Legal
Privacy Notice
This notice explains what data AdvancedMind AI collects, how we use it, who we share it with, and the choices and rights you have. It applies to the AdvancedMind AI web application and API. It should be read together with the Terms of Service and the No-Training Policy.
Last updated: July 2, 2026
1. Scope
This notice covers personal data and account data we process when you use the Service. It does not cover third-party sites or services we link to, which have their own policies. Where you use the Service on behalf of an Organization, that Organization is responsible for its own users and may set policies governing their use.
2. Data we collect
We collect three categories of data.
- Account data. Information you provide to create and manage an account and Organization: name, email address, organization name, role, and, where you apply for Research Mode, the identity, professional or institutional profile, country, and project details you submit in a Research Mode application.
- Usage metadata. Records describing each request: the model used, timestamps, input and output token counts, computed cost, request status, the API key prefix used, latency, the Provider route, and the retention window declared for the model used. This metadata is what powers the Research Ledger, your Usage view, and metering. We also collect first-party web analytics events such as page views, checkout starts, top-up clicks, campaign parameters, page path without query string, and referrer host so we can understand the purchase funnel. The analytics sink redacts values that look like email addresses or secrets. We also collect ordinary technical logs such as IP address and user agent for security and abuse prevention.
- Billing data. Your credit balance, plan, top-ups, and transaction records. Card and payment-instrument details are collected and processed by our payment processor; we do not store full card numbers.
Request and response content (your inputs and the model outputs) is processed to serve your requests and is retained only for the 30-day operational window described in Section 5. Usage metadata describes a request without reproducing what was asked or answered.
3. How we use data
- To provide the Service. Authenticate you, route requests to Providers, generate responses, and return them to you.
- To meter and bill. Compute per-request cost, debit your credit balance, apply plan allotments and top-ups, and show your usage history.
- To review Research Mode access. Evaluate Research Mode applications, issue and scope entitlements, and monitor high-risk access as described in the Research Mode Policy.
- To secure the Service. Detect, investigate, and prevent abuse, fraud, and violations of the Acceptable Use Policy, and to keep audit and risk records.
- To support and improve operations. Respond to support requests, diagnose problems, and maintain the reliability of the Service.
- To comply with law. Meet legal, tax, and regulatory obligations and respond to lawful requests.
4. No training on customer data
We do not use your inputs or outputs to train or improve any model, and we require our Providers not to train on content routed through the Service. This commitment is set out in full in the No-Training Policy. Usage metadata may be used in aggregate to operate and secure the Service, but aggregate operational analytics are not model training.
5. Retention
We retain different categories of data for different periods. Request and response content is governed by the 30-day operational window each model declares, shown on the models page: content may be retained for up to 30 days to support debugging, abuse detection, and reliability, then deleted.
In addition, under the No-Training Policy, your content is never used to train or improve any model, by us or our Providers.
Account data is retained while your account is active and for a reasonable period afterward. Usage metadata and billing records are retained as needed for metering, audit, and to meet legal and tax obligations, which may require retention beyond account closure. Security and audit logs are retained for a limited period appropriate to their purpose.
6. Providers and subprocessors
Serving a request necessarily discloses its content to the model Provider that runs it. We route requests to Providers solely to generate the response you asked for, subject to the retention window in force and to contractual commitments that restrict the Provider's use of that content, including our no-training requirement. We also rely on subprocessors for infrastructure functions such as hosting, payment processing, and email delivery.
- Model Providers: host and serve the models your requests are routed to.
- Cloud and hosting: run the application, API, and data stores.
- Payment processor: handles plan charges and top-ups; processes payment instruments on our behalf.
- Communications: deliver transactional email and account notices.
We impose data-protection and confidentiality obligations on subprocessors consistent with this notice. Subprocessors may process data in jurisdictions other than your own; where they do, we use appropriate safeguards for international transfers as required by applicable law.
7. How we share data
We do not sell personal data. We share data only as described in this notice: with Providers and subprocessors to operate the Service; within your Organization, where administrators can see usage and billing for the account; where required by law or to respond to a valid legal request; to protect the safety, rights, and security of users, the public, or the Service; and in connection with a merger, acquisition, or sale of assets, subject to this notice.
8. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to withdraw consent where processing relies on it. You can update much of your account data directly in the application. To exercise other rights, contact us using the details below; we will verify your request and respond within the time required by applicable law. Where you use the Service through an Organization, some requests may need to be directed to that Organization as the controller of its users' data. If you are in a region with a supervisory authority, you may also have the right to lodge a complaint with it.
9. Security
We use technical and organizational measures appropriate to the risk to protect data, including encryption in transit, access controls, key scoping and per-key spend limits, and audit logging of sensitive actions. API keys are shown in full only once at creation and are stored in a form designed so they cannot be recovered later; you can revoke a key at any time. No method of transmission or storage is completely secure, and you are responsible for safeguarding your credentials and keys.
10. Children
The Service is not directed to children and is intended for users who can form a binding contract. We do not knowingly collect personal data from children.
11. Changes to this notice
We may update this notice from time to time. When we make material changes, we will update the “Last updated” date and, where appropriate, provide additional notice. Continued use of the Service after changes take effect constitutes acceptance of the updated notice.
12. Contact
For privacy questions or to exercise your rights, contact our privacy team at [email protected]. For the terms governing your use of the Service, see the Terms of Service.