Privacy Policy
What Conifer collects, why, who sees it, and how to make it stop.
Conifer Solutions, Inc. · Effective 2026-08-13
Most privacy policies describe a service that sends everything to a server. This one mostly describes a program that runs on your machine. That difference is the product, so we have written this policy to be specific enough to check rather than broad enough to cover anything.
Where we make a claim, we mean it literally. Where a protection is imperfect, we say so instead of rounding up.
The short version
| Local inference | Prompts, answers, files, and execution stay on your device. Nothing is sent for a turn that runs locally. |
| Cloud inference | The endpoint you or the router selects for a turn receives that turn's prompt and context. We do not log it, and we make no second copy. |
| Usage data | Categorical metadata — which screens, which model class, which error category. On by default, one switch to turn off. Never contains your text. |
| Prompt samples | A separate channel that does send your prompt text. Off by default. Nothing enables it but you. |
| Training | We never use your content to train models. Not ours, not anyone's. There is no opt-in for this because there is no program to opt into. |
| Cookies | None. Not for analytics, not for advertising, not for anything. |
| Selling data | Never. We do not sell or share personal information for cross-context behavioural advertising. |
Who we are
Conifer Solutions, Inc., a Delaware corporation, is the controller of the personal data described here.
- Notice address: 2418 Rogers Isle
- Contact for any privacy question or request: [email protected]
One address reaches us for everything — privacy requests, data-subject rights, and security reports included. We answer within two business days.
What we collect, by system
Conifer collects data through five systems that share no identifier with each other. Your anonymous install id cannot be linked to your account; the website visitor hash cannot be linked to either. This is a structural property, not a policy promise.
2.1 Website analytics — on, cookieless
When you visit conifer.build we record the page path, referrer, traffic source and campaign, clicks and scroll depth, coarse country, and browser user agent.
To count visitors without identifying them, we store a daily-rotating hash:
SHA-256 of your IP address, your user agent, the date, and a secret salt.
- Your raw IP address is never stored. It exists only in memory, as an input to that hash.
- The hash changes every day by construction, so it cannot follow you from one day to the next.
- If your browser sends Do Not Track or Global Privacy Control, we drop the hash and the country entirely and keep only an anonymous page count.
We set no cookies and use no third-party analytics service.
2.2 App usage data — on by default, one switch off
The desktop app records categorical facts about how it runs: device class
(platform, memory, CPU threads, GPU vendor, app version, power class), which app
areas and tools you used, which model architecture and quantization ran on which
lane, coarse error categories, timing buckets, and a conversation topic
label classified on your device into one of thirteen buckets such as coding,
writing, health, or finance.
This is on by default. Turn it off in Settings → Privacy & data. When you do, the app collects and sends nothing on this channel. On desktop your choice is remembered per machine, so it survives a reinstalled browser profile.
Events are buffered on your device, sent only when you are online, and the local copy is wiped once the send succeeds.
This channel carries no text. That is enforced by the server, not merely intended: the intake accepts a fixed list of fields and clamps every string to a closed set of permitted values. A value not on the list is discarded rather than stored. Only release builds collect at all.
The topic label is worth stating plainly: we learn that a conversation was about health or finance, as a category. We do not learn anything you said.
2.3 Prompt and search samples — off unless you turn them on
This is the only channel that sends your text off your device, and it is off by default.
Turning it on requires you to enable a switch that is separate from the usage-data switch above. Once on, samples of your prompt and search text may be sent with your usage data. Four conditions must all hold for a sample to be captured:
- usage data is on, and
- the prompt-sample switch is explicitly on, and
- the app is not in offline / Local-only mode, and
- the text does not trip our sensitivity filter.
Condition 3 means text is never even stored while you are offline — so a Local-only session cannot leak later when you reconnect.
Condition 4 refuses a sample outright — not redacts it — when the text mentions passwords, secrets, API or private keys, social security numbers, credit cards, or passports.
