Privacy Policy
Last updated: September 2026
This Privacy Notice for Komplexity AI LLC (doing business as Komplex AI) (“we,” “us,” or “our”) describes how and why we might access, collect, store, use, and/or share (“process”) your personal information when you use our services (“Services”), including when you:
- Visit our website at https://komplexai.io or any website of ours that links to this Notice;
- Use the Komplex AI Hallucination Detector — a probabilistic hallucination detection service for large language model outputs. You submit text through a web interface or API and receive a statistical estimate of the likelihood that the text contains a hallucination, with a suggested classification. We are designed for transient processing: submitted text is not stored in any persistent datastore and is not retained after your result is returned.
- Engage with us in other related ways, including any marketing or events.
Questions or concerns? We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. Contact us at legal@komplexai.io.
Our Key Privacy Commitments
- Zero retention of your text. We do not store the prompts, model responses, or other text you submit for hallucination analysis in any persistent datastore, and we do not retain it after your result is returned.
- We never train on your inputs. Your submitted text is never used to train, fine-tune, or improve any model — ours or anyone else's — so there is no training opt-out to manage.
- We do not sell or share your personal information, and we do not use it for cross-context behavioral advertising.
- No third-party advertising or analytics trackers — we use only strictly necessary cookies.
Each of these commitments is described in detail below.
Summary of Key Points
What personal information do we process? Account registration data (name, email), usage metadata (request timestamps, token counts, API key identifiers, response latency), and technical information (IP address, device data). We are designed for transient processing and do not store the text you submit for hallucination analysis in any persistent datastore.
Do we use submitted text to train models? No — we never use text submitted for hallucination analysis to train, fine-tune, or improve any model, or share it with third parties for that purpose. It is processed transiently: we do not store it in any persistent datastore and do not retain it after returning your result.
Do we sell or share your personal information? No. We do not sell your personal information and do not share it for cross-context behavioral advertising.
Do we collect information from third parties? Only limited profile data from your social-login provider (if you choose to use one). We do not run advertising or third-party analytics trackers, and we do not buy personal information about you from data brokers.
How do we keep your information safe? We use appropriate organizational and technical measures. No system is guaranteed 100% secure.
What are your rights? Depending on where you are located, applicable privacy law may give you certain rights regarding your personal information.
How do you exercise your rights? Visit komplexai.io/contact or email legal@komplexai.io.
Table of Contents
- What information do we collect?
- How do we process your information?
- What legal bases do we rely on?
- When and with whom do we share your personal information?
- Do we use cookies and other tracking technologies?
- Do we offer artificial intelligence-based products?
- How do we handle your social logins?
- Is your information transferred internationally?
- How long do we keep your information?
- How do we keep your information safe?
- Do we collect information from minors?
- What are your privacy rights?
- Controls for do-not-track features
- Do United States residents have specific privacy rights?
- Do other regions have specific privacy rights?
- Do we make updates to this notice?
- How can you contact us about this notice?
- How can you review, update, or delete the data we collect from you?
1. What Information Do We Collect?
Personal information you disclose to us
We collect personal information you voluntarily provide when you register, express interest in our products, participate in activities, or contact us, which may include: email addresses; passwords (stored as hashed credentials via our authentication provider); usernames; billing addresses; contact or authentication data; names.
Payment Data. We may collect data necessary to process your payment if you make purchases, such as your payment instrument number and security code. All payment data is handled and stored by Stripe (see the Stripe Privacy Policy at stripe.com/privacy).
Social Media Login Data. If you register using a social media account, we collect certain profile information as described in Section 7.
Information automatically collected
We automatically collect certain information when you visit or use the Services — including IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, and other technical information — primarily to maintain the security and operation of our Services and for internal, first-party diagnostics from server logs (we do not use third-party analytics trackers). This includes:
- Log and Usage Data — diagnostic, usage, and performance information (IP address, device information, browser type/settings, date/time stamps, pages viewed, actions taken).
- Device Data — information about your device (IP address, device/application identifiers, location, browser type, hardware model, ISP, system configuration).
- API usage metadata — for each request: timestamp, API key identifier (not the key itself), token count of the request, and response latency. We do not store the text submitted for hallucination analysis in any persistent datastore, and we do not retain it after returning your result. See Section 9 for the full retention schedule.
