Skip to content

Legal

Privacy Policy

How Caedral collects, uses, and protects your information.

Last updated: August 30, 2026

This Privacy Policy describes how Caedral (“Caedral,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use our website, API, dashboard, and related services (collectively, the “Service”). By using the Service, you agree to this Privacy Policy.

Caedral is the data controller responsible for personal information processed through the Service. For privacy inquiries, contact us at [email protected].

Information we collect

Information you provide

  • Account information: name, email address, organization name, and authentication credentials when you register
  • Seller program information: legal name, date of birth, address, SSN or ITIN, EIN for companies, identity documents, company records, and optional Stripe account identifiers when you apply to Caedral for Sellers
  • Billing information: billing address, tax identifiers where applicable, and subscription details (payment card data is processed by Stripe — we do not store full card numbers)
  • API usage data: API keys, request metadata, token usage, and usage metrics associated with your account
  • API request content: full text of prompts, queries, documents, messages, and other inputs you submit through the API, plus the generated outputs returned to you (text responses, rankings, embedding confirmations, and image or audio metadata)
  • Communications: messages you send us via email, Discord, or other support channels
  • Prompts and inputs: content you submit through the API for model inference

Information collected automatically

  • Log data: IP address, browser type, operating system, pages visited, timestamps, and referring URLs
  • Device and usage information: actions taken in the dashboard, error logs, latency metrics, and performance data
  • Cookies and similar technologies: used for authentication, session management, preferences, and analytics on our website

How we use information

We use the information we collect to operate, maintain, and improve the Service, including:

  • Providing API access, model inference, and account management
  • Processing subscriptions and payments through Stripe
  • Reviewing Caedral for Sellers applications, storing identity documents for compliance, and creating Stripe Connect accounts for approved sellers
  • Monitoring usage, enforcing rate limits, and preventing abuse or fraud
  • Sending service-related communications (billing receipts, security alerts, product updates, and policy changes)
  • Analyzing usage patterns and request content to improve reliability, performance, and product design
  • Retaining API request and response content for quality assurance, debugging, abuse prevention, and future model training
  • Complying with legal obligations and responding to lawful requests from authorities

Legal bases for processing (EEA and UK)

Where the GDPR or UK GDPR applies, we process personal information on the following bases: performance of a contract (providing the Service you requested), legitimate interests (security, fraud prevention, product improvement, and analytics in a manner that does not override your rights), compliance with legal obligations, and consent where required (for example, non-essential cookies or optional programs).

API content logging and model training

When you use the Caedral API, we log and retain the full content of your API requests and responses. This includes chat messages, embedding queries, rerank queries and documents, image and audio prompts, and the text or metadata of generated outputs. Binary media files (such as generated images or audio) are stored in our existing file storage; we log the associated text prompts and response metadata alongside billing records.

We use this content to operate the Service, investigate errors, monitor quality, prevent abuse, and improve Caedral's models and infrastructure. Captured inference content does not enter model training automatically: it must pass eligibility checks, policy filters, and explicit review/approval before any training use. Direct subscription customers can request opt-out or deletion via the dashboard or [email protected]. See the Data Policy for channel-specific retention, zero-retention, and do-not-train controls.

OpenRouter marketplace traffic

When Caedral serves inference as an OpenRouter provider (availability pending provider approval), that traffic uses a separate provider authentication and settlement channel. It does not debit Caedral subscription usage pools and does not use customer API keys (cd_live_*). OpenRouter may signal zero data retention or do-not-train preferences; Caedral honors those signals by skipping payload persistence and blocking training eligibility for affected requests. Operational metrics (latency, tokens, status codes) may still be retained for reliability and settlement.

Subprocessors and third-party model providers

We use subprocessors — including cloud hosting providers, analytics vendors, payment processors, and model infrastructure partners — to operate the Service. These providers process data on our behalf under contractual obligations requiring appropriate security and confidentiality.

Inference requests may be routed to third-party model providers necessary to fulfill specific model tiers. Those providers process Input and generate Output solely to provide the requested inference, subject to their own terms and our data processing agreements where applicable. We do not authorize subprocessors to use your content for their own model training except as required to deliver the Service and as disclosed in their applicable terms.