Before a sample is stored we run best-effort redaction over what remains, removing credential assignments, bearer tokens, recognisable API-key shapes, email addresses, long digit runs, and long opaque tokens. We run the same redaction again on our servers.
We describe this as best-effort because it is. Pattern matching cannot recognise a secret or personal detail written in ordinary prose — "my password is …", a name, an address, a health or financial description. Treat any text you enable this switch for as text we may hold. If that is not acceptable, leave the switch off. It is off unless you change it.
Samples are truncated at 4,000 characters. Conifer staff can read them in an internal dashboard, which shows recent samples in full. We use them to understand what people actually ask for. Turning the switch off purges buffered samples that have outlived your consent.
2.4 Account, forms, and purchases
- Account: your email address. We use magic links, so we never collect a password. Your session is kept in your browser's local storage, or your operating system keyring on desktop — not in a cookie.
- Forms: feedback, waitlist, and letters of intent store your email and whatever name, company, and message you provide. A contact-form message is emailed to us and not written to any database — it is a note to a human.
- Newsletter: you are added only if you explicitly tick the box. A waitlist signup alone does not subscribe you. Our email provider records opens and clicks. Every email has an unsubscribe link.
- Purchases: payment is handled by Stripe on Stripe's own pages. Card numbers never reach Conifer. We receive a signed confirmation that a purchase completed, which grants you what you bought.
- Marketplace: listings and media you publish are content you provide, and are visible according to the listing's status.
2.5 Cloud inference
When a turn runs on a cloud model, the prompt and the conversation context required to answer it go to the exact serving endpoint selected for that turn.
What we do not do, stated as commitments:
- We do not log your prompts or the model's responses.
- We do not make a second copy for training, evaluation, reward modelling, or routing feedback. There is no such send.
- We do not use your content to train any model.
What we do keep: metering records — account id, request id, model, token counts, cost, latency — so we can bill correctly and you can quote a request id to us when something goes wrong. Signed-in clients also upload per-turn metadata observations (where it ran, which model, token counts, latency). That is on by default and your client can turn it off.
One honest exception. After a request settles, the response body is held briefly in the gateway's working memory so that retrying the same request returns the same answer instead of charging you twice. It lives in RAM, never in a database, disappears when the process restarts, and never includes your prompt, your credentials, or any secret.
Your own API keys (BYOK). If you bring a provider key, we encrypt it with authenticated encryption under a master key, store only the ciphertext, and bind each stored key cryptographically to your account and that provider — so even a database-level attacker cannot make your key work under another account. It is decrypted only in memory at the moment of a call, and we never show it back to you: only the last four characters.
Provider terms still apply. Whatever provider serves your turn handles that request under its own policy, including when you use your own key. We cannot control their retention. Running local models avoids this entirely.
Why we process it, and on what legal basis
For users in the EU, UK, and other regions with equivalent law, our legal bases under the GDPR are:
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the service you asked for | Account, inference requests, purchases | Contract (Art. 6(1)(b)) |
| Bill accurately and prevent abuse | Metering, request metadata | Contract and legitimate interests (Art. 6(1)(f)) |
| Keep the service secure and working | Error categories, diagnostics | Legitimate interests (Art. 6(1)(f)) |
| Understand aggregate product usage | Usage data (§2.2) | Legitimate interests (Art. 6(1)(f)) — you may object at any time using the off switch |
| Learn what people ask for | Prompt samples (§2.3) | Consent (Art. 6(1)(a)) — off unless you enable it, withdrawable at any time |
| Send the newsletter | Email address | Consent (Art. 6(1)(a)) |
| Meet legal and tax obligations | Purchase records | Legal obligation (Art. 6(1)(c)) |
We do not carry out automated decision-making producing legal or similarly significant effects about you.
Who we share it with
We share personal data only with the subprocessors listed on our subprocessors page, which names each one, what it receives, and why. We update that page before adding a new one.
