Privacy policy.

Effective 3 September 2026 · contact: support@eachlabs.ai

1. Scope and Roles

This Privacy Policy explains how Eachlabs Inc. ("Eachlabs", "we", "us") collects, uses, discloses, and protects personal data across our websites, developer console, APIs, software development kits (SDKs), and platform services (collectively, the "Services").

Controller vs. Processor Boundary

Under applicable data protection laws (including the EU General Data Protection Regulation (GDPR), UK GDPR, Swiss Federal Act on Data Protection (FADP), Turkish Law on Protection of Personal Data (KVKK), and United States federal and state privacy laws), Eachlabs operates in two distinct legal capacities:

  • ·Eachlabs as an independent Controller: Eachlabs acts as an independent Controller for Account Data, including profile and registration details, commercial billing records, developer contact communications, website cookies and analytics, and technical API telemetry. This Privacy Policy governs our processing of personal data in our capacity as an independent Controller.
  • ·Eachlabs as a Processor: In accordance with Section 14 of the Terms of Service, this Privacy Policy does not govern Customer Content (including prompts, input parameters, uploaded files, and generated outputs submitted to or processed through the Services). Customer Content is processed strictly as a Processor on Customer's documented instructions and is governed exclusively by our Data Processing Addendum (DPA).

2. Information We Collect

In our capacity as a Controller, Eachlabs collects the minimum personal information necessary to deliver, bill, secure, and operate the Services:

Account and Registration Information

When you create an account, register an organization, or generate API credentials, we collect your name, email address, password hash, organization name, and role. If you authenticate through third-party identity providers (such as Google OAuth or GitHub), we receive authentication identifiers and profile details authorized by your provider settings.

Billing and Transaction Information

Payment card processing and billing transactions are handled directly by our PCI-DSS compliant payment processor, Stripe. Eachlabs stores transaction records, invoice history, credit balances, and tokenized payment identifiers, but does not store raw payment card credentials (such as full card numbers or CVV/CVC codes).

Technical Telemetry and Usage Data

When you access our websites or make calls to the API, our servers automatically record technical telemetry and operational usage data. This technical telemetry includes request counts, timestamps, execution IDs, HTTP methods, endpoint routes, status codes, latency, client IP address, and browser or device user-agent information.

Customer Content Clarification

When you submit inputs, prompts, or files for inference, they constitute Customer Content and are processed in accordance with the DPA rather than this Privacy Policy.

4. AI Models and Model Training

Eachlabs Model Training Commitment

Eachlabs does not use Customer Content or Personal Data, or any copy, embedding, or derivative of them, to train, retrain, fine-tune, or improve any AI or machine-learning model, whether for Eachlabs, another customer, or any third party.

Third-Party Model Providers

When Customer directs Eachlabs to route requests to third-party AI models (e.g. OpenAI, Anthropic, Google Cloud), data handling, retention, and model practices are governed by the respective independent provider's terms and privacy policies, as set forth in DPA Section 5 and Terms of Service Section 9. Eachlabs makes no representation or warranty regarding upstream provider data handling or model training.

5. Cookies and Tracking Technologies

We use cookies, web beacons, and related tracking technologies on our public website and developer console to operate, analyze, and improve the Services.

Scope of Tracking Technologies

These analytics, measurement, and advertising technologies apply solely to website visitors navigating our public marketing pages. In accordance with Section 8 of our Terms of Service and Section 5 of our Data Processing Addendum (DPA), Customer Content and API Usage Data are never shared with advertising networks, used for cross-context behavioral advertising, or used to profile individuals.

Tracking Technologies Disclosed

Our public website utilizes the following analytics, conversion measurement, and relationship tooling:

  • ·Google Tag Manager (GTM): Facilitates tag management and loading of site measurement scripts.
  • ·Google Ads (gtag.js): Measures conversion events and effectiveness of developer acquisition campaigns.
  • ·PostHog: Product analytics, user interaction tracking, session replay for error diagnosis, and feature evaluation.
  • ·X (formerly Twitter) Conversion Pixel: Measures conversion events and developer campaign engagement.
  • ·Meta Pixel: Measures conversion events and advertising campaign effectiveness.
  • ·OpenAI Ads Pixel: Measures developer campaign acquisition and conversion events.
  • ·RB2B: Identifies visiting business entities to analyze business-to-business website interest and developer onboarding.
  • ·HubSpot: Contact forms, developer communication, and relationship management.
  • ·LinkedIn Insight Tag: Measures professional network outreach and campaign engagement.

Managing Preferences and Opt-Out Rights

Users can manage or disable cookie preferences through browser settings or privacy extensions. Because our public website does not currently deploy an automated consent management banner, users and California residents wishing to exercise statutory rights to opt out of cross-context behavioral advertising or request data deletion under the California Consumer Privacy Act (CPRA) may do so at any time by contacting support@eachlabs.ai.

6. Service Providers and Subprocessors

Eachlabs engages trusted third-party service providers to deliver cloud infrastructure, developer authentication, payment processing, error tracking, and operational support. To maintain an authoritative single source of truth, our complete and current list of authorized subprocessors—including corporate entities, processing activities, and locations—is published in our Subprocessor Directory at eachlabs.ai/subprocessors and Schedule 3 of our Data Processing Addendum (DPA).

