Privacy Policy
Last updated: 1 August 2026 · Version: 2026-08-01.4
Relixr Ltd ("Relixr", "we", "us", or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal data when you use our website, dashboard, API, and related services (the "Services"). Capitalized terms not defined here have the meaning in our Terms of Service.
By using the Services, you acknowledge this Policy. If you do not agree, do not use the Services.
1. Who we are and roles
Relixr provides a prepaid AI inference interface and related account tools.
- For account, billing, security, and product administration data, Relixr typically acts as a controller.
- For prompts, completions, and other customer content that we process solely to fulfill your API requests under your instructions and configuration, Relixr typically acts as a processor. Our Data Processing Agreement at /trust/dpa describes that processing.
Controller contact: security@relixr.com.
2. Personal data we collect
Data you provide. Account registration and profile details (such as name, email, optional phone, country), authentication factors, workspace membership and roles, billing and tax details you submit, support messages, and legal acceptance or preference records.
Data collected automatically. Usage metadata such as model identifiers, token counts, cost, request identifiers, timestamps, approximate location or IP address where collected for security and abuse prevention, device and browser information, and diagnostic logs needed to operate the Services.
Payment data. Payment partners process card and local payment credentials. We receive limited payment status and transaction metadata, not full card numbers.
Inputs and outputs. Text or other content you send to models ("Inputs") and model responses ("Outputs") are transmitted to fulfill your requests. Prompt and completion bodies are not retained in Relixr logs unless you enable logging in your workspace data settings.
From third parties. We may receive information from payment partners, identity or fraud vendors, and model providers as needed to operate the Services.
We do not control how upstream model providers handle Inputs and Outputs under their own terms. Review the provider's practices for the models you choose. Relixr does not use your Inputs or Outputs to train models.
3. How we use personal data
We use personal data to:
- Provide, operate, secure, and improve the Services
- Transmit Inputs to model providers you select (or that routing selects) and return Outputs
- Process payments, credits, invoices, and tax records
- Authenticate users, protect accounts, and prevent fraud and abuse
- Communicate about the Services, security, and material policy changes
- Provide customer support
- Comply with law and enforce our Terms
- Produce aggregated, de-identified metrics about Service usage
Where required, we rely on one or more of: performance of a contract; legitimate interests (such as securing and improving the Services) balanced against your rights; consent (for example non-essential analytics or marketing where required); and legal obligation.
4. How we share personal data
We share personal data only as needed to operate the Services:
- Model providers you select (or that are selected by routing), to generate Outputs
- Infrastructure and operations vendors that host or support the Services under contract
- Payment partners that process purchases
- Professional advisors and authorities when required by law or to protect rights and safety
- A successor in connection with a merger, acquisition, or asset sale, subject to appropriate protections
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising. You may still use our Privacy Choices controls and Global Privacy Control (GPC) signals where applicable.
A current list of subprocessors is available on request via the Trust Center access form at /trust/request.
5. International transfers
We and our vendors may process personal data in countries other than your own, including outside the EEA, UK, and Switzerland. Where required, we use appropriate safeguards such as Standard Contractual Clauses (and UK transfer addenda where applicable), together with supplementary measures as needed.
6. Retention
We retain personal data only as long as needed for the purposes above, including:
| Category | Typical retention |
|---|---|
| Account profile | Life of the account, then up to 30 days after a verified deletion request (subject to legal holds) |
| Usage metadata | Up to 24 months, subject to product defaults |
| Prompt/completion logs (if enabled) | Per your workspace retention setting (for example 7, 30, or 90 days) |
| Billing and tax records | Up to 7 years where legally required |
| Legal acceptances | Duration of the account plus applicable limitation periods |
| Privacy request records | Up to 3 years after closure |
7. Security
We use administrative, technical, and organizational measures appropriate to the risk, including encryption in transit, access controls, workspace isolation, hashed API keys, and optional customer-configurable logging and guardrails. No method of transmission or storage is completely secure. See /trust for a plain-language overview.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing, to data portability, and to withdraw consent. California residents may have CCPA/CPRA rights including to know, delete, correct, and opt out of sale or sharing (we do not sell or share as described above).
Submit requests via Privacy Center (/dashboard/settings?tab=privacy), /privacy/request, or security@relixr.com. We may need to verify your identity. You may also lodge a complaint with your local supervisory authority.
9. Children
The Services are not directed to children under 16 (or the higher age required in your country). We do not knowingly collect personal data from such children. If you believe we have, contact security@relixr.com.
10. Cookies and similar technologies
We use essential cookies and similar technologies to operate the Services, and optional analytics technologies where permitted. Details are in our Cookie Policy at /cookies. In the EEA, UK, and Switzerland, non-essential analytics require opt-in where required by law. We honor stored declines and GPC signals for applicable opt-outs.
11. Changes
We may update this Privacy Policy from time to time. The "Last updated" date and version will change when we publish a revision. For material changes, we will provide additional notice where appropriate. Continued use after the effective date constitutes acceptance where permitted by law.
12. Contact
security@relixr.com
Latest privacy policy: /privacy