Privacy Policy

Last updated: May 17, 2026

This Privacy Policy explains how Unnma LLC ("Unnma," "we," "us," or "our") collects, uses, retains, shares, and protects personal information in connection with the COP Gateway service (the "Service"). Capitalized terms not defined here have the meaning given to them in our Terms of Service. The Terms of Service are incorporated into this Privacy Policy by reference.

If you have questions about this Privacy Policy or wish to exercise any of the rights described in §6, please contact us at privacy@unnma.ai.


1. Scope

This Privacy Policy applies to personal information collected through the Service: our website, dashboard, APIs, and related communications. It does not apply to:

  • The third-party large-language-model Vendors to which we route your prompts. Each Vendor has its own privacy policy that governs the Vendor's handling of data we send to it. Links to Vendor privacy policies are in §4.
  • Third-party websites or services that link to or from the Service.
  • Information you provide to us through channels outside the Service (e.g., contracts negotiated by email outside the dashboard).

2. Information We Collect

2.1 Information you provide

Account information (via Clerk, our identity provider). Email address, name, and password credential when you create an account. If you sign in via a third-party provider supported by Clerk (e.g., Google, GitHub), we receive the basic profile information that provider shares with us. You may also optionally provide organization name and country.

Billing information (via Stripe, our payment processor). When you initiate a top-up, Stripe collects your payment-card information or bank-account details. We receive from Stripe a payment-method identifier, the last four digits and brand of your card, your billing address, and the result of each charge. We do not store your full payment card number; Stripe does.

Support correspondence. Messages you send to support@unnma.ai, billing@unnma.ai, privacy@unnma.ai, security@unnma.ai, legal@unnma.ai, or abuse@unnma.ai.

2.2 Information collected automatically when you use the Service

Prompts and responses. When you submit a request to the Service, your prompt passes through our gateway. The plaintext of the prompt is held in memory for the duration of the request and is not retained after the request completes, except as described in §2.2(c) below. Vendor responses are streamed back to you and are not retained.

Request metadata. For each request we retain: timestamp, account identifier, API-key identifier, Vendor and model used, input and output token counts, latency, Vendor-billed cost, Unnma markup, total customer charge, HTTP status, request identifier, and a SHA-256 hash of the prompt. The hash is one-way and the prompt is not recoverable from it.

Blocked-attempt records. If our prompt-extraction guard determines in good faith that a request is attempting to extract, reverse-engineer, or replicate our COP optimization technique in violation of our Acceptable Use Policy, we retain the full plaintext of the prompt, the source IP address, the User-Agent string, the guard model's verdict and version, and a unique incident identifier. Retention details are in §5.

Comparison-run records. If you use the in-dashboard Comparison feature, you have explicitly elected to evaluate your prompt against both the direct Vendor and the Unnma-optimized path. In that context we retain the full plaintext of your prompt and both responses for your later review on the Comparison screen. You may delete a comparison run at any time from that screen.

Technical and device information. IP address, User-Agent string, browser type, operating system, and Service-internal session identifiers.

Cookies and similar technologies. We use first-party cookies for authentication and session management. We do not use third-party advertising cookies or pixel trackers. We do not currently respond to "Do Not Track" browser signals; you can disable cookies in your browser settings (you may not be able to sign in if you do).

2.3 Information from third parties

Clerk (identity provider) — account-creation and authentication signals.

Stripe (payment processor) — transaction-result data, card brand and last-four, billing address, fraud-risk signals.

We do not purchase personal information from data brokers and do not enrich your profile with third-party data sources.


3. How We Use Your Information

We use personal information for the following purposes. For each purpose, the corresponding legal basis under the EU General Data Protection Regulation ("GDPR") is shown in parentheses; the legal basis under U.S. state privacy laws is described in §5.

| Purpose | Legal basis (GDPR) | |---|---| | To create and maintain your account and authenticate you | Performance of contract (Art. 6(1)(b)) | | To process top-ups and charge your payment method | Performance of contract (Art. 6(1)(b)) | | To route your prompts to the Vendor you select and return responses | Performance of contract (Art. 6(1)(b)) | | To bill you for inference and reconcile against Vendor invoices | Performance of contract (Art. 6(1)(b)); legal obligation for tax/accounting (Art. 6(1)(c)) | | To provide customer support | Performance of contract (Art. 6(1)(b)) | | To monitor for abuse, enforce the AUP, and operate our prompt-extraction guard | Legitimate interest in operating a secure service and defending our trade secrets (Art. 6(1)(f); see Recital 47) | | To retain blocked-attempt records as an IP-defense corpus and security-incident artifact | Legitimate interest in defending trade secrets, in detecting attack campaigns, and in improving the guard (Art. 6(1)(f)) | | To improve the Service through aggregated metadata analysis (no prompt content) | Legitimate interest in product improvement (Art. 6(1)(f)) | | To respond to legal process and protect Unnma's legal rights | Legal obligation and legitimate interest (Art. 6(1)(c) and (f)) | | To send service-related communications (billing receipts, security notices, material Terms changes) | Performance of contract (Art. 6(1)(b)) | | To send optional product updates and newsletters | Consent (Art. 6(1)(a)); withdrawable at any time |

We do not use your prompt content to train any of our own models or any third party's models, and we do not retain the plaintext of legitimate prompts at all, for any purpose, including for COP improvement. Improvements to COP are derived from aggregated metadata only.


