Aplum AI Privacy Policy

Effective date: July 25, 2026 Version: 2026-07-25-v4

This Privacy Policy explains how Aplum AI LLC ("Aplum AI," "we," "us," or "our") collects, uses, discloses, and retains personal information when a person visits, creates an account for, purchases, or uses Aplum AI. It also explains the choices available to users. Contact founder@aplumlabs.com with privacy questions or requests.

1. Scope and roles

This Policy covers Aplum AI's public website, customer account, model-evaluation application, billing and support functions, and related transactional communications (collectively, the "Service"). The Service may be offered to United States businesses and adults acting for them ("Business Customers") and, only when Aplum AI's separate individual-sales launch controls are enabled, to adult United States residents purchasing and using it personally ("Individual Customers"). It is not directed to children.

For account administration, security, billing, direct support, and Aplum AI's own business operations, Aplum AI determines why and how personal information is processed. For prompts, test materials, model inputs and outputs, reports, and similar material submitted through an account ("Customer Content"), the Customer decides what to submit and which AI providers and workflows to use. A Business Customer determines the business purpose and is responsible for required notices and authority for personal information it submits. An Individual Customer submits Customer Content for that person's own purposes and is responsible for having rights to submit any information about another person.

This Policy does not govern an AI provider, payment service, linked website, or other third party acting under its own terms and privacy notice. Their practices may differ from ours.

2. Information we process

Depending on how the Service is used, we process the following categories.

The current customer Service does not accept ordinary server-side file uploads or per-prompt attachments. For the battery CSV import, the browser reads the selected CSV locally, displays normalized permitted rows for review, and transmits only the structured row values the user confirms. Aplum AI does not receive or store the original CSV bytes, local path, or original filename through that flow. Pasted or manually entered text is Customer Content even if it originated in another document.

3. Sources of information

We receive information directly from users, interested visitors, Business Customers, and Individual Customers; automatically from the browser, application, and hosting infrastructure when the Service is used; from Stripe about checkout, subscriptions, payments, cancellation, and refunds; from transactional-email providers about message delivery; from selected AI providers when they return outputs or usage information; and from a person who contacts us or validly directs us to act.

The current customer Service has no data-broker or purchased-consumer-profile intake.

4. Notice at collection and how we use information

At or before account registration, Aplum AI links to this Policy and identifies the account and eligibility information being requested. We collect those categories to create and secure the account, record the selected customer type and legal acceptance, provide the no-card trial when offered, communicate about the account, and administer access. We retain them using the criteria in Section 10. We do not sell them for money or share them for cross-context behavioral advertising.

We use information to:

We do not use the substance of Customer Content to advertise to a user. Research use is governed separately as described below.

5. AI providers and provider keys

Aplum AI supports workflows involving Anthropic, OpenAI, Google, Sakana AI, xAI, and supported Meta-hosted model endpoints. The available list may change. A workflow may send relevant Customer Content and instructions to more than one provider—for example, a target model and a separate evaluator, grader, report, image, search, innovation, or analyst model. The interface and model configuration determine which providers are used.

Current production customer accounts use provider keys supplied for that account; customer activity is not charged to Aplum AI's internal provider keys. We encrypt stored customer provider keys using dedicated application key material and transmit a key to its provider as needed to authenticate a requested call. A user may replace or delete a stored key through account controls. The provider receives the request under the provider account associated with that key, and the customer's agreement with that provider may govern charges, retention, training, abuse monitoring, and other processing. Aplum AI does not control those provider practices.

We may introduce an expressly identified platform-funded provider feature in the future. We will update the Service or this Policy as appropriate if that materially changes the processing described here.

6. Research Mode

Research Mode is an Aplum AI administrative configuration; it is not currently a customer-accessible research console. When Research Mode is off, no new content-based Research Use begins, research-discounted enrollment is unavailable, and Aplum AI does not use the substance of Customer Content for generalized benchmark development, model training, advertising, or content-based product research. Processing needed to perform requested features, secure the Service, provide support, and measure non-content operational performance continues.

If Research Mode is enabled, Customer Content may be used for the specific research purposes and categories described in the then-current Research Mode Terms and Research Use Disclosure only after an eligible Business Customer's authorized account owner separately accepts those documents and affirmatively authorizes Research Use. Individual Customer Content is not eligible for Research Use under the current legal package. General Terms or this Policy alone do not grant that authorization. Withdrawal stops new content-based Research Use as described in those documents. Provider credentials, authentication information, billing data, and support communications are not authorized for Research Use.

We may preserve lawfully created aggregated or de-identified findings that are not reasonably linkable to a customer and do not reveal identifiable Customer Content. We do not attempt to re-identify de-identified material except to test safeguards or as required by law.

7. Disclosures and service providers

We disclose information only as reasonably necessary for the purposes above, including to:

The public site loads fonts from Google Fonts. As a result, a visitor's browser may make a direct request to Google that includes ordinary network information such as IP address and browser headers.

Aplum AI personnel with administrator access may access or, when reasonably necessary, impersonate a customer account to provide requested support, investigate security or billing issues, administer access, enforce restrictions, or comply with law. Authorized research personnel may access authorized research material only when Research Mode and valid Research Use Authorization permit it. We limit such access by role and purpose; administrator access is not a customer collaboration feature.

