Privacy Policy
Last updated: July 30, 2026
FlatCompute ("FlatCompute", "we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what personal data we collect, how we use it, and what rights you have under the EU General Data Protection Regulation (GDPR) and Spanish law (LOPDGDD).
01Data Controller
FlatCompute is the data controller for personal data collected through the Platform. For data protection inquiries, contact us at privacy@flatcompute.com.
Legal address: [To Be Confirmed], Spain. FlatCompute is not currently registered with the Spanish Data Protection Agency (AEPD) as a data controller — registration will be completed before the Platform enters general availability.
02Data We Collect
Account data: Email address, name, and password (hashed). We use your email for authentication, notifications, and account recovery.
Payment data: We use Stripe as our payment processor. FlatCompute does not store full card numbers or CVV codes. We store your Stripe customer ID and the last 4 digits of your card for display purposes. Stripe processes all payment data according to its own privacy policy.
Usage data: For each inference request, we log: user ID, zone ID, subscription ID, model, prompt tokens, completion tokens, total tokens, duration (ms), time-to-first-token (ms), time-per-output-token (ms), and HTTP status code. This data is used for billing verification, capacity planning, rate-limit enforcement, and abuse prevention.
Technical data: IP address, browser type, and device information collected via standard HTTP headers. This is used for security, fraud prevention, and debugging.
API request content: The content of your prompts and the model's responses is not stored permanently by FlatCompute. The LiteLLM gateway processes requests in-memory and does not write prompt/response bodies to disk. Usage logs contain only token counts and metadata, not content. Exception: if we investigate abuse or policy violations, we may temporarily log request content for up to 30 days.
03How We Use Your Data
We use your personal data for the following purposes:
- Service provision: Authentication, subscription management, API key issuance, and usage tracking.
- Billing: Processing payments via Stripe, managing subscriptions, and verifying founding seat reservations.
- Capacity planning: Aggregating usage metrics per zone to make decisions about seat limits, hardware allocation, and new zone openings.
- Security & abuse prevention: Detecting rate limit violations, unauthorized access, and policy violations.
- Communication: Sending service notifications (zone activation, maintenance, billing issues) and responding to support requests.
- Legal compliance: Fulfilling legal obligations and responding to lawful requests from authorities.
04Legal Basis for Processing (GDPR Art. 6)
We process your personal data under the following legal bases:
- Contract (Art. 6(1)(b)): Processing your account, subscription, and usage data to provide the service you requested.
- Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, capacity planning, and platform improvement.
- Legal obligation (Art. 6(1)(c)): Retaining billing records and responding to legal requests as required by Spanish law.
- Consent (Art. 6(1)(a)): For any optional data collection that requires consent, such as marketing emails. You can withdraw consent at any time.
05Data Sharing & Subprocessors
We do not sell your personal data. We share data with the following subprocessors:
- Stripe (payment processing) — processes your payment data. Stripe is PCI-DSS compliant.
- GitHub (code hosting & CI/CD) — stores our source code and deployment configuration. Does not process user data directly.
- Brevo (transactional email) — sends service notifications and emails on our behalf. Receives your email address and email content.
- Cloud provider (OVH / Vast.ai) — hosts our infrastructure and GPU compute. Has physical access to servers but does not access application data.
We may share data with authorities if required by law. We do not transfer personal data outside the EU/EEA except where subprocessors have appropriate safeguards (e.g., Standard Contractual Clauses).
06Data Retention
Account data: Retained for as long as your account is active. Deleted within 30 days of account closure.
Usage logs: Retained for 90 days at full resolution, then aggregated to zone-level metrics (no user-identifiable data). Zone-level metrics are retained indefinitely for capacity planning.
Billing records: Retained for 7 years as required by Spanish tax law (Ley General Tributaria).
Abuse investigation logs: If request content is logged during an abuse investigation, it is deleted within 30 days of the investigation closing.
07Your Rights (GDPR)
Under the GDPR, you have the following rights:
- Access (Art. 15): Request a copy of your personal data.
- Rectification (Art. 16): Correct inaccurate or incomplete data.
- Erasure (Art. 17): Request deletion of your data ("right to be forgotten"). Note: billing records are retained for legal compliance.
- Restriction (Art. 18): Restrict processing of your data in certain circumstances.
- Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Objection (Art. 21): Object to processing based on legitimate interests.
- Withdraw consent: Withdraw consent for processing that was based on consent, at any time.
To exercise these rights, email privacy@flatcompute.com. We respond within 30 days. If you are not satisfied with our response, you may file a complaint with the Spanish Data Protection Agency (AEPD) at aepd.es.
08Security Measures
We take the following measures to protect your data:
- Passwords are hashed using bcrypt. We never store plaintext passwords.
- API keys are hashed at rest. Full keys are shown only once at creation time.
- All traffic between you and the Platform uses TLS encryption (HTTPS).
- Internal traffic between services (backend, LiteLLM, vLLM) travels over a private Docker network.
- Access to production infrastructure is restricted to authorized personnel using SSH keys.
No system is 100% secure. If we become aware of a security breach affecting your personal data, we will notify you and the relevant authorities within 72 hours, as required by GDPR Art. 33.
10Children's Privacy
FlatCompute is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us and we will delete it.
11Changes to This Policy
We may update this Privacy Policy from time to time. We will notify users of material changes via email at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
Questions?
Contact us at legal@flatcompute.com or write to: FlatCompute, [Legal Address To Be Confirmed], Spain.