Privacy Policy
LogionOS Inc. ("LogionOS," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI compliance platform, APIs, dashboard, browser extension, and related services (collectively, the "Service").
1. Information We Collect
1.1 Account Information
When you register for the Service, we collect:
- Email address
- Organization name
- API key credentials (generated by our system)
1.2 Compliance Query Data
When you submit queries to the LogionOS API for compliance analysis, we process:
- The text content of your query (input)
- The jurisdiction selection
- Compliance check results (matched rules, risk scores, actions)
1.3 Usage Data
We automatically collect:
- API request timestamps and response times
- Feature usage patterns (dashboard pages visited, reports generated)
- Error logs for debugging and service improvement
1.4 Information We Do NOT Collect
- We do not collect or store passwords (authentication is API key-based)
- We do not collect payment card information directly (handled by third-party processors)
- We do not collect biometric data
2. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Provide and operate the compliance checking service | Performance of contract |
| Generate audit logs and compliance reports | Performance of contract |
| Monitor service performance and uptime | Legitimate interest |
| Improve service quality and accuracy | Legitimate interest |
| Send service notifications and updates | Performance of contract |
| Comply with legal obligations | Legal obligation |
| Train and improve compliance detection models (opt-in only) | Consent |
2.1 Machine Learning and Compliance Intelligence
By default, LogionOS does not use your compliance query content to train machine learning models. Your submitted content is processed in real-time for compliance analysis and stored only as part of your audit logs (as cryptographic hashes, not raw text).
Opt-In Compliance Intelligence: You may choose to participate in our Compliance Intelligence program, which uses anonymized and de-identified compliance telemetry to improve our detection models. If you opt in:
- Query content undergoes automated PII removal and anonymization before processing
- Only compliance-relevant patterns (e.g., regulation matches, risk classifications) are retained
- Your data is aggregated with other participants — individual queries are never identifiable
- You may opt out at any time via Dashboard settings; previously contributed data remains anonymized in aggregate datasets
Founder Program participants are encouraged to opt in as part of the program's value exchange. Enterprise customers on dedicated plans may negotiate custom data handling terms.
3. Data Retention
- Audit Logs: Retained for the duration of your account plus 90 days after termination, unless you request earlier deletion.
- Account Information: Retained as long as your account is active. Deleted within 30 days of account closure.
- Usage Data: Aggregated and anonymized data may be retained indefinitely for analytics purposes.
3.1 Legacy Creator Risk Layer (discontinued) — Historical Receipt Retention
The Legacy Creator Risk Layer is discontinued and is not a currently offered product. The following terms remain solely to document historical processing obligations for session receipts generated while that service was active. Each receipt was a hash-chained record of the checks the extension ran and the signals returned.
| Historical Plan | Receipt Retention |
|---|---|
| Trial | 7 days after the receipt was closed |
| Basic | 30 days |
| Team | 90 days (authorized team members could view team receipts within this window) |
| Enterprise | 365 days, or a custom term in the applicable Master Services Agreement |
Customers could export receipts as signed JSON bundles before the applicable retention window closed; Team customers could also export PDF copies. Exported copies remain under the customer's control.
3.2 Legacy Creator Risk Layer (discontinued) — Creator Telemetry
By default, raw query text from historical Creator Risk Layer checks was not retained beyond the hash-chained event entries needed to produce receipts. Receipt events referenced a SHA-256 hash of the check payload, while structural metadata included target venues, action_type, fired rule IDs, and safety_status.
Customers could opt in to Creator Telemetry. When enabled, anonymized, PII-removed snippets of checks that fired strong disclosure rules were retained solely to improve historical risk-signaling accuracy. Opting out stopped new telemetry collection; previously anonymized aggregate data could remain without a link to the account.
