Privacy policy · effective 18 September 2026

Privacy,
without guesswork.

1. Who is responsible

TrimLayer is the service operator and data controller for account, website and commercial data described here. For customer content sent through the optimization service, TrimLayer generally acts as a processor on the customer’s instructions. Privacy questions and rights requests can be sent to [email protected].

2. Data we process

We also process essential technical data such as IP address, user agent, security events and request timestamps when needed to deliver, secure and troubleshoot the service.

3. Why we use it

  • Provide accounts, authentication, context optimization, exact recovery, usage reporting and support.
  • Measure quotas, enforce rate limits, prevent abuse and maintain service reliability.
  • Manage subscriptions, invoices and customer communications.
  • Meet legal obligations and establish, exercise or defend legal claims.
  • Improve performance and safety using content-free operational measurements.

Depending on the relationship and applicable law, processing is based on performance of a contract, legitimate interests in operating and securing the service, consent where requested, or compliance with legal obligations.

4. Prompts, documents and AI context

TrimLayer does not store prompt or response bodies in ordinary request logs. The optimization service processes supplied context in memory and returns optimized_context or the unchanged original. It does not accept model-provider credentials or make a downstream model call. When recoverable context is enabled, omitted source bytes are encrypted with AES-256-GCM before being written to PostgreSQL, scoped to the organization, project and API key, and are available only through the matching recovery credential. Recovery entries expire after 30 minutes by default, never later than 24 hours, and are limited to 500 live entries per API key.

Your application decides whether and where to use the returned context. Any later processing by a model provider is governed by your direct agreement with that provider.

5. Cookies and local storage

We use essential cookies for secure sessions and the temporary Google sign-in state. Session cookies are HttpOnly, Secure in production and use restrictive SameSite settings. We also use Google Analytics to measure aggregate website usage; analytics may set or read identifiers according to your browser and consent settings. We do not use advertising cookies.

6. Service providers and transfers

Data is shared only as needed with infrastructure, analytics, email-delivery, authentication and payment providers. Current integrations may include Google for optional sign-in and site analytics, Stripe when checkout is enabled, and the configured SMTP delivery service. TrimLayer does not send optimized context or provider credentials to a model provider. These service providers process data under their own terms and may operate in other countries. We use contractual and technical safeguards where applicable.

7. Retention and security

We keep account and billing records while your workspace is active and as needed for legal, accounting, fraud-prevention and dispute purposes. Security tokens expire and are single-use; password reset links expire after 30 minutes. Operational records are retained according to the deployment’s configured retention policy. When an account is deleted, data is deleted or de-identified unless retention is required by law or necessary to protect legitimate claims.

Controls include password hashing, hashed API and session keys, encryption for recoverable source content, tenant-scoped database access, row-level security, rate limits and restricted administrative access. No online system can promise absolute security.

8. Your choices and rights

Subject to applicable law, you may request access, correction, deletion, restriction, portability or information about recipients, and may object to certain processing or withdraw consent without affecting earlier lawful processing. You may also lodge a complaint with your local data-protection authority. Send requests to [email protected]; we may verify your identity before acting.

9. Children and changes

The service is intended for business users who are at least 18 or the age of legal majority where they live. We may update this policy as the product, providers or law changes. Material changes will be announced in the service or by email, and the effective date above will be updated.