8. Cookies and local browser storage

We use a secure session cookie to maintain authentication and a CSRF cookie to protect authenticated requests. Production session cookies are configured as Secure, HttpOnly, and SameSite=Lax; the CSRF cookie must be readable by the application script and is configured as Secure and SameSite=Lax. We use local browser storage for interface preferences, selected model settings, pending-job references, and related requested functionality.

We do not currently use third-party advertising pixels or a third-party customer-behavior analytics script. Infrastructure and linked providers may process ordinary network information under their own policies. Browser settings can clear cookies and local storage, but doing so may sign the user out, remove preferences, or interrupt pending-job display.

9. Sale, targeted advertising, and browser privacy signals

We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising, use Customer Content for targeted advertising, or knowingly sell or share personal information of anyone under 18. We do not offer financial incentives for personal information.

Because we do not engage in those sale or targeted-advertising practices, a Global Privacy Control signal does not change such processing. We will treat a recognized opt-out signal as required if our practices change or applicable law requires a response. We do not track users across unrelated websites for advertising, so browser "Do Not Track" signals do not cause a separate change in the Service.

10. Retention, deletion, and account closure

Retention depends on the type of information, account status, requested features, security and fraud needs, provider behavior, financial and legal obligations, and whether information is needed to resolve a dispute or enforce an agreement. We apply the following criteria:

Account deletion does not itself cancel an active Stripe subscription. A linked subscription must be completely canceled before permanent account deletion so that future charges and transaction ownership can be reconciled safely. Users can cancel through the Stripe billing portal available in the Service or contact us for help. Aplum AI may retain information longer when required by law, legal hold, security investigation, fraud prevention, or an unresolved transaction or claim.

11. Security

We use safeguards designed for the nature of the information in our control. Confirmed measures include TLS in production; password hashing; hashed, expiring, single-use account tokens; encrypted provider keys with dedicated key material; secure session settings; CSRF protections; same-origin restrictions; security response headers; signed Stripe and email webhooks; access controls; plan and ownership checks; and restricted-content screening. No online system is perfectly secure, and we cannot guarantee that information will never be accessed, lost, altered, or disclosed improperly.

Users are responsible for protecting credentials, choosing appropriate provider settings, reviewing who can access their account email and provider accounts, and avoiding restricted information. Contact founder@aplumlabs.com promptly if unauthorized access is suspected.

12. Choices and privacy requests

Users can update available account settings and provider keys, delete stored provider keys, delete certain application items, manage or cancel subscriptions through billing controls, and withdraw Research Use Authorization when that feature is available. A person who submitted availability-interest information may ask us to access, correct, or delete it by contacting us. Because available exports cover particular product artifacts and summaries rather than every account or interest record, a person may request a broader copy of personal information by contacting us.

Subject to applicable law and appropriate verification, a user may request access to, correction of, or a portable copy of personal information; deletion; information about categories and recipients; restriction or objection where applicable; limitation of sensitive-personal-information use where applicable; or an appeal of a denied privacy request. A user may also ask us to confirm that we do not sell or share personal information for targeted advertising. We will not unlawfully discriminate for exercising a privacy right.

Send requests to founder@aplumlabs.com with the subject "Privacy Request." Describe the account and request without including passwords, provider keys, restricted data, or unnecessary Customer Content. We may verify the requester's identity, email ownership, business authority where applicable, and authorization of an agent. If Aplum AI processes personal information only on behalf of the requester's business, we may direct the request to that business. We may deny or limit a request where permitted by law and will explain available appeal steps. To appeal, reply with the subject "Privacy Appeal."

13. Children and restricted information

The Service is for users at least 18 years old, whether acting for a United States business or using an enabled Individual Customer account. We do not knowingly collect personal information from children through the customer Service. Contact us if a child is believed to have provided personal information.

Do not submit medical records; health, medical, wellness, diagnosis, treatment, or health-inference information about an identifiable person; information about minors; payment-card data; government identifiers; authentication secrets other than supported provider credentials; biometric identifiers; student records; nonpublic consumer-credit information; or information for regulated credit, housing, insurance, employment, or similar high-impact decisions. Technical acceptance is not permission. The Service may reject restricted submissions without retaining the submitted text.

14. United States operation

Aplum AI is operated from the United States and the public Service is limited to United States Business Customers and, when separately enabled, adult United States Individual Customers. Information is processed in the United States and may be processed in other locations where a selected provider or service provider operates. Do not use the Service from another jurisdiction if that processing or the applicable United States customer terms are not permitted.

15. Changes to this Policy

We may update this Policy prospectively. We will post the new version and effective date and provide additional notice when appropriate to the significance of the change. We will not use a Policy update alone to authorize materially broader content-based Research Use; that requires the separate acceptance and affirmative authorization described above.

16. Contact

Aplum AI LLC
Privacy email: founder@aplumlabs.com

For the safest response, do not put passwords, provider keys, payment-card data, medical information, or other restricted data in an email request.