4. Data Sharing and Disclosure
We do not sell your personal information. We may share information only in the following circumstances:
- Service Providers: Cloud hosting providers (for infrastructure operation only), subject to data processing agreements
- Legal Requirements: When required by law, court order, or governmental authority
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with notice to affected users
- With Your Consent: When you explicitly authorize disclosure
5. Data Security
We implement industry-standard security measures including:
- TLS 1.2+ encryption for all API communications
- Unique API keys per account with role-based access control (RBAC)
- 4 permission levels: admin, developer, auditor, viewer
- Audit logging of all system access and data modifications
- Regular security assessments and monitoring
6. International Data Transfers
Our Service is hosted on infrastructure that may process data in the United States. If you are located outside the United States, your data may be transferred to and processed in the US. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy and applicable data protection laws.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Rectification: Request correction of inaccurate personal data
- Deletion: Request deletion of your personal data
- Data Portability: Request your data in a structured, machine-readable format
- Objection: Object to processing of your personal data
- Restriction: Request restriction of processing in certain circumstances
To exercise any of these rights, please contact us at chris.ma@logionos.com. We will respond within 30 days.
8. Jurisdiction-Specific Provisions
8.1 European Economic Area (GDPR)
If you are in the EEA, we process personal data under the legal bases described in Section 2. You have the right to lodge a complaint with your local data protection authority.
8.2 California (CCPA/CPRA)
California residents have the right to know what personal information is collected, request deletion, and opt out of the sale of personal information. We do not sell personal information.
8.3 Japan (APPI)
We comply with the Act on the Protection of Personal Information. Japanese residents may request disclosure, correction, or deletion of personal data by contacting us.
8.4 United Kingdom (UK GDPR)
UK residents have equivalent rights under the UK GDPR. Our data protection practices comply with the requirements of the UK Data Protection Act 2018.
8.5 Singapore (PDPA)
We comply with the Personal Data Protection Act 2012 (as amended). Singapore residents may contact us to access or correct personal data.
9. Chrome Extension
The LogionOS Chrome Extension provides real-time AI interaction compliance monitoring for enterprise deployments, scanning queries on supported AI platforms (ChatGPT, Claude, Google Gemini) against your organization's configured compliance rules before they leave the browser. The following disclosures apply specifically to the extension:
| Permission | Purpose |
|---|---|
storage | Save user preferences, daily statistics, and recent check history locally in Chrome |
activeTab | Detect which AI platform tab is active |
scripting | Inject the compliance interceptor on supported AI platform pages |
| Host permissions | Run content scripts on chatgpt.com, chat.openai.com, claude.ai, gemini.google.com only |
| Optional host permissions | Connect to user-configured API endpoint (requested only when a custom API URL is set for on-premise deployments) |
- The extension only activates on the AI platform domains listed above
- Query text is sent only to the user-configured LogionOS API endpoint for compliance analysis; raw text is not stored server-side beyond the hash-chained audit log entry required to produce your compliance record
- All settings, statistics, and local check history are stored locally in
chrome.storage.local - The extension does not collect browsing history, personal information outside the prompt, or AI responses
- The extension does not contain remote code loading — all logic is bundled in the package
- Organizations using on-premise API deployments retain full control over all data processing
10. Founder Program
If you participate in the LogionOS Founder Program, the following additional data practices apply:
10.1 Application Data
When you apply to the Founder Program, we collect:
- Company name, website, and product description
- Founder name and email address
- Country, team size, funding information, and revenue status
- Industry vertical, target market, and use case type
This data is used to evaluate your application, manage Program participation, and conduct internal analytics about represented industries and regions.
10.2 Program Analytics
During Program participation, we track:
- API key activation date and first and last usage timestamps
- Aggregate API usage volumes, not individual query content
- Account status within the Program lifecycle
This data helps us monitor Program health and identify participants who may need support or are approaching usage limits.
10.3 Aggregated Data
Anonymized, aggregated Founder Program statistics may be used for product improvement, internal reporting, and investor communications. No individual company data is disclosed without explicit written permission.
11. Cookies and Tracking
Our website uses minimal cookies for essential functionality only. The Enterprise Dashboard uses localStorage for session management. We do not use third-party advertising trackers.
12. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we discover we have collected data from a child, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website with a new "Last updated" date.
14. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact:
LogionOS Inc.
Data Protection Inquiries
Email: chris.ma@logionos.com
Website: https://logionos.com