4. Sharing of Information

We share personal information with the following categories of recipients only as described below. We do not sell your personal information.

4.1 Service providers (sub-processors)

We use the following sub-processors to operate the Service. Each is contractually bound to use your information only as we direct.

| Sub-processor | Purpose | Location | Privacy policy | |---|---|---|---| | Clerk | Identity, authentication | United States | clerk.com/legal/privacy | | Stripe | Payment processing | United States | stripe.com/privacy | | Vercel | Web-app hosting, edge delivery | United States | vercel.com/legal/privacy-policy | | Neon | Managed Postgres database | United States | neon.tech/privacy-policy |

4.2 Vendors (third-party LLM providers)

When you select a Vendor for a request, we transmit your optimized prompt to that Vendor for processing. Each Vendor has its own privacy policy that governs its handling of the prompt and the response it generates. The Vendors supported at launch are:

| Vendor | Privacy policy | |---|---| | Anthropic | anthropic.com/legal/privacy | | OpenAI | openai.com/policies/privacy-policy | | Google (Gemini) | policies.google.com/privacy | | Together AI | together.ai/privacy | | Fireworks AI | fireworks.ai/privacy-policy | | Groq | groq.com/privacy-policy | | xAI | x.ai/legal/privacy-policy | | DeepSeek | deepseek.com/privacy | | OpenRouter (used as fallback adapter for models not directly integrated) | openrouter.ai/privacy |

We may add, remove, or substitute Vendors with reasonable notice. You select the Vendor for each request; we do not transmit your prompts to a Vendor you have not selected, except where you have enabled multi-Vendor routing in your account settings.

We may disclose personal information in response to a subpoena, court order, or other lawful request from a governmental authority, or where we believe in good faith that disclosure is necessary to (a) comply with applicable law, (b) enforce our Terms or AUP, (c) prevent or investigate fraud or abuse, or (d) protect the rights, property, or safety of Unnma, our users, or the public. Where lawful, we will provide you with notice of any compelled disclosure of your information.

4.4 Corporate transactions

If Unnma is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will provide notice of any change in control or material change in the entity processing your information.

4.5 Aggregated, de-identified data

We may share aggregated or de-identified data — information that cannot reasonably identify you — for benchmarking, marketing, research, or analytics. Aggregated data is not subject to this Privacy Policy.


5. Retention

We apply different retention rules to different categories of data. The same retention rules apply whether you are located in the United States or elsewhere; where required, we also identify the legal basis on which we rely to retain the data.

5.1 Standard API traffic

What we keep. SHA-256 hash of the prompt; non-content metadata (timestamp, Vendor, model, token counts, latency, cost, request identifier, account identifier, API-key identifier).

What we do NOT keep. Plaintext of your prompt; Vendor's response.

How long. We retain the hash and metadata indefinitely for billing reconciliation, dispute resolution, and aggregated service analytics. You may request earlier deletion under §6.

Lawful basis (US). Performance of contract; legitimate business interest in service operation. Lawful basis (GDPR). Art. 6(1)(b) (performance of contract); Art. 6(1)(f) (legitimate interest in operating the Service).

5.2 Blocked-attempt records

What we keep. Full plaintext of the prompt; source IP address; User-Agent; guard verdict and version; unique incident identifier; timestamp; account identifier; API-key identifier.

How long. Indefinitely, subject to your right to request deletion under §6 and our right to retain such records as described in §6.4. Records that we determine are no longer necessary for the purposes in this section are purged on a periodic schedule.

Purpose. (i) Defense of Unnma's intellectual property in trade-secret misappropriation matters; (ii) detection and analysis of attack campaigns against the Service; (iii) improvement of our prompt-extraction guard.

Lawful basis (US). Cal. Civ. Code §1798.105(d)(2) (security-and-integrity exception under the California Consumer Privacy Act, as amended by the California Privacy Rights Act); analogous "security and integrity" or "defense of legal claims" exceptions in other U.S. state privacy laws (e.g., Va. Code §59.1-582; Colo. Rev. Stat. §6-1-1304(3); Conn. Gen. Stat. §42-520(c)).

