Privacy Policy
Last updated 9 October 2026
Draft pending legal review. Details in [brackets] will be completed when the operating company is registered.
This policy explains what personal data [company legal name] ("eWest", "we") collects when you use ewest.ai, the console and the API, why, how long we keep it and your rights. We are the controller for account data. For the content you send through the API, we process it on behalf of you or your organisation.
1. What we collect
- Account data: name, email address, password hash or Google sign-in identifier, organisation name, and the members and invitations of your organisations.
- Request content: prompts, uploaded images and the text, images and videos generated for you.
- Usage data: for each request, the model, API key, timing, token or unit counts, cost, status and trace ID.
- Technical data: IP address, browser details and error reports, used for security and to fix problems.
- Payment data: when billing launches, payments will be handled by a payment provider; we will not store full card numbers.
2. How we use it
- To provide the Service: authenticate you, run your requests, show traces and usage, and bill usage (performance of our contract with you).
- To keep the Service secure, prevent abuse and enforce our policies (legitimate interests).
- To send service emails such as sign-in links, invitations and important changes. We do not send marketing email without your consent.
- To meet legal, tax and accounting obligations.
3. No training on your content
We do not use your prompts or outputs to train models. We select model providers whose API terms do not allow them to train on your requests [to be confirmed for each provider].
4. How long we keep it
- Prompts and outputs in request traces: 7 days, then deleted.
- Generated and uploaded media on cdn.ewest.ai: 7 days, then deleted. Download anything you want to keep.
- Usage and cost records: for as long as your organisation exists and as required for accounting.
- Account data: until you delete your account, then removed within [30] days except where the law requires us to keep it.
6. International transfers
Our main infrastructure is in the EU. Some providers, including some model providers, process data in other countries such as the United States. Where required, we rely on safeguards such as the EU Standard Contractual Clauses.
7. Security
Traffic is encrypted in transit, API keys are stored hashed or encrypted, and access to production systems is restricted. No system is perfectly secure; we will notify you and the authorities of a personal data breach as the law requires.
8. Your rights
Depending on where you live, you can ask to access, correct, delete or export your personal data, object to or restrict its processing, and complain to your data protection authority. Contact [privacy email]. For data in your organisation's requests, we will work with the organisation's owner.
10. Changes and contact
We will post changes here and tell you about material changes by email or in the console. Questions: [privacy email], [company legal name], [registered address].