Astorias — Privacy Policy
Effective date 16 September 2026 · Last updated 16 September 2026
Saturated Labs Private Limited (operating Astorias; "we", "our", or "us") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect Personal Information when you use https://astorias.ai/ and our related AI inference APIs, model hosting, and cloud software (the "Services").
We support the EU General Data Protection Regulation ("GDPR"), the UK GDPR, and similar data-protection laws. You can make access, correction, deletion, export, and related requests as described in Section 8. Saturated Labs is established in India; that does not change those rights.
This policy should be read with our Terms of Use.
1. Scope and roles
This Privacy Policy covers Personal Information we collect from or about you as a Site visitor or account holder.
Saturated Labs Private Limited is the data controller of account, billing, and usage-log Personal Information we collect to operate the Services.
Inference User Content (prompts and completions) is handled under our Zero Data Retention (ZDR) practice described in Section 4. We do not store that LLM content after the request finishes. If you put personal data about other people in Inputs, you are typically the controller of that data; we process it only to complete the live request and then discard it.
2. Personal Information We Collect
"Personal Information" means information that identifies you or could reasonably be used to identify you.
2.1 Information you provide
- Account Information: name, email, and login identifiers from our auth provider (WorkOS) when you sign in with Google, GitHub, or similar. That includes the profile photo URL your Google or GitHub account already exposes for sign-in (the same public avatar on those services). We use it only as your avatar in the dashboard. We do not collect other photos of you, and this is not LLM or prompt data. Organization name and any profile details you submit are also account information.
- Payment and billing Information: payment method details processed by our payment providers, billing address, invoices, and transaction history. We do not store full card numbers on our own servers when a processor handles the card.
- Communication Information: content of support emails or messages you send to support@astorias.ai, and related contact details.
2.2 Information collected automatically
When you use the Site or Services, we may collect:
- Log and Technical Information: IP address, browser type/settings, device type, operating system, referring URLs, date/time of requests, and similar diagnostics needed to run and secure the Site.
- Usage logs (billing and account operation only): numerical, non-content records such as request identifiers, which model was called, token or unit counts (prompt, completion, cached, reasoning where applicable), request status, timestamps, credits or amounts charged, and which API key or organization was billed. These logs exist so billing, balances, invoices, and usage dashboards can function. They are not your prompts or model outputs, and we do not use them to train models.
- Cookies and similar technologies: cookies or local storage needed to run the Site (session, auth, security). If we use analytics cookies, we will describe them here or in a Cookie notice as we add them.
2.3 What we do not store from model use (ZDR)
For AI inference and model hosting:
- We do not store LLM data: prompts, completions, uploaded inference payloads, or equivalent User Content, after the request is processed and Output is delivered.
- We do not use your Input or Output to train our models, or anyone else's.
- We do not keep a library of your conversations, datasets, or model outputs for later reuse, advertising, or product improvement.
- KV cache and similar short-lived technical state may exist only while the request is being served and is not kept as a content archive afterward.
- What may remain related to model usage is usage logs described above—token counts, model, timestamps, identifiers needed to bill the request—not the text of your prompts or completions.
Automated safety screening may run during a request. It is not model training and is not used to build a retained library of your User Content.
If law requires retention or we must investigate abuse or security incidents, we may keep limited data only as reasonably necessary and for no longer than needed for that purpose.
2.4 CCPA-style categories (last 12 months)
Depending on how you use the Services, we may collect:
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Name, email, IP, account ID, public OAuth avatar URL | Yes |
| Customer records-type data | Name, billing details via processors | Yes (limited) |
| Protected classifications | Race, religion, etc. | No (not sought) |
| Commercial information | Purchase / credit history on Astorias | Yes |
| Biometric information | — | No |
| Internet / network activity | Site interactions, billing usage logs | Yes |
| Geolocation (precise) | — | No |
| Sensory data | — | No |
| Professional / employment | — | No (unless you put it in support mail) |
| Education records | — | No |
| Inferences | Profiles, preferences, or other inferences from prompts, completions, or usage | No |
3. How We Use Personal Information
We do not use Personal Information or User Content for model training. We do not store LLM prompts or completions to improve models or for any later reuse.
We use Personal Information to:
- Provide, operate, secure, and administer the Services (including authentication);
- Bill the account: usage logs (token counts, model, timestamps, identifiers) are required for credits, invoices, balances, and usage reporting to function;
- Communicate with you about your account, security, and support;
- Prevent fraud, abuse, and misuse; protect our systems and other users;
- Comply with law and enforce our Terms;
- With your consent where required, send product updates or marketing (you can opt out of marketing).
3.1 Legal bases (GDPR / UK GDPR)
Under GDPR and UK GDPR we process Personal Information on these bases:
- Contract (Art. 6(1)(b)): to create and run your account, provide inference, and keep the usage logs billing depends on;
- Legitimate interests (Art. 6(1)(f)): to secure the Services, prevent fraud and abuse, and keep the Site working, in ways that do not override your rights;
- Legal obligation (Art. 6(1)(c)): tax, accounting, and other records we must keep;
- Consent (Art. 6(1)(a)): optional marketing, where we ask for it. You can withdraw consent at any time without affecting processing already done.
Providing account and billing information is required if you want a paid or authenticated account. We do not make solely automated decisions that produce legal or similarly significant effects about you.