Lawful basis (GDPR). Art. 6(1)(f) (legitimate interest in defending trade secrets, detecting attack campaigns, and operating a secure service); Art. 17(3)(e) (retention necessary for the establishment, exercise, or defense of legal claims). The recognition of trade-secret defense as a legitimate interest is supported by Recital 47 GDPR and by the Article 29 Working Party Opinion 06/2014.

5.3 Comparison-run records

What we keep. Plaintext of your prompt and both responses returned during a Comparison run.

How long. Until you delete the comparison run from the Comparison screen, or until your account is deleted, whichever is sooner. You can delete a comparison run at any time.

Lawful basis. Performance of contract; your explicit election to use the Comparison feature.

5.4 Account information and billing

What we keep. Email, name, organization, billing address, payment-method identifiers (not full card numbers), transaction records.

How long. Account and contact information are retained for the duration of your account and for thirty (30) days thereafter, then deleted. Financial transaction records (invoices, receipts, tax data) are retained for seven (7) years to satisfy tax and accounting recordkeeping obligations under U.S. Treasury Regulation §1.6001-1 and applicable state law; the personal identifiers in these records are minimized to the extent feasible.

5.5 Support correspondence

Two (2) years from the last message in the thread, then deleted.

5.6 Server logs and security telemetry

Up to ninety (90) days, then deleted or aggregated. Logs that record a security incident may be retained longer as evidence.

5.7 Backups

Encrypted backups of the production database are retained for thirty (30) days for disaster-recovery purposes. Backups may contain copies of any data category described above.

If you are involved in a legal dispute or we receive a legal hold notice, we may retain your data longer than the periods described above until the legal matter is resolved. Where lawful we will notify you of a hold affecting your data.


6. Your Rights

Depending on where you are located, you may have one or more of the following rights with respect to your personal information. To exercise any of these rights, email privacy@unnma.ai from the email address on your account.

6.1 Access and portability

You may request a copy of the personal information we hold about you and a description of how we use it. Where applicable law requires, we will provide your information in a portable, machine-readable format.

6.2 Correction

You may correct inaccurate or incomplete account information at any time from your dashboard, or by emailing us.

6.3 Deletion

You may request deletion of your account and your personal information. On receipt of a verified request, we will within forty-five (45) days (extendable once to ninety (90) days for complex requests, with notice to you):

  • delete your account and account information (§5.4) (except as required by §5.4's tax-record retention);
  • delete your API keys;
  • delete your hashes and metadata in standard API traffic logs (§5.1);
  • delete your comparison-run records (§5.3);
  • delete your support correspondence and notification preferences (§5.5).

6.4 Exceptions to deletion (blocked-attempt records)

We may decline to delete blocked-attempt records (§5.2), to the extent permitted by:

(a) Cal. Civ. Code §1798.105(d)(2) (security-and-integrity exception under CCPA/CPRA);

(b) GDPR Article 17(3)(e) (retention necessary for the establishment, exercise, or defense of legal claims); and

(c) analogous provisions of other applicable laws.

Anonymization on deletion. Where we retain blocked-attempt records after a deletion request, we will anonymize the records by (i) removing the link to your account (setting the user and API-key identifiers to null), (ii) truncating the source IP address to remove the host portion, and (iii) retaining the prompt text, guard verdict, User-Agent, and incident identifier as the IP-defense corpus content. The resulting records are no longer reasonably linkable to you.

Notice and appeal. When we decline to delete blocked-attempt records, we will provide you a written response identifying (i) the records we are retaining, (ii) the legal basis for retention, (iii) the anonymization steps we have taken, and (iv) your right to appeal — under CCPA §1798.130(a)(3)(B) (right to file a complaint with the California Attorney General) or, for EU residents, GDPR Article 77 (right to lodge a complaint with a supervisory authority in your Member State).

6.5 Opt-out of marketing

You may opt out of optional product-update and newsletter emails at any time by clicking the unsubscribe link in any such email or by emailing privacy@unnma.ai. We will continue to send service-related communications (billing receipts, security notices, material Terms changes).

6.6 Right to object (GDPR)

If our processing is based on legitimate interest (Art. 6(1)(f)), you have a right to object to that processing under Art. 21. We will weigh your objection against our legitimate interest and respond within thirty (30) days. Where we rely on Art. 6(1)(f) for blocked-attempt records, the balancing test applied is the one described in §5.2 above.

6.7 Right to lodge a complaint

EU residents may lodge a complaint with their local supervisory authority under Art. 77 GDPR. California residents may file a complaint with the California Attorney General or the California Privacy Protection Agency. Residents of other U.S. states with comprehensive privacy laws have analogous rights with their state attorney general.

6.8 Non-discrimination

We will not discriminate against you for exercising any right under this Privacy Policy. We will not deny you the Service, charge you a different price, or provide a different level or quality of service because you exercised a right.

6.9 Authorized agents

You may designate an authorized agent to make a request on your behalf, subject to our verification of the agent's authority and your identity.


