Skip to content

Privacy policy

This Privacy Policy describes how Standard Thinking, Inc. (“Standard Thinking,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information when you visit our websites, create an account, use our APIs and related services, or communicate with us.

Our core commitment. We process Customer Content on your behalf to provide, operate, secure, and support the Services you request, and as required by law. Processing, caching, and retention depend on the service and configuration; ZDR applies where expressly specified. We do not use Customer Content for our independent purposes unless you separately and expressly authorize that use or that use is expressly permitted under Section 5.3 of the Terms of Service. We do not use Inputs or Outputs to train public or shared models unless you give a separate, explicit opt-in or that use is expressly permitted under Section 5.3 of the Terms of Service.

1. Scope and processing roles

This Policy applies when Standard Thinking determines why and how personal information is processed, including website, account, billing, sales, and support data. When we process personal information contained in Customer Content solely on a business customer’s instructions, that customer is the controller or business and Standard Thinking acts as its processor or service provider. In that situation, the customer’s privacy notice governs the individuals whose data appears in Customer Content.

This Policy does not cover third-party websites or services that have their own privacy practices.

2. Information we collect

Information you provide

  • Account information: name, email address, organization, role, authentication details, and account preferences.
  • Billing information: billing contact, transaction details, tax information, and payment status. Our payment processor handles full payment-card details.
  • Customer Content: Inputs submitted to the Services, Outputs returned by selected models, and data you designate for customer-enabled storage features. Processing and retention follow the applicable service terms described in Section 3.
  • Communications: support requests, sales inquiries, survey responses, feedback, and any content you choose to share with us.

Information collected automatically

  • Service metadata: model identifier, token counts, timestamps, latency, status and error codes, routing decisions, feature use, and project or account identifiers.
  • Device and network data: IP address, browser and device type, operating system, approximate location derived from IP, referring page, and security events.
  • Cookies and similar technologies: information needed for authentication, preferences, security, analytics, and site performance.

Information from other sources

We may receive information from an organization that invites you to its account, identity and login providers, payment processors, cloud marketplaces, resellers, security vendors, and public business sources.

3. Customer Content and inference data

We process Customer Content on your behalf to provide, operate, secure, and support the Services you request, and as required by law. This may involve temporary buffers, queues, prompt or KV caches, and intermediate processing data reused across requests. Methods and durations depend on the service, configuration, and technical requirements, subject to the limits in the Data Processing Policy, §4. Temporary processing data is kept only as long as reasonably necessary for the applicable function and is then cleared through the relevant service processes. We do not promise a fixed cache lifetime or immediate deletion of all processing data after each response.

Zero Data Retention (“ZDR”) applies only where expressly identified for a service or configuration in the product description, service documentation, or customer agreement. For covered inference, Inputs and Outputs are not retained as content logs, histories, backups, or other persistent content records. Any permitted temporary inference caching is governed by the applicable ZDR terms. This commitment does not extend to separately enabled storage features, material voluntarily provided for support or feedback, or copies kept by your application or other services you use.

Storage through the Product Plan data platform is optional. When you enable it, we retain the data you designate to provide that feature on your behalf, outside the scope of inference ZDR. Other customer-enabled features that require retained content, such as history, response caching, batch processing, retrieval, evaluations, fine-tuning, and stored model assets, follow their disclosed retention terms. Enabling storage does not remove a ZDR commitment from separately covered inference processing or authorize independent use of Customer Content.

We may retain content-free service metadata, including model identifier, token counts, timestamps, latency, region, routing decisions, status and error codes, non-reversible safety signals, and project or account identifiers, to meter usage, bill customers, investigate reliability, enforce limits, detect abuse, and improve platform performance.

We do not use Customer Content for our independent purposes unless the customer separately and expressly authorizes that use or that use is expressly permitted under Section 5.3 of the Terms of Service. We do not use Inputs or Outputs to train public or shared models unless the customer gives a separate, explicit opt-in or that use is expressly permitted under Section 5.3 of the Terms of Service. Subprocessors must follow the processing and retention restrictions applicable to the service, including materially equivalent ZDR restrictions where a ZDR commitment applies.

4. How we use information

Our use of Customer Content remains subject to the purpose and retention limits in Section 3.

