ColomboAI · Legal
Privacy Policy
Effective: August 23, 2026
This policy explains how ColomboAI handles personal information and Customer Content when you use Cairo, MC-1, our APIs, websites, consoles, and related services.
Scope and who we are
ColomboAI provides AI software, infrastructure, and the MC-1 adaptive intelligence control plane (the “Services”). This policy applies when ColomboAI determines how and why personal information is processed. A business customer may separately act as controller, with ColomboAI acting as its service provider or processor.
“Customer Content” means prompts, inputs, files, tool definitions and results, instructions, and model or system outputs submitted to or generated through the Services.
Information we collect
- Account and contact data, including name, work email, organization, authentication identifiers, role, project membership, support messages, and communication preferences.
- Customer Content needed to perform an authorized request.
- Usage and technical data, including request and route identifiers, provider selection, tokens, costs, timestamps, audit events, IP address, device/browser information, and security logs.
- Billing data and limited payment-method metadata; payment processors handle complete card details under their own policies.
- Information you direct identity, model, compute, or connected-service providers to make available to us.
How we use information
We use information to authenticate users; provide, route, evaluate, secure, support, and bill for the Services; enforce customer policies and budgets; prevent abuse; investigate incidents; maintain reliability; communicate about accounts; comply with law; and improve product performance.
We may use aggregated or de-identified statistics for analytics, capacity planning, security, and product improvement, and do not attempt to re-identify them.
AI inputs, outputs, and providers
MC-1 may transmit necessary Customer Content and request metadata to model, inference, cloud, tool, or customer-compute providers selected under your configuration and policy. Those recipients process the data to deliver the requested function and may operate in different regions.
Your agreement with a provider also governs customer-managed keys or endpoints. Provider-specific retention and training terms may apply unless a contract or verified route attribute provides a stronger commitment.
Training policy
ColomboAI does not use Customer Content to train shared or foundation models unless the customer gives explicit, documented authorization for a defined training purpose.
Customer-authorized adaptation or specialized-model workflows are separate from ordinary inference and require an authorized dataset, stated purpose, provenance, retention policy, secure storage reference, budget, and policy approval. We do not silently convert ordinary prompts or completions into training data.
Customers requiring no-training or zero-data-retention processing must select and verify an eligible provider route or customer-controlled compute.
How we disclose information
We disclose information to providers that help operate the Services, to customer-authorized integrations, during a corporate transaction, or when reasonably necessary to comply with law, protect rights and safety, or prevent fraud and abuse.
We do not sell personal information, share it for cross-context behavioral advertising, or disclose Customer Content for a recipient’s independent marketing.
Prompt, completion, and metadata retention
By default, MC-1 does not durably retain raw prompts or completion bodies after an inference request finishes.
Request content may exist transiently while processed or streamed. ColomboAI retains it beyond that point only when a customer explicitly enables storage, submits it for support or recovery, authorizes defined training, or limited retention is reasonably necessary for security, fraud prevention, disputes, or law.
Operational metadata—excluding raw prompt and completion bodies—is generally retained for 7 days on Free, 30 days on Developer, 90 days on Pro, 365 days on Team, and up to seven years for Business or contractually governed accounts. Billing, security, audit, fraud-prevention, and legal records may be retained longer where required.
Security
We use safeguards including scoped access, authentication, tenant and project boundaries, credential hashing or secret references, transport encryption, audit controls, and incident response. No transmission or storage method is completely secure.
Your choices and privacy rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information; object to or restrict processing; withdraw consent; and appeal a decision. Submit requests to [email protected]. We may verify identity and authority before acting.
Children
The Services are intended for businesses and adults and are not directed to children under 13. We do not knowingly collect personal information from children under 13.
International processing
ColomboAI is based in the United States. The United States ISO 3166-1 alpha-2 inference country code is US. We and authorized providers may process information in the United States and other locations associated with a route, using recognized transfer safeguards where required.
Changes and contact
We may update this policy prospectively and will post a new effective date and give additional notice when required. We will not retroactively use Customer Content for materially different purposes without appropriate notice and authorization.
Questions or privacy requests: [email protected]. ColomboAI, 15804 Carriage House Rd, Edmond, Oklahoma 73013, United States.