Privacy policy · effective 18 September 2026
Privacy,
without guesswork.
This policy explains how TrimLayer processes personal data when you visit trimlayer.com, create a workspace, use the dashboard, context optimization API or MCP integration, or contact us.
1. Who is responsible
TrimLayer is the service operator and data controller for account, website and commercial data described here. For customer content sent through the optimization service, TrimLayer generally acts as a processor on the customer’s instructions. Privacy questions and rights requests can be sent to [email protected].
2. Data we process
Account and workspace
Name, work email, organization and project names, selected plan, onboarding answers, email-verification state and acceptance timestamps for these policies.
Authentication
Password hashes, hashed session and email-token values, login state and security timestamps. Passwords and reset links are not stored in readable form.
API and usage
Project-key prefix and hash, provider and model identifiers, protocol, status, latency, byte and token counts, optimization decision, saved-token totals, quotas and billing period.
Support and billing
Messages you send us and subscription identifiers or billing status. Payment-card details are handled by the configured payment provider and are not stored by TrimLayer.
We also process essential technical data such as IP address, user agent, security events and request timestamps when needed to deliver, secure and troubleshoot the service.
3. Why we use it
- Provide accounts, authentication, context optimization, exact recovery, usage reporting and support.
- Measure quotas, enforce rate limits, prevent abuse and maintain service reliability.
- Manage subscriptions, invoices and customer communications.
- Meet legal obligations and establish, exercise or defend legal claims.
- Improve performance and safety using content-free operational measurements.
Depending on the relationship and applicable law, processing is based on performance of a contract, legitimate interests in operating and securing the service, consent where requested, or compliance with legal obligations.
4. Prompts, documents and AI context
TrimLayer does not store prompt or response bodies in ordinary request logs. The optimization service processes supplied context in memory and returns optimized_context or the unchanged original. It does not accept model-provider credentials or make a downstream model call. When recoverable context is enabled, omitted source bytes are encrypted with AES-256-GCM before being written to PostgreSQL, scoped to the organization, project and API key, and are available only through the matching recovery credential. Recovery entries expire after 30 minutes by default, never later than 24 hours, and are limited to 500 live entries per API key.
Your application decides whether and where to use the returned context. Any later processing by a model provider is governed by your direct agreement with that provider.
5. Cookies and local storage
We use essential cookies for secure sessions and the temporary Google sign-in state. Session cookies are HttpOnly, Secure in production and use restrictive SameSite settings. We also use Google Analytics to measure aggregate website usage; analytics may set or read identifiers according to your browser and consent settings. We do not use advertising cookies.
7. Retention and security
We keep account and billing records while your workspace is active and as needed for legal, accounting, fraud-prevention and dispute purposes. Security tokens expire and are single-use; password reset links expire after 30 minutes. Operational records are retained according to the deployment’s configured retention policy. When an account is deleted, data is deleted or de-identified unless retention is required by law or necessary to protect legitimate claims.
Controls include password hashing, hashed API and session keys, encryption for recoverable source content, tenant-scoped database access, row-level security, rate limits and restricted administrative access. No online system can promise absolute security.
8. Your choices and rights
Subject to applicable law, you may request access, correction, deletion, restriction, portability or information about recipients, and may object to certain processing or withdraw consent without affecting earlier lawful processing. You may also lodge a complaint with your local data-protection authority. Send requests to [email protected]; we may verify your identity before acting.
9. Children and changes
The service is intended for business users who are at least 18 or the age of legal majority where they live. We may update this policy as the product, providers or law changes. Material changes will be announced in the service or by email, and the effective date above will be updated.
