests beyond the console, contact the team through the console.
Transparency about AI
Responses produced by the service are generated by artificial intelligence. Where you share them onward, applicable transparency laws (including the EU AI Act) may require you to disclose that.
Changes & contact
Material changes to this policy will be announced in the console or by email before they take effect. Questions: contact the Project Ares team through the console.