Website, waitlist, and contact information
If you submit a form or contact us, we collect the information you provide, such as name, work email, company, role, and message content. Requests to the website also necessarily include network information such as IP address, browser or user-agent, requested URL, referrer, and timestamp.
Account and workspace records
Hosted Inferock accounts may include user and admin email addresses, tenant or workspace identifiers, authentication and session records, onboarding state, support messages, plan or order-form records, and Inferock API key metadata. Inferock API keys are not stored back in plaintext after issuance.
Hosted proxy evidence
When you route traffic through hosted Inferock, we process the request body to send it to the selected model provider and to create measurement evidence. Stored canonical events include items such as tenant, provider, model, route, request identifiers, operation identifiers, status, timing, usage, cache fields, pricing status, body hash, optional request-secret digests, response content, tool calls, tool schema metadata, provider safety fields, citations, raw usage fields, and derived failure signals.
BYOK key handling
In hosted BYOK mode, customer provider API keys are stored per tenant in the key vault. The shipped key path uses AWS KMS envelope encryption with tenant encryption context, a customer-managed KMS key with rotation enabled, and a DynamoDB key-vault table with AWS-managed table encryption, point-in-time recovery, and TTL for rotated records. Plaintext keys are used only as needed to verify or route provider requests.
Local inferock-bench records
inferock-bench is different from hosted Inferock. It runs on localhost by default. Provider keys stay in the local environment or local config file, local events are written under the user's inferock-bench home, and receipts stay local until the user copies, posts, attaches, or otherwise shares them. Local event files can contain response text, tool calls, tool schemas, model names, usage fields, timing, selected provider IDs or headers, and detector evidence.
Billing and commercial records
For paid or approved customer use, we may process order forms, plan records, account status, invoicing details, tax details, billing contacts, payment status, and service-mode information. Fees and economics are governed by the applicable order form or plan, not this policy.