# Privacy Policy **Last updated:** September 10, 2026 ## In plain language - We collect only what we need: your email, name, and basic usage data. - **Your AI conversations are encrypted** — even we can't read them at the inference step. - We **do** store your chat history on our server (so you can revisit it). We promise not to read it, but this is a promise, not a technical guarantee. - We never train on your data, and we never sell it. - You can export or delete your data at any time. The full policy is below. Questions? info@inference.coop. --- ## 1. Our privacy philosophy The Inference Cooperative is a member-governed project. We are **not** an ad-supported or data-extractive business — we have no incentive to read or sell your data. Privacy is a structural value, built into how we operate. ## 2. What we collect - **Account data:** your email and name (from Open Collective). - **Membership data:** your contribution status and role. - **Usage data:** token counts, model used, and timestamps (for metering your monthly budget). - **Content:** your prompts and the AI's responses (stored in your chat history). - **Billing data:** handled by Open Collective — we do not see full payment details. ## 3. What we *can't* see (architectural privacy) Inference runs inside **encrypted enclaves** (TEEs). Your model inputs and outputs are encrypted end-to-end, so **even our own infrastructure cannot read them at the inference step.** This is verifiable through remote attestation — it's a property of the system, not a promise. ## 4. What we *can* see (an honest caveat) Your **chat history is stored on our server** so you can revisit past conversations. Unlike the inference step, stored chat history is **not** encrypted in a way that prevents us from technically reading it. We commit not to read it. But this is a **policy commitment**, not an architectural guarantee. We're transparent about this distinction because it matters. ## 5. Search Web search runs through our self-hosted search instance. Search queries are forwarded to the underlying search engines (e.g. DuckDuckGo), which may see them. This is inherent to how web search works. ## 6. What we do NOT do - We do **not** train models on your data. - We do **not** sell, rent, or share your data. - We do **not** use your data for advertising or profiling. ## 7. Third parties - **Tinfoil** — provides encrypted inference (cannot read your content). - **Open Collective** — handles billing and membership (their own privacy policy applies). - **Cloudron** — our self-hosted platform; no third-party cloud provider. - **Search engines** — receive your search queries (see §5). ## 8. Retention and deletion - Chat history is retained until you delete it. - On leaving, your account is deactivated (data preserved for reactivation). - You may request full deletion at any time: info@inference.coop. ## 9. Security - Self-hosted on Cloudron (sandboxed apps, SSL, backups). - Per-member API keys; access gated on live membership. - No external dependencies for core infrastructure. ## 10. Your rights - **Access, correct, export, and delete** your data. - As a member, you also have **governance** rights over this policy itself (through Loomio). ## 11. Children The service is for people **18 and older**. We do not knowingly collect data from children. ## 12. Changes We may update this policy as the project evolves. Material changes are announced to members and, where appropriate, decided through Loomio. ## 13. Contact **info@inference.coop**