4. Zero Data Retention (model Content)
Summary: We do not store LLM data. Prompt and completion content does not remain after inference completes. We do not train on it. Usage logs needed for billing may remain.
| Data | Kept after the request? |
|---|---|
| Input / Output (LLM prompts, completions, payloads) | No (ZDR), except ephemeral processing and rare legal/abuse needs |
| KV cache / in-flight technical state | Only during processing |
| Usage logs (tokens, model, timestamps, request/org/key IDs, credits charged) | Yes — required for billing and usage reporting to function |
| Account, billing, support tickets | Yes, as needed to run the business (Section 10) |
5. Aggregated or De-Identified Information
We may aggregate or de-identify information (for example overall traffic or which models are billed most) and use it to operate the Services or publish high-level statistics. That aggregation is from usage logs, not from stored prompts or completions. We will not try to re-identify de-identified data except as allowed by law.
6. How We Share Information
We do not sell your Personal Information for money. We may share information with:
- Service providers who help us run the Services (authentication via WorkOS, hosting, cloud, email, analytics if used, payment processors), under instructions to use data only for their task. WorkOS receives the name, email, and public profile photo URL your Google or GitHub account already provides at sign-in.
- Model or infrastructure providers solely as needed to process a live inference request (content is handled under ZDR and not kept by us afterward as described above);
- Professional advisors (lawyers, accountants) under confidentiality;
- Authorities when required by law or to protect rights, safety, or security;
- Transaction parties if we are involved in a merger, acquisition, or asset sale (subject to confidentiality and this Policy's spirit);
- Affiliates of Saturated Labs, if any, under this Policy.
We do not share prompt or completion archives with third parties for their advertising or training, because we do not keep those archives under ZDR.
7. International Transfers
Saturated Labs is based in India. If you access the Services from elsewhere, including the EEA or UK, your information may be processed in India and in other countries where our providers operate. Where GDPR or UK GDPR requires a safeguard for that transfer, we use appropriate measures (for example standard contractual clauses) for cross-border transfers.
8. Your Rights and GDPR data requests
We support GDPR and UK GDPR. That includes these rights over Personal Information we hold, and we also honor equivalent rights under Indian and California law where they apply:
- Access (Art. 15): a copy of Personal Information we hold about you;
- Rectification (Art. 16): correct inaccurate Personal Information;
- Erasure (Art. 17): delete Personal Information, subject to legal exceptions (for example invoices and tax records we must keep);
- Restriction (Art. 18): limit how we use Personal Information in certain cases;
- Portability (Art. 20): receive Personal Information you provided, in a structured, commonly used format;
- Objection (Art. 21): object to processing based on legitimate interests, including profiling related to such processing;
- Withdraw consent where processing is based on consent, without affecting prior processing;
- Opt out of marketing emails via the unsubscribe link or by emailing us.
How to make a request
Email support@astorias.ai with the subject line "GDPR / data request" (or equivalent). Tell us which right you want to exercise and enough detail for us to find your account (for example the email you registered with). We may need to verify your identity before we act.
We aim to respond within one month of a verified GDPR request. If the request is complex or numerous, we may take up to two further months and will tell you. We do not charge a fee unless a request is manifestly unfounded or excessive.
Because we do not store LLM prompts or completions, a data request cannot return inference content we never retained. We can address account, billing, support, and usage-log records we actually hold.
You also have the right to lodge a complaint with a supervisory authority in the EEA or UK, in particular where you live, work, or where you think a GDPR infringement occurred. We would rather fix the issue first: email support@astorias.ai.
9. Children's Privacy
The Services are for users 18+. We do not knowingly collect Personal Information from children under 18. If you believe a minor has provided us data, contact support@astorias.ai and we will delete it where appropriate.
10. Security and Retention
Security
We use commercially reasonable technical and organizational measures to protect Personal Information. No method of transmission or storage is fully secure.
Retention
| Data type | Typical retention |
|---|---|
| Inference Input / Output (LLM data) | Not stored after the request (ZDR); see Section 4 |
| Usage logs (tokens, model, timestamps, billed identifiers) | Kept as needed for billing, invoices, balances, and related account operation |
| Account Information | While the account is active, then as needed to close out the account |
| Billing / transaction records | As required for tax and accounting (often several years) |
| Support communications | As needed to resolve issues and for a reasonable follow-up period |
| Security / abuse logs | As needed for security and investigations |
11. Third-Party Sites
Links to other sites are governed by those sites' policies, not ours.
12. Changes
We may update this Privacy Policy by posting a new version on https://astorias.ai/legal/privacy and changing the "Last updated" date. Material changes may also be notified by email or in-product notice where appropriate. Continued use after the update means you accept the revised Policy, to the extent permitted by law.
13. Contact
Saturated Labs Private Limited
(operating Astorias)
Data controller for account, billing, and usage-log Personal Information
CIN: U62099UP2025PTC232320
Registered office: 47, Narayan Enclave Phase 2, Sewla Semri Road, Agra, Uttar Pradesh 282001, India
Privacy and GDPR requests: support@astorias.ai
Privacy page: https://astorias.ai/legal/privacy
Terms: https://astorias.ai/legal/terms
Pricing: https://astorias.ai/pricing