Effective July 10, 2026

Privacy for Inferock.

OpiusAI ("Inferock", "we", "us") provides reliable and accountable LLM inference with per-call evidence. This policy explains what data each surface processes and where the evidence boundary sits.

Review status

Last updated

July 10, 2026. Material changes will be posted here, and account holders may receive notice by email.

Local bench stays local

inferock-bench keeps provider keys, local event logs, and receipts on your machine unless you choose to share them.

Hosted Inferock evidence

The hosted proxy stores per-call usage, receipt, and failure evidence. BYOK provider keys are stored in the KMS-backed vault.

Review status

Effective and last updated: July 10, 2026.

This policy covers the public website, hosted Inferock, and the local inferock-bench posture where this page links to those public docs. This policy is under periodic legal review.

The policy is written the way Inferock writes receipts: concrete controls, concrete data paths, and no certification or recovery claim that is not backed by shipped product reality.

Data collected

Data categories by surface.

Website, waitlist, and contact information

If you submit a form or contact us, we collect the information you provide, such as name, work email, company, role, and message content. Requests to the website also necessarily include network information such as IP address, browser or user-agent, requested URL, referrer, and timestamp.

Account and workspace records

Hosted Inferock accounts may include user and admin email addresses, tenant or workspace identifiers, authentication and session records, onboarding state, support messages, plan or order-form records, and Inferock API key metadata. Inferock API keys are not stored back in plaintext after issuance.

Hosted proxy evidence

When you route traffic through hosted Inferock, we process the request body to send it to the selected model provider and to create measurement evidence. Stored canonical events include items such as tenant, provider, model, route, request identifiers, operation identifiers, status, timing, usage, cache fields, pricing status, body hash, optional request-secret digests, response content, tool calls, tool schema metadata, provider safety fields, citations, raw usage fields, and derived failure signals.

BYOK key handling

In hosted BYOK mode, customer provider API keys are stored per tenant in the key vault. The shipped key path uses AWS KMS envelope encryption with tenant encryption context, a customer-managed KMS key with rotation enabled, and a DynamoDB key-vault table with AWS-managed table encryption, point-in-time recovery, and TTL for rotated records. Plaintext keys are used only as needed to verify or route provider requests.

Local inferock-bench records

inferock-bench is different from hosted Inferock. It runs on localhost by default. Provider keys stay in the local environment or local config file, local events are written under the user's inferock-bench home, and receipts stay local until the user copies, posts, attaches, or otherwise shares them. Local event files can contain response text, tool calls, tool schemas, model names, usage fields, timing, selected provider IDs or headers, and detector evidence.

Billing and commercial records

For paid or approved customer use, we may process order forms, plan records, account status, invoicing details, tax details, billing contacts, payment status, and service-mode information. Fees and economics are governed by the applicable order form or plan, not this policy.

How data is used

How data is used.

We use data to run the service, route calls, preserve evidence, secure accounts, and answer customer requests. We do not turn a receipt into a recovery promise or a compliance certification.

Operate Inferock

Authenticate tenants, route provider calls, verify BYOK keys, stream provider responses, maintain account state, and keep the dashboard usable.

Produce loss reports

Create per-call receipts, usage records, failure signals, billing-integrity checks, loss report rows, and remedy-status evidence.

Administer accounts

Manage onboarding, support, billing, notices, security reports, customer requests, and waitlist or product communications.

Security and compliance

Detect abuse, investigate errors, maintain emission-completeness evidence, enforce terms, respond to legal obligations, and protect the service.

Sub-processors and sharing

Vendors and disclosures.

We share data only where needed to provide the service, follow customer-directed provider choices, comply with law, protect the service, or complete ordinary business operations.

Cloud hosting

Hosted Inferock runs on Amazon Web Services. The product code uses AWS services including Lambda, DynamoDB, KMS, SSM Parameter Store, SNS, SQS, Aurora PostgreSQL, CloudWatch, Cognito, S3, and CloudFront. The primary product AWS region is US West (Oregon), in the United States; edge assets may use AWS edge regions.

