Better InferBack to site

Privacy Policy

Last updated: 2026-09-26

1. Who is responsible

The controller within the meaning of the GDPR is Lukas Conrad, Better Infer, c/o IP-Management #5532, Ludwig-Erhard-Str. 18, 20459 Hamburg, Germany. Email: [email protected]. See also the imprint.

2. The short version

  • We do not store your prompts or the model’s answers, and we do not use them to train models.
  • We store your account (email, password hash), your balance and payment records, and usage metadata (token counts, timing, status), so we can bill and operate the service.
  • Payments are handled by Paddle, emails are sent through Resend.
  • We use one cookie, needed to keep you logged in. No analytics, no advertising, no tracking.

3. Visiting the website and hosting

When you open our website or call our API, the server processes technical connection data such as your IP address, the time and the requested address. This is needed to deliver the pages, keep the service stable and secure and to defend against abuse (legal basis: our legitimate interest, Art. 6(1)(f) GDPR). Retention: [retention period, to be defined].

The service is hosted by [hosting provider, to be added], which processes this data on our behalf under a data processing agreement.

4. Your account

To create an account we need your email address and a password (legal basis: performing the contract, Art. 6(1)(b) GDPR). Without them we cannot offer an account. We store:

  • your email address, and whether and when you confirmed it;
  • your password only as a salted Argon2 hash, never in plain text;
  • your current balance and the time the account was created;
  • for each login session: a hash of the session token, the time of the login and the last activity, and the browser’s User-Agent text, so you can see and end your sessions;
  • short-lived hashed tokens for confirming your email and resetting your password.

Accounts whose email address is not confirmed within 24 hours are deleted. A session ends after 14 days without activity.

5. API keys

For each API key we store a hash of the key, its first characters (so you can recognise it), the name you gave it and when it was created or revoked. The full key is shown once when you create it and cannot be read back.

6. Using the API

When you send a request, our server forwards it to a GPU server that we rent for this purpose from Vast.ai and its datacenter partners ([GPU server locations, to be confirmed]). The model processes your request there, and the answer is returned to you through our server. Prompts and answers are held in memory while the request runs. Our software does not write them to our database or to disk, and we do not use them to train or improve models. Please do not send personal data of other people unless you are allowed to.

What we do store per request (legal basis: performing the contract, Art. 6(1)(b), and our legitimate interest in running and securing the service, Art. 6(1)(f) GDPR):

  • which of your API keys was used and when;
  • the number of input, cached and output tokens, and the finish reason;
  • the result (completed or failed), a short generic error category, the request path and timing values (total time, time to first token, queue time);
  • a coarse label of the client software, such as “curl” or “OpenAI SDK”, derived from the User-Agent.

Retention: [retention period, to be defined].

7. Payments

You top up your balance through Paddle, which acts as the seller (merchant of record). Paddle collects and processes your payment details, such as name, email, billing address, payment method and IP address, under its own privacy policy. On the payment page your browser loads Paddle’s script, so Paddle receives your IP address. We receive from Paddle the confirmation of a payment, its amount and its transaction ID, and notices about refunds and chargebacks. We store these together with your balance movements (legal basis: performing the contract, Art. 6(1)(b), and legal bookkeeping obligations, Art. 6(1)(c) GDPR). Retention: [retention period, to be defined].

8. Emails

We send emails only to run your account: confirming your address and resetting your password. They are sent through Resend, which processes your email address and the mail content on our behalf. We send no marketing emails.

9. Suspension and fraud prevention

If a payment is reversed through a chargeback, the affected account is suspended automatically, and administrators can suspend accounts, for example on suspicion of fraud or abuse. We store the time and a reason for the suspension. The legal basis is our legitimate interest in protecting the service and its users from payment fraud and abuse (Art. 6(1)(f) GDPR). The automatic suspension is a decision made without human involvement. You can contact us at any time to have it reviewed by a person and to state your view.

10. Cookies

We set a single cookie named session. It keeps you logged in, is technically necessary, is not readable by scripts (HttpOnly) and is valid for up to 14 days. It needs no consent (§ 25(2) no. 2 TDDDG). We do not use analytics, advertising or tracking cookies.

11. Who receives your data

  • [hosting provider, to be added]: hosting of the website, API and database;
  • Vast.ai and its datacenter partners: GPU servers that process your requests;
  • Paddle: payments;
  • Resend: sending of account emails;
  • public authorities, where we are legally obliged to disclose data.

Where these providers act on our behalf we have concluded, or will conclude before launch, data processing agreements with them.

12. Transfers outside the EU/EEA

Some of these providers process data in the United States or other countries outside the EU/EEA. We rely on an adequacy decision (such as the EU-US Data Privacy Framework) or on the European Commission’s standard contractual clauses. You can ask us for a copy of the safeguards.

13. How long we keep data

  • Account data: until you delete your account or ask us to.
  • Unconfirmed accounts: deleted after 24 hours.
  • Sessions: end after 14 days without activity.
  • Usage metadata: [retention period, to be defined].
  • Payment and balance records: [retention period, to be defined].
  • Server logs: [retention period, to be defined].
  • Database backups: [retention period, to be defined].

14. Security

Passwords are stored as salted Argon2 hashes. Session tokens, reset tokens and API keys are stored only as hashes.

15. Your rights

You have the right to:

  • access the data we hold about you (Art. 15 GDPR);
  • have inaccurate data corrected (Art. 16);
  • have your data erased (Art. 17);
  • restrict the processing (Art. 18);
  • receive your data in a portable format (Art. 20);
  • object to processing that is based on our legitimate interests (Art. 21), on grounds relating to your particular situation;
  • lodge a complaint with a data protection supervisory authority (Art. 77), for example in the country where you live or work.

To exercise them, write to [email protected]. We answer within one month. Some records, such as payment records, we have to keep for a legally required period even after you ask us to erase your data.

16. Changes

We update this policy when the service or the law changes. The date at the top shows the current version.