Privacy policy

Last updated August 2026. This version has not yet been reviewed by counsel.

Draft — legal review required

This document was written to describe how Larsa actually works, but it is not a finished legal instrument. Have it reviewed by a lawyer qualified in your jurisdiction before you rely on it, and fill in the bracketed placeholders — the operator's legal name, its registered address, and the governing law — before publishing it.

1. Scope

This Privacy Policy explains what personal data Larsa (“we”, “us”) collects when you create an account, use the console, or call the API at api.console.larsa.larsima.com, why we collect it, and the choices you have. It covers the operator's own systems; it does not cover the content of the requests you send to the models themselves beyond what is described in Section 4, which is deliberately narrow.

This policy is about you as our customer — the person or organization with an account. If you are an end user of something one of our customers built on top of the Service, that customer's own privacy policy governs you and is where you should direct a data request; we process that data as their processor, as described in the Data Processing Addendum.

2. Account and billing information

When you create an account we collect the information you give us: name, email address, and for an organization account, the organization's name and the members you invite. If you add payment details, our payment processor collects and stores them; we retain only the metadata needed to reconcile a charge — the last four digits of a card, an invoice ID, an amount — not the full instrument.

We keep a record of your ledger: top-ups, the metered charges against them, and your spend cap, because that record is the basis of your invoices and is required for our own financial and tax records.

3. Usage metering and request metadata

Every API call is metered so it can be billed and rate-limited: the endpoint called, the model used, the timestamp, the size of the request and response in tokens, characters, audio minutes or pages, the API key used, the response status, and the latency. This is the data behind your usage dashboard and your invoice line items, and it is retained for as long as your account is active plus the period described in Section 7.

We also log operational metadata needed to run and secure the Service: IP address, user agent, and request identifiers, used for abuse detection, rate limiting, and debugging an incident.

4. What we do not collect: your request and response content

The bodies of your API requests and responses — the prompts you send, the documents you upload for OCR or retrieval, the audio you send for transcription, the text a model returns — are not used to train any model, ours or a third party's, and are not reviewed by a person as a matter of course. Content passes through the inference pipeline to produce your response and is not kept beyond the operational window needed to serve that request and its immediate retries, except for content you deliberately store yourself in a Knowledge Base, which persists until you delete it because storing it is the feature.

We may retain request content for longer only where necessary to investigate a specific abuse report, a security incident, or a legal obligation — and only that content, not as a general practice.

5. Cookies

The console uses four cookies and no third-party tracking or advertising cookies.

Cookie Purpose Duration
larsa_session Keeps you signed in. Strictly necessary — without it the console cannot tell your requests apart from a stranger's. Session, until you sign out
larsa_owner Marks a session as an operator-staff session, so the owner panel and the customer console can share infrastructure without one leaking into the other. Session, until you sign out
larsa_lang Remembers your chosen interface language so the console does not fall back to browser defaults on every visit. 1 year
larsa_theme Remembers your chosen light, dark, or system theme. 1 year

None of these cookies are used for advertising or cross-site tracking, and none are shared with a third party.

6. How we use information

We use account and billing information to operate your account, meter and bill usage, enforce the spend cap you set, and communicate with you about the Service. We use usage metadata to render your dashboards, apply rate limits, detect abuse, and diagnose incidents. We use aggregated, de-identified usage statistics — total requests per model, not tied back to you — to plan capacity on our own hardware.

7. Retention

Account and billing records are kept for the life of your account and for [RETENTION PERIOD, e.g. seven years] after closure, to satisfy tax and accounting obligations. Usage metering records behind your invoices are kept for the same period. Operational logs (IP address, request identifiers) are kept for [OPERATIONAL LOG RETENTION, e.g. 90 days] and then deleted or aggregated beyond identifiability. Knowledge Base content is kept until you delete it or close your account, after which it is removed from active storage within 30 days and from backups on their normal rotation.

8. Sub-processors and other recipients

We use a small number of sub-processors to run the Service: our payment processor, for billing; our email delivery provider, for account and security notices; and infrastructure providers for the services we do not run on our own hardware, such as backup storage and outbound mail delivery. Inference itself runs on hardware we operate; we do not route your request content through a third-party model API. A current list of sub-processors is available on request to [PRIVACY CONTACT EMAIL].

We disclose personal data to a third party otherwise only where you have asked us to (an integration you configured), where the law compels it, or in connection with a merger, acquisition, or sale of assets, in which case we will require the recipient to honor this policy.

9. International transfers

Our infrastructure is located in [PRIMARY DATA LOCATION — FILL IN]. If you or your users are located elsewhere, using the Service involves transferring data to that location. Where the law requires a specific transfer mechanism, we put one in place before the transfer occurs; see the Data Processing Addendum for the mechanism that applies to your account.

10. Security

We encrypt data in transit with TLS and encrypt stored account, billing, and Knowledge Base data at rest. Access to production systems is limited to staff who need it for their role, is logged, and is removed when it is no longer needed. We describe our technical and organizational measures in full in the Data Processing Addendum.

11. Your rights

Depending on where you are located, you may have the right to access the personal data we hold about you, correct it, delete it, export it in a portable format, restrict or object to some processing, and withdraw a consent you have given. You can see and edit most of your own account data directly from the console; for anything you cannot, or to exercise any of these rights, contact us at [PRIVACY CONTACT EMAIL] and we will respond within the period the law where you are located requires.

Deleting your account removes your profile and Knowledge Base content as described in Section 7; billing records we are required to keep for tax purposes are retained on the schedule in that section regardless of a deletion request, as the law permits.

12. Children

The Service is not directed at anyone under 18 and we do not knowingly collect personal data from a child. If we learn an account belongs to someone under that age we will close it.

13. Changes to this policy

We may update this policy as the Service changes. For a material change we will give notice through the console or by email before it takes effect. The “last updated” date at the top of this page always reflects the current version.

14. Contact

Questions about this policy, or a request to exercise the rights in Section 11, can be sent to [PRIVACY CONTACT EMAIL] or to [REGISTERED BUSINESS ADDRESS]. Where applicable law requires a designated data protection officer or representative, theirs is the contact on file at that address.