Model providers

When a customer selects a model provider, prompts, responses, request metadata, and provider credentials or account context needed for the call are sent to that provider. In BYOK, the provider account and provider terms are the customer's. In Managed, provider handling is governed by the applicable order form.

Commercial systems

We may share account, support, billing, and contact records with service providers that help us operate the business. We will update this policy or customer terms before materially expanding subprocessors for hosted customer data.

Analytics and observability

The shipped hosted path uses CloudWatch logs and product databases for operational telemetry and evidence persistence. inferock-bench does not send local receipt or event telemetry to Inferock unless the user chooses to share it.

Legal and safety disclosures

We may disclose information when required by law, to enforce our terms, to investigate abuse or security issues, to protect rights or safety, or as part of a merger, financing, acquisition, or similar corporate transaction.

Sub-processor updates

The currently identified infrastructure subprocessor for hosted product data is AWS. Customer-selected model providers are customer-directed recipients in BYOK and order-form governed in Managed mode.

Retention

Default periods

Hosted call-event records and derived report data are retained for service reporting and evidence review. The deployed data-plane maintenance job is configured with an 18-month partition retention window. CloudWatch log groups shown in the product infra are generally configured for one month. The emission ledger is a 30-day TTL operational ledger, and the ingest dead-letter queue retains messages for 14 days.

Deletion

Customer controls

Customers may request deletion of account records, hosted provider keys, and hosted customer data by emailing founders@opiusai.com. We may retain information where needed for security, legal compliance, billing records, dispute handling, or legitimate operational evidence.

International transfers

Location and transfer terms

The hosted product's primary AWS region is US West (Oregon), in the United States. If you use Inferock from outside the United States, your information may be processed in the United States and wherever customer-selected model providers process routed calls.

Security

Concrete controls in the shipped path.

Encryption and isolation

Hosted provider keys are encrypted with KMS envelope encryption, tenant encryption context, and a retained KMS key with rotation enabled. DynamoDB tables for key vault, API keys, and onboarding are configured with AWS-managed encryption where shown in the infra code. Request digest secrets are read from SSM SecureString, and service roles are scoped to the DynamoDB, KMS, SNS, SSM, and ledger actions they need.

Incident response

We triage credible reports about key storage, routing, local auth, telemetry, or package integrity at founders@opiusai.com. We have not claimed SOC 2, ISO, HIPAA, or similar certifications on this page.

Bring Your Own Keys

BYOK and Managed have different data postures.

In BYOK, the customer keeps its own provider account and provider bill. Inferock stores the customer provider key in the hosted key vault, uses it to route selected calls, and stores evidence for usage, receipts, and failure analysis. BYOK reporting is visibility on the customer's own provider bill; it is not a promise that OpiusAI will recover or credit every provider-side issue.

In Managed mode, OpiusAI may operate the provider relationship as part of the service only where separately approved in the applicable order form or plan. Managed credits, if any, are bounded service credits under those terms.

User rights

Rights, choices, and customer roles.

You may request access, correction, deletion, export, or marketing opt-out by emailing founders@opiusai.com. We may need to verify your identity and may route organization-controlled data requests through the customer's administrator. We may deny or limit requests where the law permits, including for security, billing, legal, or dispute-preservation reasons.

Processor/controller roles

For hosted customer traffic, OpiusAI generally processes customer data to provide the service under the customer's instructions and applicable order terms. For account, website, support, security, billing, and business records, OpiusAI uses data to administer and protect the service.

Inferock is not directed to children under 13. We do not sell personal information, and this policy does not permit us to sell hosted customer prompts, responses, provider keys, receipts, or local bench files.

Contact and effective date

Questions and privacy requests.

Privacy contact

Email founders@opiusai.com for privacy requests, security reports, and data questions.

Effective date

Effective July 10, 2026. Last updated July 10, 2026.