Privacy notice · website and hosted service
Your data supports the service. It is not the product.
This notice explains how InferCrane handles personal data across infercrane.com, the email updates, console authentication, and the hosted service. We do not sell personal data or use account data, prompts, or model outputs to train models.
Who is responsible
InferCrane is an international service currently operated by Yasin Toy from Germany. Privacy requests may be sent to privacy@infercrane.com. We apply the privacy rights required where each user lives and use international-transfer safeguards when personal data crosses borders.
Website and email-update data
The email-update form collects your email address and subscription status. A confirmation email completes the double opt-in process, and the confirmed subscription is retained until you unsubscribe, withdraw consent, or the list is retired. The public landing page does not request provider credentials, prompts, model outputs, or control-plane access.
Workload-pilot inquiries
A workload-pilot inquiry collects your email address, optional company or project, current model or provider, workload description, primary bottleneck, optional spending band, and consent to contact you about that inquiry. Please do not submit credentials, prompts, model outputs, or production datasets. Resend delivers the inquiry to the engineering contact mailbox. Sending an inquiry does not create an account, start an experiment, or subscribe you to marketing; product updates require their own double opt-in.
Authentication and Google user data
The console supports email, GitHub, and Google sign-in through Clerk. If you choose Google, InferCrane receives only the basic identity information covered by the requested scopes: your Google account identifier, email address, name, and profile image. We use that data only to create and secure your InferCrane account, maintain your session, and associate you with the organizations you choose. InferCrane does not request access to Google Drive, Gmail, Calendar, contacts, or other Google product data. Google sign-in data is not used for advertising or model training and is shared only with processors needed to provide authentication and the hosted service.
Console and service data
When you use the hosted service, we process account and organization identifiers, configuration, audit events, service usage, request metadata, operational evidence, and billing records needed to provide and secure the service. Connected credentials are handled only through designated secret paths. Whether request content is retained is controlled by the applicable product setting or written agreement; it is not placed in analytics or used to train models.
Hosted model inference
When you call an InferCrane-hosted model directly or through a distribution partner such as OpenRouter, we process the prompt, supported attachments, generation settings, and model output only to provide the requested inference. We do not sell that content, use it for advertising, or use it to train models. Request content is not intentionally written to InferCrane application logs or durable storage and is discarded after the response completes. This is a zero-day content-retention policy for the hosted model endpoint unless a separate written agreement expressly says otherwise.
We retain content-free operational records such as request identifiers, model and endpoint revisions, region, token counts, timing, status, and error class for up to 30 days to reconcile billing, investigate failures, and protect the service. Invoices and legally required financial records may be retained for the period required by law. If you reach InferCrane through OpenRouter or another distributor, that distributor separately processes the request under its own privacy notice before forwarding it to us.
Why we process data
We process data to provide the service and perform our agreement with you, protect the service and prevent abuse, comply with legal obligations, and improve reliability based on our legitimate interests. Product-update email is based on consent and may be withdrawn at any time.
Processors and international transfers
We use service providers for specific functions, including Clerk for authentication, Supabase for hosted application data, Vercel and Fly.io for application delivery, Stripe for payments, Resend for transactional email, Modal and RunPod for hosted GPU inference and infrastructure qualification, and PostHog and Vercel Web Analytics for product and site analytics. Infrastructure providers vary by the deployment path and are disclosed before customer traffic is routed. These providers process data on our instructions under their own contractual and security commitments. We prefer European regions where available; when data is transferred outside the European Economic Area, we rely on applicable contractual or legal safeguards.
Analytics
We use Vercel Web Analytics for aggregate page traffic. We may also use PostHog in cookieless mode to understand where visitors leave the launch journey, such as whether the email-update form was viewed, started, or completed. Analytics never receives the email address entered in the form, confirmation tokens, prompts, model outputs, credentials, or session recordings. PostHog is configured without cookies, browser storage, person profiles, automatic interaction capture, or session replay. It records aggregate Core Web Vitals so we can find slow or unstable pages. We may use anonymous feature-flag assignments to compare launch-page wording; those experiments use the same cookieless, content-free analytics boundary.
When a visitor arrives through an X advertisement, the landing URL may contain an X click identifier. If that visitor successfully confirms email updates or sends a workload pilot inquiry, we may return that click identifier and an opaque deduplication identifier to X through its server-side Conversion API. We do not load the X browser pixel, set X advertising cookies, or send X the visitor's email address, phone number, IP address, user agent, workload contents, or form contents. We honor browser Global Privacy Control and Do Not Track signals by omitting this attribution.
Retention and security
Data is retained only while needed for the purposes above, to meet legal obligations, resolve disputes, or protect the service. Retention periods vary by record type; account data is deleted or anonymized after a valid deletion request unless it must be retained by law. We apply access controls, encryption in transit, secret separation, logging, and organization isolation appropriate to the data being processed.
Your choices and rights
Every marketing update includes an unsubscribe option. You may request access, correction, deletion, restriction, portability, or objection where applicable, and you may withdraw consent without affecting earlier processing. You can revoke Google access from your Google Account and may request deletion of the corresponding InferCrane account by emailing privacy@infercrane.com. You may also complain to your local data-protection authority.
Changes
We may update this notice when the service or its providers change. Material changes will be announced through the service or by email where appropriate.
Last updated: September 23, 2026.
← Back to InferCrane