Legal
Privacy policy.
Last updated: May 3, 2026. The short version is on this page. The long version is in the DPA.
What we collect.
- Account data: your email, name, org name, password hash. Used to log you in and send you billing emails.
- Fleet metadata: fleet names, node hostnames, GPU model, agent version, public_address you set. Used to show you a useful dashboard.
- Metering events: request_id, timestamp, model name, status code, latencies, token counts, hashed client IP, error code. Used to bill, alert, and dashboard. Never the prompt or completion content.
- Audit log: who logged in, who created/revoked keys, who changed budgets. Used for your own forensics.
What we do NOT collect.
- Prompts or completions sent through your gateway.
- Model weights, custom checkpoints, fine-tunes.
- Plaintext API keys (we hash with HMAC+SHA256 + per-org pepper at create time and never see plaintext again).
- Plaintext end-user IPs (only the SHA-256 prefix).
Where we store it.
Postgres in our cloud (currently AWS Mumbai region). All at-rest encrypted. RLS-isolated per org. Backups encrypted with KMS keys we hold.
Who else sees it.
Nobody, unless legal process compels disclosure (in which case we notify you first when allowed). We never sell, share, or sublicense your data. We don't use it to train any model.
How long we keep it.
- Audit log: 7 days for free tier, 90 days for Team, configurable for Enterprise.
- Usage events: 30 days raw, then aggregated to hourly rollups.
- Account data: until you delete your account, then purged within 30 days.
Your rights.
You can export everything, delete everything, or ask us a question. Email privacy@huxkan.com. We respond within 7 days.