Infrastructure and Operational Categories

  • ·Cloud Infrastructure: Scalable compute, encrypted object storage, managed relational databases, and edge networking located in AWS us-east-1 and global CDN points of presence.
  • ·Authentication and Security: Developer identity management, OAuth authentication, DDoS mitigation, and web application firewall services.
  • ·Billing and Support Tooling: Secure payment processing (Stripe), developer support ticketing, on-call incident alerting, and engineering issue management.

Customer-Directed Endpoints

Third-party AI model providers accessible through the Eachlabs API operate as independent Customer-Directed Endpoints under Section 5 of the DPA and Section 9 of the Terms of Service. When Customer selects or invokes a specific model endpoint (directly or through assisted model selection, routing, or fallback features), Customer affirmatively directs and instructs Eachlabs to route the relevant prompt and input data to that independent third-party provider for inference execution. These third-party AI model providers are invoked at Customer direction and do not form part of Eachlabs core infrastructure.

7. Data Retention

Eachlabs retains personal data and technical records only for as long as necessary to fulfill the purposes described in this policy, satisfy legal, tax, and accounting obligations, and deliver the Services in accordance with Schedule 1 of the DPA:

  • ·Execution Records: Execution records (including prompts, inputs, outputs, parameters, and provider response metadata) are retained in secure cloud storage in AWS us-east-1 for the lifetime of Customer's organization to maintain workflow history, debugging, and billing auditability.
  • ·Stored Media and Files: Uploaded files and media stored via the Storage API follow Customer-configured retention policies (default 180 days, configurable between 60 seconds and 365 days, or non-expiring).
  • ·Account and Billing Records: Account and billing records are retained for the active life of the account plus statutory tax and accounting retention periods (typically 7 years).
  • ·Backups: Automated database backups are retained for 14 days; versioned object storage backups are retained for up to 30 days. Backups are isolated and not used for ordinary processing.

8. Security Measures

Eachlabs implements commercially reasonable administrative, physical, and technical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorized access.

  • ·Data in Transit: Web traffic and public API requests enforce modern encryption in transit via TLS.
  • ·Data at Rest: Encryption at rest where supported in cloud storage and databases.
  • ·Access Control: Role-based access control (RBAC) and least privilege principles governing internal access.
  • ·Vulnerability Monitoring: Ongoing vulnerability monitoring, automated edge threat filtering, and structured incident response procedures.

9. International Data Transfers

Eachlabs operates infrastructure hosted primarily in the United States (AWS us-east-1). Where personal data originating in the European Economic Area (EEA), United Kingdom, Switzerland, Türkiye, Saudi Arabia, or the UAE is transferred to Eachlabs, such transfers are governed by appropriate legal transfer mechanisms:

  • ·EEA Transfers: Standard Contractual Clauses (EU SCCs - Commission Implementing Decision (EU) 2021/914) incorporated into DPA Schedule 4.
  • ·United Kingdom Transfers: UK International Data Transfer Addendum (Version B.1.0) issued by the ICO.
  • ·Switzerland Transfers: Swiss Federal Act on Data Protection (FADP) adaptations to the EU SCCs.
  • ·Türkiye Transfers: Turkish Personal Data Protection Law (KVKK No. 6698) Standard Contracts executed under DPA Schedule 4.D.
  • ·Saudi Arabia and UAE: Controller-to-processor contractual safeguards complying with Saudi PDPL and UAE Federal Decree-Law No. 45/2021.

10. Your Privacy Rights

Depending on your jurisdiction, you may hold statutory rights regarding your personal data under the GDPR, UK GDPR, Swiss FADP, Turkish KVKK, or US State Privacy Laws (e.g. CCPA/CPRA):

  • ·Right to Access & Portability: Request confirmation of processing and obtain a copy of your personal data.
  • ·Right to Rectification: Request correction of inaccurate or incomplete personal data.
  • ·Right to Erasure: Request deletion of personal data where statutory grounds apply.
  • ·Right to Restriction & Objection: Restrict or object to processing based on legitimate interests.
  • ·Right to Opt Out of Sale/Sharing: Opt out of personal data sharing for cross-context behavioral advertising (CPRA).
  • ·Right to Lodge a Complaint: Lodge a complaint with a competent supervisory authority in your jurisdiction.

We respond to verifiable data subject requests within 30 days (or statutory deadline). To exercise any of these rights, please contact support@eachlabs.ai. (Note: Customer Content requests should be directed to the Customer/Controller; Eachlabs will assist the Customer in fulfilling data subject requests in accordance with our DPA).

11. Children's Privacy

The Services are designed and offered exclusively to businesses, organizations, and professionals aged 18 and older. The Services are not directed to individuals under 18. Eachlabs does not knowingly collect or solicit personal data from anyone under 18. If we learn that an account has been created by or personal data collected from an individual under 18, we will take prompt steps to terminate the account and delete associated data.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements, platform functionality, or operational practices. Notice of material changes will be posted on our website or communicated to registered users via email. Continued use of the Services following notice constitutes acknowledgment of the updated policy.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us:

EntityEachlabs Inc. (Delaware Corporation)
Address8 The Green, Suite A, Dover, Delaware 19901, USA
Emailsupport@eachlabs.ai
Support & Compliancesupport@eachlabs.ai