7. Security

We implement administrative, technical, and physical safeguards designed to protect personal information. These include:

  • Encryption in transit. All communication with the Service uses TLS 1.2 or higher.
  • Encryption at rest. Database storage is encrypted at rest using the encryption-at-rest features of our managed Postgres provider.
  • Access controls. Access to personal information is restricted to Unnma personnel with a documented need to access it (e.g., for support, security review, or IP enforcement). Access is logged.
  • Authentication. API access requires a per-account API key. Dashboard access uses our identity partner Clerk and supports multi-factor authentication.
  • Audit logging. Access to blocked-attempt records is recorded in an internal audit log.

No security program is perfect. We do not guarantee that the Service will be free from unauthorized access or compromise. If we discover a security incident affecting your personal information, we will notify you without undue delay and, in any event, within seventy-two (72) hours of confirmation, and we will provide information about the data affected and the steps we are taking. We may also notify regulators and other parties as required by applicable law (e.g., Cal. Civ. Code §1798.82; GDPR Arts. 33–34).


8. International Transfers

The Service is operated from the United States, and our sub-processors are located in the United States. If you access the Service from outside the United States, your personal information will be transferred to and processed in the United States.

For EU/EEA, UK, and Swiss users. Where transfers of personal data outside the EEA, UK, or Switzerland are subject to GDPR, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914) or, where applicable, the UK International Data Transfer Addendum. We do not currently have an establishment in the EU/EEA and have not appointed a representative under Article 27 GDPR; we will reassess this if the volume of EU traffic warrants it.

For data subjects outside the United States generally. By creating an account and using the Service, you consent to the transfer of your information to the United States and to the application of U.S. law to that information, except as Mandatory law in your jurisdiction requires otherwise.


9. Children

The Service is not directed to individuals under the age of eighteen (18), and we do not knowingly collect personal information from individuals under 18. If we learn that we have collected personal information from a child under 18 without verified consent of a parent or guardian, we will delete that information. If you believe we have collected information from a child, please contact privacy@unnma.ai.


10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make a material change, we will provide at least fourteen (14) days' advance notice by email to your account email address and by posting the updated policy on the Service. Non-material clarifications (e.g., typo fixes, formatting) take effect immediately on posting.


11. State-Specific Disclosures (United States)

The following disclosures supplement the foregoing for residents of U.S. states with comprehensive privacy laws.

11.1 California (CCPA / CPRA)

Categories of personal information we collect. Identifiers (name, email, account identifier, IP address); commercial information (transaction records); internet/network activity (request metadata, hashed prompt content, blocked-attempt prompt content where §5.2 applies); inferences (usage patterns).

Sources. You; our identity partner Clerk; our payment processor Stripe; our infrastructure providers.

Business purposes. As described in §3.

Disclosure / sale. We disclose information to the categories of sub-processors and Vendors in §4. We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising.

Sensitive personal information. We do not knowingly collect sensitive personal information as defined by CPRA §1798.140(ae) for purposes that would trigger a §1798.121 right to limit use. To the extent your prompts contain sensitive personal information you have submitted to us, the §1798.121 right does not apply where processing is reasonably necessary for the §1798.121(b) enumerated purposes, including ensuring the security and integrity of personal information that we use or maintain.

Your rights. Right to know, right to delete (subject to §6.4), right to correct, right to opt out of sale or sharing (n/a; we do neither), right of non-discrimination, right of access via an authorized agent. To submit a request, email privacy@unnma.ai. We will verify your request as described in §6.

Appeal. If we deny your CCPA request, you may appeal to the California Attorney General at oag.ca.gov/contact/consumer-complaint-against-business-or-company or to the California Privacy Protection Agency.

11.2 Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon, Montana, Iowa, Indiana, Tennessee, Delaware, New Hampshire, New Jersey, Maryland, Kentucky, Rhode Island, Minnesota

Residents of these states have rights that are generally similar to the CCPA rights described above, including the right to access, the right to delete (subject to the exceptions in each state's law, which are reflected in §6.4), the right to correct, the right to opt out of certain processing, and the right to appeal an adverse decision. To submit a request, email privacy@unnma.ai. The deletion exception for blocked-attempt records relies on each state's "security and integrity" or "defense of legal claims" exception.

11.3 Nevada

Nevada residents may request that we not sell their personal information. We do not sell personal information, but you may submit a confirmation request to privacy@unnma.ai.


12. Contact

| | | |---|---| | Entity | Unnma LLC | | Jurisdiction of formation | Florida, USA | | Privacy contact | privacy@unnma.ai | | EU representative under Art. 27 GDPR | Not appointed at this time; see §8 | | Data Processing Addendum | See revenue-drivers/cop-gateway/legal/data-processing-addendum-v1.md; available to customers on request |


By using the Service, you confirm that you have read and understood this Privacy Policy.