Privacy Policy
This policy explains what personal data the Sushila research project ("we") collects through sushila.ai, the model downloads and the Sushila serverless API, why, and your choices. We collect as little as we can.
1. What we collect
- Your account: the e-mail addresses you add and verify, your name and (optionally) organization, when you created the account and last signed in, and records of sign-ins and e-mail changes. Sign-in codes are stored only as a keyed hash and expire after 5 minutes.
- Downloads: for each download, which file, when, that you accepted its license, and the country of your connection.
- Early-access sign-up: the e-mail address and the optional list of models you enter, the time of sign-up and the country of your connection (derived by our hosting provider from your IP address). If you choose to e-mail us instead, we receive what you send.
- Requests to the website and downloads: our hosting provider, Cloudflare, processes your IP address, browser user agent, the pages and files requested and the time, to deliver the site, prevent abuse and keep it secure.
- Serverless API (when you use it): your account and billing details, API usage (such as token counts and times) for billing and capacity, and the Inputs and Outputs needed to answer each request.
The website sets one cookie, a signed session cookie, only when you sign in. It uses no advertising, no tracking cookies and no third-party analytics scripts. Copying a checksum uses your browser's clipboard locally.
2. Why we use it
- to provide the website, downloads and API, and to bill for the API (performance of a contract);
- to contact you about the early access you asked for (your consent, which you can withdraw at any time);
- to secure the Services, prevent abuse and fix problems (our legitimate interests);
- to meet legal, tax and accounting duties (legal obligation).
3. Prompts and outputs
API Inputs and Outputs are processed only to answer your requests. We do not use them to train models, and we do not sell them. We do not store them after a request completes, except as needed for short-term abuse prevention or debugging that you ask for, or where the law requires it.
4. Sharing
We do not sell or rent personal data. We share it only with service providers that process it for us under contract, such as Cloudflare (website hosting and network), Amazon Web Services (DynamoDB, where account and download records are stored), Backblaze (B2, where the files you download are stored), Resend (which sends sign-in codes), GPU cloud providers that run the API, and a payment processor for billing; with professional advisers; when the law requires it; or as part of a merger or sale of our business, under this policy.
5. International transfers
Our providers may process data in the United States and other countries. Where required, we use legal safeguards such as the European Commission's Standard Contractual Clauses.
6. How long we keep it
Account data and download records are kept while your account exists; ask us to delete your account and we will delete them, except where the law requires us to keep them. Early-access sign-ups are kept until you ask us to delete them or until early access ends and you have not become a customer, whichever is first. API account and billing records are kept for as long as your account is open and then as long as tax and accounting laws require. Hosting logs are kept by Cloudflare for a short period under its own policies.
7. Your rights
Depending on where you live (for example under the GDPR, the UK GDPR or California law), you may have the right to access, correct, delete or export your personal data, to object to or restrict its use, and to withdraw consent. E-mail contact@sushila.ai to make a request; we will answer within 30 days. You may also complain to your data protection authority. We do not sell or share personal data for cross-context behavioral advertising.
8. Security
Data is sent over HTTPS and stored with access limited to the people who need it. No system is perfectly secure; if a breach affects your data, we will notify you as the law requires.
9. Children
The Services are not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes
We will post any change here with a new effective date, and e-mail API customers and people on the early-access list about material changes.
11. Contact
The Sushila project, contact@sushila.ai.