Otherwise, we disclose data only:
- when you direct us to,
- to comply with a valid legal obligation, or
- in a merger or acquisition — in which case this policy continues to apply until you are given notice of a replacement.
We have never sold personal information, and we do not share it for cross-context behavioural advertising. We use no ad networks, no data brokers, and no session-replay tools.
How long we keep it
| Data | Retention |
|---|---|
| Usage telemetry and prompt samples | 180 days, then deleted |
| Website analytics events | 24 months |
| Account records | While your account is open, then 30 days |
| Purchase and billing records | 7 years (tax and accounting law) |
| Form submissions and contact emails | Until you ask us to delete them |
| Gateway response cache | Minutes, in memory only — cleared on restart |
Ask us to delete something sooner and we will, unless the law requires us to keep it (billing records generally do).
Your rights
Everyone, wherever you live, may ask us to access, correct, delete, or export your data, or to stop a particular use. Email [email protected]. We reply within 30 days and will not charge you or degrade your service for asking.
If the GDPR or UK GDPR applies to you, you have the rights of access, rectification, erasure, restriction, portability, and objection, plus the right to withdraw consent at any time — withdrawal does not affect processing already carried out. You may also complain to your national data protection authority, though we would rather you told us first.
If you are in California, the CCPA/CPRA gives you the rights to know, delete, correct, and opt out of sale or sharing, and not to be discriminated against for exercising them. We do not sell or share personal information, so there is no opt-out to exercise — the Global Privacy Control signal is honoured on our website regardless. In the last 12 months we collected the categories in §2 and disclosed them only to the subprocessors in §4.
Other US states — including Virginia, Colorado, Connecticut, Utah, and Texas — provide substantially the same rights, and we extend the same process to everyone.
The fastest route for most requests is not to contact us at all: turn off usage data and prompt samples in Settings → Privacy & data, and delete local data on your device directly.
How we protect it
- Encryption in transit everywhere. Plaintext HTTP is refused for any endpoint carrying credentials.
- Your provider keys are envelope-encrypted at rest, bound to your account, and never displayed back to you.
- Row-level security on every database table, deny-by-default for public keys. Administrative reads need a separate server-side credential that is never shipped to a browser.
- Payment card data never touches our systems — Stripe collects it directly.
- The intake whitelists rather than blacklists, so a compromised client cannot smuggle unexpected data into our store.
- We never collect passwords, because we do not use them.
No system is perfectly secure, and we will not claim ours is. If you find a vulnerability, email [email protected] and we will work with you.
International transfers
Conifer is based in the United States and our providers are US-based, so data you send us is processed in the United States. If you are in the EU, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) for these transfers, together with the technical measures in §7.
The local-first design is itself a transfer control: a turn that runs on your device never crosses a border at all.
Children
Conifer is not for children under 13, and we do not knowingly collect personal data from them. If you are between 13 and 18, you may use Conifer only with a parent or guardian's involvement.
If you believe a child under 13 has given us personal data, email [email protected] and we will delete it promptly.
Cookies and local storage
We set no cookies. No analytics cookies, no advertising cookies, no third-party tags.
We do use your browser's local storage on your own device for things the product cannot work without: your sign-in session, your theme, your settings, and the on-device telemetry buffer. That data stays on your machine and is not a tracking mechanism. Clearing your browser storage clears it.
Changes to this policy
When we change this policy we update the version date at the top and publish the new version at this address. For a change that materially reduces your privacy protections, we will give notice at least 30 days beforehand — by email if we have your address, and in the app — so you can object, export your data, or stop using the service before it takes effect.
We will never apply a materially different use to data already collected without asking you first.
Contact
Questions, requests, or complaints: [email protected]
Conifer Solutions, Inc. · 2418 Rogers Isle
Version history: 2026-08-13 — first complete policy; replaces the 2026-08-04 summary. Adds legal bases, retention, rights, subprocessors, transfers, children's privacy, and full disclosure of the prompt-sample channel and the gateway response cache.