What we do not collect. We are designed for transient processing: we do not store the text you submit for hallucination analysis (the prompt, model response, or other input text) in any persistent datastore, and we do not retain it after returning your result. That content is processed transiently to generate a result, and we take reasonable measures to keep it out of our logs. We also do not collect protected health information (PHI) as defined under HIPAA, and you must not submit PHI. We are not a HIPAA-covered entity and do not enter into Business Associate Agreements (BAAs).
Google API
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2. How Do We Process Your Information?
We process your personal information to:
- Facilitate account creation, authentication, and account management;
- Deliver and facilitate the Services requested;
- Respond to inquiries and provide support;
- Send administrative information (changes to terms/policies, service notices);
- Fulfill and manage orders, payments, and billing;
- Request feedback and contact you about your use of the Services;
- Protect the Services (fraud and abuse monitoring, performed on request metadata only — not on the text you submit);
- Identify usage trends from aggregate usage metadata (request counts, token counts, latency) to improve the Services;
- Manage API access — authenticate users, issue and manage API keys, enforce quotas and rate limits;
- Deliver the web interface — authenticate users and process submitted text transiently to return inference results.
No training on submitted text. We do not use the text you submit for hallucination analysis to train, fine-tune, or improve any machine learning model, including our own. Submitted text is processed transiently: we do not store it in any persistent datastore, we do not retain it after returning your result, and we take reasonable measures to keep it out of our logs. Any future model improvement program would apply only going-forward and opt-in, under a separate written agreement.
3. What Legal Bases Do We Rely On?
If you are in the EU or UK, this section applies to you.
The GDPR and UK GDPR require us to explain the legal basis for each purpose:
- Performance of a contract / our legitimate interest in operating the Service — creating and managing your account, delivering the Service (including the strictly-necessary cookies that keep you signed in — see Section 5), and processing payments.
- Legitimate interests — securing the Service, preventing fraud and abuse (using request metadata), and understanding aggregate usage to improve the Service, where these interests do not override your rights.
- Consent — any optional marketing communications; you may withdraw consent at any time.
- Legal obligations — compliance with tax, accounting, and other legal duties.
We do not rely on “vital interests” for ordinary processing of your information.
If you are in Canada, this section applies to you.
We process on express or implied consent, withdrawable at any time, with limited legal exceptions.
4. When and With Whom Do We Share Your Personal Information?
We share information with vendors, service providers, and contractors (“third parties”) who perform services for us and need access to do that work, under contracts designed to safeguard your information. Our subprocessors:
- User Account Registration & Authentication: Clerk (clerk.com); Google OAuth 2.0 / Google Sign-In
- Invoice & Billing: Stripe
- Cloud Compute / Inference Hosting: Modal (modal.com) — processes inference requests transiently; does not receive retained user data
- Website Hosting: Vercel
- Database (account, billing state, usage metadata): Neon (neon.tech) — stores account identifiers, subscription/billing state, and usage metadata; does not receive the text you submit for analysis
- Transactional Email: Resend (resend.com)
- Bot protection & inbound-mail routing: Cloudflare (cloudflare.com) — Turnstile CAPTCHA on our contact form and, where enabled, inbound-email routing; processes technical signals (such as IP address) and any message you send us — not the text you submit to the detector
- Content moderation (correspondence only): OpenAI (openai.com) — we send the text of contact-form and inbound-email messages to OpenAI’s Moderation API to screen for abuse; we do not send the text you submit to the detector to OpenAI or any other third party
Business Transfers. We may share or transfer your information in connection with a merger, sale of company assets, financing, or acquisition of all or a portion of our business.
5. Do We Use Cookies and Other Tracking Technologies?
We use only strictly necessary cookies — those required to run the Service and keep it secure. These include an authentication/session cookie set by our login provider (Clerk) and cookies set by our payment processor (Stripe) during checkout and for fraud prevention. We do not use advertising cookies, cross-site tracking, or third-party analytics cookies. Because these cookies are strictly necessary to provide a service you have requested, they do not require a consent banner under applicable law. You can block or delete cookies in your browser settings, but the Service may not function correctly without the authentication cookie.
6. Do We Offer Artificial Intelligence-Based Products?
Yes. The Komplex AI Hallucination Detector is an AI-based system that uses machine learning to estimate the likelihood that text produced by a large language model contains a hallucination. Users submit text through a web interface or API; the system returns a probabilistic score and a suggested regime classification. All submitted text is processed transiently: we do not store it in any persistent datastore and do not retain it after returning your result.
