Qloud/ TOKEN FACTORYOpen Models
Console login

LEGAL

Privacy Policy

Last updated: 24 September 2026

This Privacy Policy explains how Qernel AI, Inc., doing business as Qloud (Qloud, we, us), handles personal information when you use qloud.sh, the Qloud dashboard, or the Qloud API (the Services). Input and Output have the meanings in our Terms of Service.

1. Information we collect

  • Account: name, email address, sign-in details, and your organizations and roles.
  • Billing: billing details, credit purchases, top-up settings, and invoices. Card numbers go directly to our payment processor; we never see them.
  • Messages: what you send us through our contact form or by email.
  • Usage records: for each request, the organization and key used, model, token counts, cost, status, and timing. These do not contain the text of your prompts or responses.
  • API keys: name, limits, status, and last four characters. We store only a one-way hash of each key.
  • Technical data: IP address, browser, device, and pages visited, collected when you use the website or dashboard.

We use only cookies that are strictly necessary to sign you in, secure your session, and take payments. We do not use advertising, analytics, or tracking cookies.

2. How we use it

We use personal information to run your account, serve and bill API requests, enforce limits, prevent fraud and abuse, keep the Services secure and reliable, provide support, send service and billing notices, and meet legal obligations. We may send occasional product news where the law allows, and you can unsubscribe at any time.

3. Your prompts and responses

We don't store the text of your prompts or responses (your Input and Output). They pass through our systems, and those of the inference provider serving the request, only to generate the response, and are held in memory only while the request is served. If a request fails, our error logs may capture a short excerpt of the error message. We never use your prompts or responses to train or fine-tune models, and we never sell them. The self-serve API does not offer a Zero Data Retention guarantee; contact us about Dedicated capacity if you need one.

When a business customer includes personal information in its prompts, we process it on the customer's behalf, and that customer's privacy notice applies. Business customers can request a Data Processing Addendum.

4. How we share it

We share personal information only with:

  • Service providers that work for us under contract, such as providers of sign-in, payments, hosting, email, databases, and security monitoring. A current list is available on request;
  • Inference providers that run models on our behalf. We only route to providers that do not train on your data, though they may briefly keep it for abuse monitoring under their own terms;
  • your organization's administrators, who can see members' roles and usage;
  • authorities or others when required by law or needed to protect rights, safety, or security; and
  • a buyer or successor in a merger, acquisition, or sale of assets, who must honor this Policy.

We do not sell personal information or share it for targeted advertising.

5. How long we keep it

Information

Retention

Account information

While your account is open, and briefly after closure to settle billing and support

Usage and API key records

While your account is open, and afterwards as needed for billing, security, and disputes

Billing records

As long as tax law requires, generally seven years

Prompts and responses

Not stored beyond serving the request, apart from short error excerpts

Logs and messages

Only as long as needed to operate the Services or handle your enquiry

6. Security and transfers

We protect information with measures including encryption in transit, hashed API keys, and role-based access. No system is perfectly secure, and we will notify you of a breach as the law requires. We are based in the United States and may process information there and in other countries, using safeguards such as the EU Standard Contractual Clauses where required.

7. Your rights

Depending on where you live, you may ask to access, correct, delete, or receive a copy of your personal information, or object to or restrict its use. Email hello@qloud.sh from your account address. We will verify your identity and respond within the time the law requires. You may use an authorized agent, and you may appeal a refusal by replying to our decision or complain to your data-protection authority. We will not treat you differently for exercising these rights.

EEA, UK, and Swiss residents: we rely on contract, legitimate interests (security and service improvement), legal obligation, and, for marketing where required, consent.

U.S. residents: in the past 12 months we collected identifiers, commercial information, internet activity, professional information, and communications content, as described above, and disclosed them only to the recipients in Section 4. We do not sell or share personal information, or use sensitive personal information to infer characteristics, and we honor Global Privacy Control signals.

8. Children

The Services are for people 18 and over. We do not knowingly collect information from anyone under 18; contact us and we will delete it.

9. Changes

We may update this Policy and will change the date above. We will notify you of material changes by email or in the dashboard.

10. Contact

Qernel AI, Inc. (Qloud), 460 California Ave, Suite 205, Palo Alto, CA 94306

hello@qloud.sh