overview
inference shell ("Inference Shell Inc.", "we", "us") takes your privacy seriously. this policy explains what personal data we collect, why we collect it, how we use it, and what rights you have.
data controller: Inference Shell Inc., Delaware, USA contact: [email protected]
information we collect
account information
- email address (required for authentication)
- name and avatar (optional, from OAuth provider)
- team membership and role
usage data
- API calls, task execution logs, and resource consumption
- feature usage patterns (anonymized)
technical data
- IP address and approximate geolocation
- browser type, device information, and user agent
- session tokens and authentication events
payment data
- billing is handled entirely by Stripe. we never store card numbers, CVVs, or bank details
- we store only Stripe customer and subscription IDs
content data
- prompts, files, and inputs you submit for processing ("Customer Input")
- outputs generated by the platform ("Output Content")
lawful basis for processing
we process your data under the following legal bases (GDPR Article 6):
| purpose | lawful basis | details |
|---|---|---|
| service provision | contract (Art 6.1.b) | necessary to provide the platform you signed up for |
| account security | legitimate interest (Art 6.1.f) | authentication, session management, fraud prevention |
| billing and payments | contract (Art 6.1.b) | processing transactions and maintaining credit balances |
| audit logging | legitimate interest (Art 6.1.f) | security monitoring, incident response, abuse prevention |
| legal compliance | legal obligation (Art 6.1.c) | tax records, lawful disclosure requests |
| marketing communications | consent (Art 6.1.a) | only with your explicit opt-in (you can withdraw anytime) |
how we use your information
- to provide, maintain, and improve our services
- to authenticate you and manage sessions
- to process payments and maintain credit balances
- to detect, prevent, and respond to fraud, abuse, and security incidents
- to comply with legal obligations
- to communicate service changes and security notifications (transactional)
- to send marketing communications (only with consent)
we do not use your Customer Input or Output Content to train AI models.
data retention
| data type | retention period | reason |
|---|---|---|
| account data | lifetime of account + 30 days after deletion | service provision |
| authentication logs | 90 days | security and incident response |
| API usage logs | 90 days | debugging, billing verification |
| billing records | 7 years | legal/tax obligations |
| session tokens | 30 days (active), purged on logout | security |
| anonymous/inactive accounts | purged after 365 days of inactivity | data minimization |
| Customer Input/Output | lifetime of account (you can delete anytime) | service provision |
data sharing and sub-processors
we share personal data only as necessary to provide the service:
infrastructure sub-processors
| sub-processor | purpose | location | DPA |
|---|---|---|---|
| Hetzner | primary compute, self-hosted databases, Redis, Meilisearch | Germany | ✓ |
| Leaseweb | fallback compute | Germany | ✓ |
| Google Cloud Platform | US replica compute | US | ✓ |
| Cloudflare | object storage (R2), CDN, CAPTCHA (Turnstile) | EU/US | ✓ |
| Stripe | payment processing | US | ✓ |
| Amazon SES | transactional email delivery (via SMTP) | US | ✓ |
| Simple Analytics | website analytics | EU (Netherlands) | ✓ |
| PostHog | product analytics and error tracking | US | ✓ |
| Google Fonts | web font delivery | US | ✓ |
| Fontshare (ITF) | web font delivery | US/India | ✓ |
AI model providers
when you run apps or agents on inference shell, your inputs are transmitted to the third-party AI provider serving that model. which provider processes your data depends on which app you choose to run. current providers include Anthropic, OpenAI, Google, FAL AI, Pruna, Bria, ElevenLabs, Kling AI, and others.
a current list of providers is maintained at inference.sh/providers. this list may change as new providers are added or removed. we will notify registered users of material changes to this list at least 30 days in advance.
we do not sell your personal data. we do not share it with advertisers or data brokers.
international transfers
your data may be transferred to and processed in the United States. for EU/EEA users, these transfers are protected by:
- Standard Contractual Clauses (SCCs) with all sub-processors
- EU-US Data Privacy Framework (where applicable)
your rights
under GDPR and similar privacy laws, you have the right to:
access (Art 15)
request a copy of all personal data we hold about you. contact [email protected] and we will respond within 30 days.
rectification (Art 16)
correct inaccurate personal data. you can update your profile directly in the app, or contact us for data we hold elsewhere.
erasure (Art 17)
request deletion of your personal data. we will delete your account and associated data within 30 days, subject to legal retention requirements.
restriction (Art 18)
request that we stop processing your data while a dispute is resolved.
data portability (Art 20)
receive your data in a structured, machine-readable format (JSON). available via your account settings or by request.
objection (Art 21)
object to processing based on legitimate interests. we will stop unless we demonstrate compelling legitimate grounds.
withdraw consent (Art 7)
withdraw consent for marketing communications at any time. this does not affect processing based on other lawful bases.
to exercise any of these rights, email [email protected] with your request. we will verify your identity and respond within 30 days.
data security
we implement appropriate technical and organizational measures:
- encryption at rest (AES-256) and in transit (TLS 1.2+)
- role-based access control with team scoping
- multi-factor authentication for admin accounts
- comprehensive audit logging of all access events
- rate limiting and account lockout
- regular vulnerability scanning
- incident response procedures
for full details, see our security page.
cookies
essential cookies
| cookie | purpose | duration |
|---|---|---|
| session | authentication state | 30 days |
| csrf | cross-site request forgery protection | session |
analytics cookies (with consent)
| cookie | purpose | duration |
|---|---|---|
| ph_* | PostHog product analytics and error tracking | 1 year |
analytics cookies are set only when you accept the cookie consent banner. if you decline, PostHog operates in cookieless mode and no analytics cookies are set. you can change your preference at any time through the cookie settings.
we do not use advertising cookies or sell data to third parties.
children
inference shell is not intended for users under 18 years of age. we do not knowingly collect personal data from children.
changes to this policy
we may update this policy from time to time. material changes will be communicated via email or platform notification at least 30 days before taking effect.
contact
for privacy-related questions or to exercise your rights:
- email: [email protected]
- data controller: Inference Shell Inc., Delaware, USA
if you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority.
supervisory authority
for EU/EEA residents, you may contact your local Data Protection Authority. a list is available at edpb.europa.eu.