We use personal information to:

  • provide, maintain, route, personalize, and improve the Services;
  • create and administer accounts, projects, permissions, API keys, and billing;
  • authenticate requests and control access using authentication credentials and relevant account information;
  • respond to support, security, sales, and product inquiries;
  • monitor availability, diagnose errors, plan capacity, and measure performance;
  • detect fraud, abuse, prohibited use, credential compromise, and security threats;
  • communicate service, policy, billing, and product updates;
  • comply with law, enforce agreements, and protect rights and safety; and
  • create aggregated or de-identified statistics that cannot reasonably identify an individual.

5. How we disclose information

We may disclose information to:

  • Vendors and subprocessors that provide cloud infrastructure, model execution, payments, authentication, communications, analytics, support, and security services under appropriate restrictions.
  • Your organization and its account administrators, who may manage your access and view activity associated with the organization.
  • Professional advisers such as auditors, insurers, lawyers, and accountants where reasonably necessary.
  • Authorities or other parties when required by law or reasonably necessary to protect the rights, safety, and integrity of Standard Thinking, our customers, or the public.
  • A transaction counterparty in connection with a financing, merger, acquisition, reorganization, or sale of assets, subject to customary confidentiality protections.

We do not sell personal information or share it for cross-context behavioral advertising. We may disclose aggregated or de-identified information that cannot reasonably be linked to an individual.

6. Retention and deletion

Inference and temporary processing: retention and caching depend on the service and configuration, subject to Section 3 and any applicable ZDR commitment. Temporary processing data is cleared through the relevant expiration, eviction, or deletion processes after it is no longer reasonably needed for the applicable function.

Customer-directed storage: content stored through the optional Product Plan data platform, other customer-enabled storage features, or a voluntarily provided support workflow follows the retention periods and controls described in the product, documentation, or customer agreement. Unless a specific period is stated, it is kept only as long as reasonably needed for the customer-directed function, requested support, or applicable legal obligations, and is then deleted or returned through the relevant service processes.

Deletion and backups: disabling a feature does not by itself require immediate deletion of previously stored data. Deletion may take a reasonable period to propagate, and backup copies may remain until the applicable replacement or deletion cycle, subject to law and contractual commitments. Remaining copies are restricted to recovery, security, or legal preservation purposes and are not used for independent purposes.

Account, billing, support, and service metadata: we retain this information only for as long as reasonably needed to provide the Services, maintain business and tax records, resolve disputes, enforce agreements, protect the platform, and meet legal obligations. Backup copies of information that is eligible for storage may remain for a limited period until overwritten.

We may preserve information already in our possession when required by law or a legal hold, or as reasonably necessary for fraud prevention or a live security investigation, subject to applicable law and contractual commitments. This does not authorize collecting content records that an applicable ZDR commitment prohibits or overriding a stricter signed agreement.

7. Security

We use administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest where appropriate, access controls, logging, monitoring, and incident response procedures. No system is completely secure, and we cannot guarantee absolute security.

You are responsible for securing your applications, devices, accounts, and API keys. See our Security Policy for more information.

8. International processing

We and our service providers may process information in the United States and other countries where privacy laws differ from those where you live. Where required, we use recognized transfer mechanisms and contractual safeguards. Enterprise customers may contact us about regional processing options and a data processing addendum.

9. Your privacy rights

Depending on your location, you may have rights to access, correct, delete, or obtain a copy of personal information; restrict or object to processing; withdraw consent; or appeal a denied request. You may also have the right to use an authorized agent and to receive equal service without unlawful discrimination for exercising a privacy right.

To submit a request, email contact@standardthinking.ai. We may verify your identity and authority before responding. If we process your information only for one of our business customers, we may direct the request to that customer.

California and other U.S. state disclosures

Subject to applicable law, residents may request the categories and specific pieces of personal information collected, the sources and purposes of collection, the categories of recipients, correction, or deletion. We do not sell personal information or share it for cross-context behavioral advertising, and therefore do not offer a sale or sharing opt-out. We do not use or disclose sensitive personal information to infer characteristics beyond purposes permitted by law.

10. Children

The Services are intended for business and developer use and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact us so we can take appropriate action.

11. Changes and contact

We may update this Policy to reflect changes in our practices, technology, or legal obligations. We will post the revised Policy, update the date above, and provide additional notice when required by law.

For questions, complaints, or privacy requests, contact Standard Thinking, Inc. at contact@standardthinking.ai.

All policies · Contact us about this policy