How We Process Your Data Using AI
Submitted text is passed to the inference engine, which produces a score and returns it to you. We do not store the text in any persistent datastore, do not use it to train or improve any model, and do not retain it after returning your result; we take reasonable measures to keep it out of our logs. Usage metadata (timestamp, API key identifier, token count, response latency) is retained for billing and quota management as described in Section 9.
GDPR — Inference Scores as Personal Data
Under GDPR, a hallucination score derived from text linked to an identifiable natural person may itself constitute personal data. Our zero-retention approach substantially mitigates this risk: we do not associate scores with individuals beyond the API key metadata retained for billing. If you have GDPR concerns about submitting text about identifiable individuals, contact legal@komplexai.io.
API — Controller/Processor
When you access the Service through the API, you act as the controller of the text you send, and we act as your processor with respect to that text (see Terms of Use, Section 10). You are responsible for the notices and consents required for your end users in their jurisdictions.
HIPAA Exclusion
Komplexity AI LLC is not a HIPAA-covered entity and does not enter into BAAs. You must not submit PHI. This prohibition is also stated in our Terms of Use.
How to Opt Out
To opt out of AI processing, stop submitting text to the Service. You may also contact us using the information in Section 17.
7. How Do We Handle Your Social Logins?
If you register or log in using a third-party social account (like Google), we receive certain profile information — typically name, email address, and profile picture — and use it only as described in this Notice. We do not control your provider’s own use of your information; review their privacy notice.
8. Is Your Information Transferred Internationally?
Our servers are located in the United States; your information may be transferred to, stored, and processed in the US and in our subprocessors’ facilities. For EEA/UK/Swiss users, these countries may not have equally comprehensive data-protection laws, but we take measures to protect your information in accordance with this Notice and applicable law.
International transfers and Standard Contractual Clauses (SCCs).Where personal information of EEA, UK, or Swiss users is transferred to the United States — where Komplex AI acts as the data importer — we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, and we flow equivalent protections down to our US-based subprocessors.
Data Processing Agreement (DPA). EU and UK customers who require a DPA under GDPR Article 28 should contact legal@komplexai.io. Our DPA template (incorporating SCCs) is available at komplexai.io/dpa.
9. How Long Do We Keep Your Information?
Different categories are kept for different periods. Submitted text is not stored in any persistent datastore and is not retained after your result is returned.
| Data type | Retention period | Purpose |
|---|---|---|
| Submitted text (prompts, model responses, input text) | Not retained — not stored in any persistent datastore; not retained after your result is returned | We do not maintain a store of submitted text, so it is not part of a data store that could be exposed in a breach |
| Hallucination scores returned to you | Not retained on our servers — returned to you only | You may store your own results; we do not |
| Usage metadata (timestamp, API key ID, token count, latency) | 24 months from each request | Billing, quota enforcement, dispute resolution, aggregate usage analysis |
| Account information (name, email, hashed password) | Until account deletion + 90 days | Account management; legal compliance |
| Payment information | Per Stripe's policy (typically ~7 years) | Billing compliance; held by Stripe, not us |
| Support communications | 3 years from last contact | Customer support; legal compliance |
When we have no ongoing legitimate business need, we delete or anonymize the information, or securely store and isolate it from further processing until deletion is possible.
10. How Do We Keep Your Information Safe?
We have implemented appropriate technical and organizational security measures. However, no electronic transmission or storage technology can be guaranteed 100% secure, so we cannot promise that unauthorized third parties will never defeat our security. Transmission of personal information to and from our Services is at your own risk; access the Services within a secure environment.
11. Do We Collect Information From Minors?
We do not knowingly collect data from or market to children under 18. By using the Services you represent that you are at least 18, or the parent/guardian of a minor consenting to their use. If we learn we have collected data from a user under 18, we will deactivate the account and delete the data. Contact legal@komplexai.io if you believe we have such data.
12. What Are Your Privacy Rights?
In some regions (EEA, UK, Switzerland, Canada) you have rights to: request access and a copy of your personal information; request rectification or erasure; restrict processing; data portability; and not be subject to automated decision-making. Make a request via Section 17.
