COLOMBOAI · PRIVACY

Privacy Policy

This policy explains how ColomboAI handles personal information and Customer Content when you use Cairo, MC-1, our APIs, websites, consoles, and related services.

Effective
August 23, 2026
Operator
ColomboAI
Contact
[email protected]

Scope and who we are

ColomboAI provides AI software, infrastructure, and the MC-1 adaptive intelligence control plane (collectively, the “Services”). This Privacy Policy applies when ColomboAI determines how and why personal information is processed. A business customer may separately act as the controller of information it submits, with ColomboAI acting as its service provider or processor under the applicable agreement.

“Customer Content” means prompts, inputs, files, tool definitions and results, instructions, and model or system outputs submitted to or generated through the Services.

Information we collect

  • Account and contact data: name, work email, organization, authentication identifiers, role, project membership, support messages, and communication preferences.
  • Customer Content: content and instructions needed to perform an authorized request, including content supplied through APIs or connected tools.
  • Usage and technical data: request and route identifiers, model and provider selection, token and cost measurements, timestamps, feature activity, audit events, IP address, device/browser information, and diagnostic or security logs.
  • Billing data: plan, credit, invoice, transaction, and limited payment-method metadata. Payment processors handle complete payment-card details under their own policies.
  • Information from integrations: data you direct an identity provider, model provider, compute provider, or connected service to make available to us.

How we use information

We use information to authenticate users; provide, route, evaluate, secure, support, and bill for the Services; enforce customer policies and budgets; prevent abuse; investigate incidents; maintain reliability; communicate about accounts; comply with law; and improve product performance.

We may create aggregated or de-identified statistics that are not reasonably linked to an individual or customer and use them for analytics, capacity planning, security, and product improvement. We do not attempt to re-identify de-identified information.

AI inputs, outputs, and providers

MC-1 is a control plane. To fulfill a request, it may transmit necessary Customer Content and request metadata to the model, inference, cloud, tool, or customer-compute providers selected under your configuration and policy. Those recipients process the data to deliver the requested function and may operate in different regions.

Where you use your own provider key or endpoint, your agreement with that provider also governs its processing. For managed routes, ColomboAI selects eligible providers based on configured capability, security, privacy, region, availability, cost, and quality constraints. Provider-specific retention and training terms may apply unless a contract or verified route attribute provides a stronger commitment.

Training policy

ColomboAI does not use Customer Content to train shared or foundation models unless the customer gives explicit, documented authorization for a defined training purpose.

Customer-authorized adaptation or specialized-model workflows are separate from ordinary inference. They require an authorized dataset, stated purpose, provenance, retention policy, secure storage reference, budget, and policy approval. We do not silently convert ordinary prompts or completions into training data.

Third-party model providers receive Customer Content only to perform an authorized route. Their independent training practices are governed by the selected provider, route configuration, and applicable contract. Customers that require no-training or zero-data-retention processing must select and verify an eligible provider route or customer-controlled compute.

How we disclose information

We disclose information to infrastructure, identity, payment, support, analytics, security, model, and inference providers that help operate the Services; to customer-authorized integrations; during a corporate transaction; or when reasonably necessary to comply with law, protect rights and safety, or prevent fraud and abuse.

We do not sell personal information or share it for cross-context behavioral advertising. We do not disclose Customer Content for a recipient’s independent marketing.

Prompt, completion, and metadata retention

By default, MC-1 does not durably retain raw prompts or completion bodies after an inference request finishes. Request content may exist transiently in memory while it is processed or streamed. ColomboAI retains it beyond that point only when the customer explicitly enables content storage, submits it for support or recovery, authorizes a defined training workflow, or when limited retention is reasonably necessary for security, fraud prevention, dispute handling, or law.

Customer-configured content storage follows the period shown in that configuration or contract and can be deleted through the applicable controls. Customer-authorized training data follows the dataset-specific retention policy. Selected model, inference, cloud, and tool providers may apply their own retention periods; customers requiring zero-data-retention processing must select and verify an eligible route or customer-controlled compute.

Operational activity metadata—such as route IDs, selected models and providers, timestamps, tokens, cost, latency, and status, but not raw prompt or completion bodies—is retained according to the customer’s plan or contract: generally 7 days for Free, 30 days for Developer, 90 days for Pro, 365 days for Team, and up to seven years for Business or contractually governed accounts. Billing, security, audit, fraud-prevention, and legal records may be retained longer where required. We delete or de-identify information when the applicable purpose and retention period end, subject to backups and legal holds.

Security

We use administrative, technical, and organizational safeguards designed for the nature of the information, including scoped access, authentication, tenant and project boundaries, credential hashing or secret references, transport encryption, audit controls, and incident response. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If you believe an account or credential is compromised, contact us promptly and revoke affected keys through the console.

Your choices and privacy rights

Depending on where you live, you may have rights to know or access, correct, delete, or obtain a copy of personal information; object to or restrict certain processing; withdraw consent; opt out of a sale or targeted-advertising sharing; limit certain uses of sensitive information; and appeal a decision. We do not discriminate against anyone for exercising applicable privacy rights.

Submit a request to [email protected]. Describe the right you wish to exercise and the account or organization involved. We may verify identity and authority before acting. An authorized agent may submit a request where permitted by law. Business customers should first direct end-user requests to the organization controlling their data.

Cookies and communications

We use essential cookies or similar technologies for authentication, security, session continuity, preferences, and service operation. We may use limited measurement technologies to understand product performance. Browser controls can restrict some technologies, but disabling essential storage may prevent sign-in or other functions.

You may opt out of non-transactional marketing messages using the instructions in the message. We may still send security, billing, account, or service notices.

Children

The Services are intended for businesses and adults and are not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.

International processing

ColomboAI is based in the United States. For provider applications and inference-location fields, the United States ISO 3166-1 alpha-2 country code is US. We and our providers may process information in the United States and other locations associated with an authorized route. Where required, we use contractual or other recognized transfer safeguards. Customers can use region, privacy, sovereign, provider, and customer-compute controls to constrain eligible execution routes.

Changes and contact

We may update this policy to reflect changes in the Services, law, or our practices. We will post the revised policy with a new effective date and provide additional notice when required. We will not retroactively use Customer Content for materially different purposes without appropriate notice and authorization.

Questions or privacy requests: [email protected]
ColomboAI, Edmond, Oklahoma, United States.