Privacy Policy
This Privacy Policy describes how 5CEOs, Inc. ("5CEOs", "we") collects, uses, and discloses information when you use the 5CEOs Service.
1. Information We Collect
- Account information: name, email, and billing details collected by our payments processor (Stripe).
- API requests: the prompts, messages, schemas, and other request fields you submit to
/v1/chat/completions. - API responses: the outputs returned by the inference engine.
- Telemetry: request timestamp, API key identifier, tenant identifier, model identifier, token counts, latency, schema-enforcement flag, request ID, HTTP status.
- Audit log: append-only record of metering events (the fields above) for billing reconciliation and operational diagnostics.
- Server logs: IP address, user-agent, and HTTP request metadata, retained for security and operational purposes.
2. How We Use Information
- To provide the Service (route requests to the inference engine, enforce quotas, return responses).
- To bill for usage (via Stripe; Compliance and Enterprise plans are invoiced separately).
- To detect and mitigate abuse, including violations of the Acceptable Use Policy.
- To diagnose operational issues, including correlating individual requests with system-level events.
- To publish aggregated, de-identified determinism and reliability metrics via the open-source bench (no individual request content is included).
3. What We Do NOT Do
- We do not train language models on Customer prompts or outputs.
- We do not sell or rent Customer data.
- We do not transmit Customer prompts or outputs to any third-party language-model API provider.
- We do not retain raw prompt or response bodies after the response is delivered to the Customer, with the exception of operational debugging windows described below.
4. Retention
- Prompt and response bodies: not retained after delivery to the Customer. (Operational note: anonymized request-level entries may exist in transient debug logs for up to 7 days for diagnostics.)
- Audit log (telemetry only): retained for 24 months for billing reconciliation. No prompt content is in the audit log.
- Server logs: retained for 90 days, then purged.
- Account and billing records: retained for the longer of the duration of the subscription plus 7 years, or as required by applicable tax or financial regulations.
5. Sub-processors
The following sub-processors receive Customer data in the course of providing the Service:
- Amazon Web Services, Inc. (us-east-1, or Customer-selected region for Enterprise) — hosts the gateway, the inference substrate, and the audit log. All Customer prompts and outputs are processed within AWS infrastructure under our account.
- Brave Software, Inc. — operates the third-party live web search provider used as a fallback grounding source when our substrate cannot resolve a query from training. The Customer's query text is sent to the search provider; the provider returns links and snippets that are used as grounding sources for the Customer's response. We do not transmit Customer identity, API key, or any other Customer metadata to the search provider.
- Resend, Inc. — delivers transactional email (welcome messages, key issuance receipts, billing notifications) to the Customer's verified email address. No Customer prompt, response, or substrate output is transmitted to the email provider.
- Stripe, Inc. — processes subscription payments and stores billing details. Subject to Stripe's privacy policy.
- OpenTimestamps calendar operators (the public OpenTimestamps calendar pool, operated by independent volunteers and organizations including Eternity Wall and Catallaxy) — receive opaque SHA-256 hashes of the audit-chain checkpoint state, which are then anchored to the Bitcoin blockchain to give Customer-verifiable proof that audit-log state existed at a point in time. The calendars receive only the cryptographic hash; no Customer prompt, response, identity, or metadata is transmitted. The protocol is documented at opentimestamps.org and any Customer can independently re-verify the anchor using the open-source
otsCLI without contacting our infrastructure. - GitHub, Inc. — hosts the open-source determinism bench and publishes aggregated reliability metrics. No Customer prompt or response content is published.
5CEOs will provide thirty (30) days' notice of any new sub-processor by updating this policy and notifying Compliance and Enterprise customers via email.
Conditional sub-processors (not currently active): a CRM-relay webhook (POST to a Customer-relationship-management system on subscription state changes) is supported by the gateway but is not configured in the current production deployment. If it is configured in the future, the destination will be added to this list as a sub-processor with thirty (30) days' notice before the data flow begins.
6. International Transfers
By default, Customer data is processed in AWS's us-east-1 region. Enterprise customers may select an alternative region (US-West, EU, APAC) under their order form. We do not transfer Customer prompts or outputs across regions without explicit Customer instruction.
7. Security
- All connections to the Service use TLS 1.2 or higher, terminated at an nginx ingress with a certificate issued by Let's Encrypt (90-day renewal cycle).
- API Keys are stored as SHA-256 hashes; plaintext values are only displayed once at issuance.
- Administrative credentials and API keys for sub-processors are stored in environment-file form on the host with restricted filesystem permissions, not in source code or version-controlled artifacts.
- The inference substrate (the LLM serving process) is bound to the loopback interface and is not reachable from the public internet; only the gateway can reach it.
- Compliance plans include SOC 2 Type II reports on request; Enterprise plans include the SOC 2 report and additional security review documentation under NDA.
8. Customer Rights
You have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Request deletion of your account and associated data (subject to legal retention requirements).
- Export your usage records.
- Object to or restrict processing (which may require account cancellation).
- Lodge a complaint with a supervisory authority (for GDPR jurisdictions).
To exercise these rights, contact support@5ceos.com.
9. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect information from children.
10. Changes to This Policy
We will post material changes here with a new "Last updated" date and notify Compliance/Enterprise customers via email at least 30 days in advance.
11. Contact
Privacy questions: support@5ceos.com.
Data Protection Officer / DPA requests: support@5ceos.com.