We respond to verifiable requests within the timeframes required by applicable law — generally within one month under the GDPR and UK GDPR (extendable by up to two further months for complex or numerous requests) — and we will tell you if we need more time.
EEA/UK users may complain to their data protection authority; Swiss users may contact the Federal Data Protection and Information Commissioner.
Withdrawing consent. Where we rely on consent, you may withdraw it at any time via Section 17.
Account information. You may review, change, or terminate your account from account settings or by contacting us. Upon termination we deactivate/delete your account and information from active databases, though we may retain some information to prevent fraud, resolve disputes, enforce our terms, or comply with law.
13. Controls for Do-Not-Track Features
Most browsers offer a Do-Not-Track (“DNT”) signal. Because no uniform standard has been finalized, we do not currently respond to DNT signals. California law requires us to disclose this. If a standard we must follow is adopted, we will update this Notice.
Global Privacy Control (GPC).Where applicable, we treat a Global Privacy Control (GPC) browser signal as a valid request to opt out of any “sale” or “sharing” of personal information. Because we do not sell or share personal information, no additional action is required — but we honor GPC as a matter of course.
14. Do United States Residents Have Specific Privacy Rights?
We Do Not Sell or Share Your Personal Information
Komplexity AI LLC does not sell your personal information and does not share it for cross-context behavioral advertising. This applies to all users, including California residents under the CCPA and CPRA. Because we do not sell or share, no opt-out action is required, but you may confirm at legal@komplexai.io.
Categories of Personal Information We Collect
Categories of personal information collected in the last 12 months:
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Email address, account name, IP address, API key identifier (hashed) | YES |
| B. California Customer Records personal information | Name, contact information, financial information (via Stripe) | YES |
| C. Protected classification characteristics | Not collected | NO |
| D. Commercial information | Transaction information, subscription plan, payment history | YES |
| E. Biometric information | Not collected | NO |
| F. Internet or other network activity | IP address, browser type, pages viewed, API request metadata | YES |
| G. Geolocation data | Approximate location inferred from IP address | YES |
| H. Audio, electronic, sensory information | Not collected | NO |
| I. Professional or employment information | Not collected | NO |
| J. Education information | Not collected | NO |
| K. Inferences | Transient hallucination scores are generated but not retained on our servers | LIMITED — not retained |
| L. Sensitive personal information | Account login credentials (hashed); no PHI; no financial account credentials (Stripe holds payment data) | LIMITED |
Note: categories tied to payments (financial information; transaction, subscription, and payment history) are collected only if and when you use a paid plan.
We use sensitive personal information (hashed login credentials) only to authenticate you and provide the Service; we do not use or disclose it to infer characteristics about you. This use is exempt from the CPRA “right to limit the use of sensitive personal information,” so no separate limit action is required, though you may still contact us with any questions.
Your Rights
Your rights under US state laws: right to know, access, correct, delete, obtain a copy, non-discrimination, and opt out of sale/sharing (we do not sell or share). Exercise via komplexai.io/contact or legal@komplexai.io. You may use an authorized agent (with proof of authorization). We verify identity before acting. You may appeal a declined request by emailing legal@komplexai.io. We respond to verifiable requests within 45 days, extendable by another 45 days where reasonably necessary, and we will notify you of any extension.
California “Shine The Light” Law
California residents may request, once a year and free of charge, information about categories of personal information disclosed to third parties for direct marketing (we do not disclose for third-party direct marketing). Submit requests via Section 17.
15. Do Other Regions Have Specific Privacy Rights?
Australia & New Zealand.We process under Australia’s Privacy Act 1988 and New Zealand’s Privacy Act 2020; you may access/correct your information and complain to the OAIC / NZ Privacy Commissioner.
Republic of South Africa. You may access/correct your information and contact the Information Regulator (South Africa).
16. Do We Make Updates to This Notice?
Yes. We will post an updated “Last updated” date and, for material changes, provide prominent notice or direct notification.
17. How Can You Contact Us About This Notice?
Email legal@komplexai.io, or write to:
Komplexity AI LLC7514 Girard Ave, Ste 1 #935
San Diego, CA 92037
United States
EU and UK customers with DPA inquiries: legal@komplexai.io, subject “DPA Request.”
18. How Can You Review, Update, or Delete the Data We Collect From You?
To request access, correction, or deletion of your personal information, visit komplexai.io/contact. These rights may be limited in some circumstances by applicable law.