Model Ledger

Privacy Policy

How Model Ledger handles personal data.

This Policy describes what we collect, why we process it, who else may receive it, how long we keep it, and the choices available to you.

Last updated: . Governing contact: support@modelledger.trade.

1. Who we are

This Privacy Policy applies to https://www.modelledger.trade, related dashboards, and APIs operated as Model Ledger (“we,” “us”). Contact: support@modelledger.trade.

Depending on your interaction, we may act as a controller for account and billing data, and as a processor or service provider for certain customer-directed API workloads.

2. Data we collect

Account data. Email address, display name, authentication identifiers from GitHub, Google, or magic-link sign-in, MFA enrollment metadata, and profile settings.

Billing and wallet data. Credit purchases, package identifiers, payment status, order references, refunds, ledger balances, and usage charges. Card numbers are handled by our payment partner (for example Creem) and are not stored by Model Ledger as full PAN data.

API and metering data. API key identifiers (not plaintext secrets after creation), request IDs, timestamps, model names, token or equivalent usage counts, status codes, IP allowlist configuration you set, and rate-limit counters.

Supplier operational data. If you are a supplier: supply labels, policy limits, review status, encrypted credential material, fingerprints, health signals, and earnings/payout records.

Security and support data. Audit logs for sensitive actions, device/browser metadata needed for session security, and correspondence you send to support.

Content. Prompts and model outputs may transit our gateway to fulfill your request. Production design aims not to persist full prompts or streamed outputs by default. We may retain limited technical traces needed for abuse investigation, metering disputes, or legal obligation.

3. How we use data

  • Provide, authenticate, and secure the Service;
  • Meter usage, reserve and settle Credits, and produce invoices or statements;
  • Process payments and refunds with payment partners;
  • Review supplier submissions and enforce budgets, rate limits, and acceptable use;
  • Detect fraud, abuse, and security incidents;
  • Communicate service notices and respond to support requests;
  • Comply with law and enforce our Terms of Service.

We do not sell personal information.

5. Sharing and processors

We share data only as needed to operate the Service:

  • Infrastructure & auth. Hosting, database, and authentication providers (including Supabase and Cloudflare) that process account and application data under their terms.
  • Payments. Creem or other payment / merchant-of-record partners for checkout, tax handling, refunds, and related risk checks.
  • Upstream model providers. Request content and necessary metadata are sent to the provider selected to fulfill your inference call. Their privacy terms also apply to that processing.
  • Professional advisors and authorities when required by law or to protect rights and safety.

Suppliers do not receive end-customer identity or prompt content through billing views. Platform operators access data only under role-based controls and audit expectations.

6. International transfers

We and our processors may process data in multiple regions (for example Singapore, EU, or US infrastructure). Where required, we use appropriate transfer mechanisms such as standard contractual clauses or vendor terms that include equivalent protections.

7. Retention

  • Account data for as long as the account remains active and for a reasonable period afterward for security and dispute handling;
  • Billing, ledger, and tax records for the period required by applicable bookkeeping and tax rules;
  • Audit and security logs typically on the order of months, longer if needed for an investigation;
  • Encrypted supplier secrets until revoked or deleted under our retention and purge workflows.

We design systems so prompts and outputs are not kept as a default archive. Limited retention may still occur in logs or backups for a short window.

8. Security

We use access controls, encryption in transit, envelope encryption for supplier credentials, MFA for sensitive actions, and workload separation between web, gateway, secrets, and billing roles. No method of transmission or storage is perfectly secure; see also our Security page.

9. Cookies and similar technologies

We use essential cookies and similar storage for authentication sessions and CSRF protection. We do not depend on third-party advertising cookies for the core product. Analytics, if introduced later, will be disclosed and constrained to non-sensitive surfaces.

10. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to / restrict certain processing. Contact support@modelledger.trade to make a request. We may need to verify your identity and retain data we must keep for legal or accounting reasons.

You can revoke API keys, update allowlists, and sign out of sessions in the dashboard. You can disconnect OAuth providers via the identity provider’s account settings.

11. Children

The Service is not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal data from children.

12. Changes

We may update this Policy by posting a new version with a revised date. Material changes will be called out on the website or by email when appropriate.

13. Contact