Privacy Policy
Last updated: October 2026
1. Overview
IteraCompute Artificial Intelligence Technology (Chongqing) Co., Ltd. ("we", "us" or "our"), a company registered in Chongqing, China, operates IteraCompute, this website, the IteraCompute Console and self-service model inference APIs for individual developers, teams and enterprise customers. This policy explains how we process account data, OAuth sign-in data, payment data, customer data, interaction data, API metadata and personal information. For enterprise customers, the signed service agreement prevails where it differs from this policy.
2. Customer Data and Our Role
Interaction Data belongs to your business and customer data. You are the data controller, and IteraCompute acts in principle as a neutral technical service provider processing data to deliver the services you request and according to your instructions and our written agreement.
We do not arbitrarily access, use or disclose Interaction Data. Access is restricted to the limited circumstances described below or otherwise expressly agreed with you in writing.
3. Account Data
To create and operate a self-service account we process account data you provide, such as your email address, username or display name, password credentials (stored as salted hashes, never in plain text), verification codes, account preferences and support correspondence. We also process account-security signals such as sign-in timestamps, IP addresses, device identifiers and failed login attempts as necessary for authentication, abuse prevention and fraud prevention. You must provide accurate information and keep your credentials confidential.
4. Third-Party Sign-In (OAuth)
If you register or sign in through a third-party identity provider (for example GitHub or Google, where offered), we receive the basic profile information that provider shares with us at your direction, typically your provider account identifier, email address, display name and avatar. We do not receive your third-party password. OAuth tokens are used only to authenticate you and maintain your session, and are stored with access restrictions. You can unlink third-party sign-in in your account settings where supported, after setting an alternative sign-in method.
5. Payment Data
Where paid billing is enabled, payment transactions are processed by our third-party payment provider. We receive and retain billing records such as your billing contact, transaction amount, currency, invoice status, and the card brand, last four digits and expiry month for the payment method on file. We do not store full payment-card numbers or CVV codes. The payment provider processes your complete payment details under its own privacy terms to complete the transaction and meet financial-compliance duties.
6. Interaction Data and Model Training
"Interaction Data" includes prompts, model inputs and outputs, knowledge-base files, tool-call results, conversation context, agent configurations, business data related to API calls, model parameters and other content submitted to or generated through the services.
Without your explicit authorization, we will not use your Model API call data, Interaction Data or Usage Data to train, fine-tune or optimize general-purpose foundation models offered to unspecified users.
7. API Metadata and Its Use
We may process API metadata such as call time and frequency, error codes, token usage, authentication information, model name and version, parameter configuration and other operational data related to a call, together with exception logs and service status. We use this data as necessary for billing, security audits, abuse and fraud prevention, service operations and performance optimization. We do not sell personal information or use it for cross-context behavioral advertising.
8. Retention and Special Processing
We retain information only for the period necessary to fulfill the stated purposes. Account data is retained while your account is active and for a reasonable period afterwards for security, dispute and compliance purposes; payment and invoice records are retained as required by financial and tax law. Where laws require a longer statutory retention period, we retain the relevant data for that period and delete or anonymize it promptly when the period expires.
Some service configurations may require session retention, sample feedback, effectiveness evaluation, model tuning, cache storage, monitoring and debugging, observability or plugin execution records. When any of these scenarios applies, we will separately disclose or agree with you on the applicable processing rules and retention period.
9. Access Controls and Permitted Access
We use layered, role-based access controls. Only authorized personnel may access personal information or protected service data, access is limited by business need and personnel role, and the number of authorized personnel is controlled. Staff may not freely inspect prompts, outputs or other Interaction Data.
Access may occur only when required by law; necessary for an emergency involving public safety; permitted by a separate written agreement; minimally necessary to provide technical support or troubleshooting requested by you; or necessary to process metadata and exception logs for billing, security, abuse prevention or fraud prevention.
10. Subprocessors and Sharing
We may appoint service providers to process account data, OAuth session data, payment and billing records, API metadata, logs, ticket information or technical-support information. Our current categories of subprocessors are listed on our Subprocessors page. Providers may act only on our instructions, may not use the data for other purposes, must accept contractual confidentiality and data-protection duties, and are subject to privacy and security due diligence. We may also disclose data when required by law or in a business transfer subject to confidentiality protections.
11. Processing Location and Enterprise ZDR
Service data is processed only in mainland China. Account, authentication and billing workflows may rely on third-party providers as listed on our Subprocessors page; Interaction Data itself is processed on infrastructure we operate in mainland China. Enterprise zero-data-retention requirements, including the applicable scope, technical configuration and exceptions required by law, must be established through an additional written agreement.
12. Security Incidents, Your Rights and Contact
We maintain current technical and organizational controls described on our Security page. For a confirmed incident affecting your data, we will investigate, contain and notify you according to applicable law and, for enterprise customers, the timeframe agreed in your service agreement. You may request access, correction or deletion of applicable personal information, and may close your self-service account to stop further account-data processing subject to lawful retention. Questions and requests may be sent through our contact page. We may update this policy and will publish the revised date above.