Some requests — including prompts submitted through Caedral Chat, the API, and related products — may be processed by third-party infrastructure partners that provide model inference, content moderation, or related cloud services. In customer-facing products and API responses, models are presented under Caedral model names only; underlying routing is an operational detail and does not change your agreement with Caedral.

How we share information

We do not sell your personal information. We do not share personal information for cross-context behavioral advertising. We share information only in these circumstances:

  • Service providers: vendors that help us operate the Service (hosting, analytics, customer support), bound by data processing agreements and confidentiality obligations
  • Payment processing: Stripe, Inc. processes payments on our behalf pursuant to Stripe's privacy policy and terms
  • Model infrastructure: subprocessors necessary to route inference requests, under contractual safeguards
  • Legal requirements: when required by law, regulation, subpoena, or legal process, or to protect the rights, safety, and security of Caedral, our users, or the public
  • Business transfers: in connection with a merger, acquisition, reorganization, or sale of assets, with notice where required by law

Payment processing (Stripe)

Paid subscriptions are billed through Stripe, Inc. When you subscribe, Stripe collects and processes payment information according to its privacy policy (https://stripe.com/privacy). We receive limited billing data from Stripe — such as the last four digits of your card, billing address, payment status, and transaction history — to manage your subscription and comply with accounting obligations. We do not store complete payment card numbers on our servers.

Data retention

We retain information only as long as necessary for the purposes described in this policy:

Data typeRetention period
Account and profile dataDuration of account plus 90 days after deletion request
Billing and transaction records7 years from transaction date (tax and accounting requirements)
API request logs and billing metadata90 days (30 days on Starter plans unless extended for abuse investigation)
API request and response content (execution logs)Retained under the Data Policy; not used for training without eligibility checks and approval. Contact [email protected] for deletion or opt-out
Support communications3 years from last interaction
Security and audit logs1 year

We may retain information longer when required by law, to resolve disputes, enforce agreements, or investigate security incidents.

Security

We implement technical and organizational measures designed to protect your information, including encryption in transit, access controls, and monitoring. See our Security page for an overview. No method of transmission or storage is completely secure; we cannot guarantee absolute security.

Your rights and choices

Depending on your location, you may have the following rights regarding your personal information:

  • Access: request a copy of personal information we hold about you
  • Correction: request correction of inaccurate or incomplete information
  • Deletion: request deletion of your personal information, subject to legal exceptions
  • Portability: request a machine-readable copy of information you provided
  • Restriction: request that we limit processing in certain circumstances
  • Objection: object to processing based on legitimate interests
  • Withdraw consent: where processing is based on consent, withdraw it at any time

California residents (CCPA/CPRA)

California residents have the right to know what personal information we collect, request deletion, correct inaccurate information, and opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising. To exercise your rights, email [email protected]. We will verify your request and respond within 45 days (extendable by 45 days where permitted). You may designate an authorized agent to submit requests on your behalf.

EEA and UK residents (GDPR)

If you are in the European Economic Area or United Kingdom, you have the rights listed above and may lodge a complaint with your local supervisory authority. To exercise your rights, contact [email protected]. We will respond within 30 days (extendable by 60 days where permitted and with notice).

International transfers

Caedral is based in the United States. We may process and store information in the United States and other countries where we or our service providers operate. When we transfer personal information from the EEA, UK, or Switzerland to countries not deemed adequate, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission or UK authorities, supplemented by technical and organizational measures where appropriate.

You may request a copy of applicable transfer safeguards by contacting [email protected].

Cookies

We use essential cookies required for authentication and security. We may use analytics cookies to understand how the website is used. You can control non-essential cookies through your browser settings. Where required by law, we obtain consent before placing non-essential cookies.

Children's privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact [email protected] and we will delete it promptly.

Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the “Last updated” date. Material changes will be communicated by email to the address associated with your account or through the Service at least 30 days before they take effect, where required by law.

Contact

For privacy-related questions, requests, or complaints, contact Caedral at [email protected]. For general support, contact [email protected] or join our Discord community via the Contact page.