Privacy Policy.
TheAI LTD, Innovation One, DIFC, Dubai, UAE (“TheAI”, “we”) is the controller of personal data processed in connection with the theai·cloud console at cloud.theai.com. We process personal data in accordance with the DIFC Data Protection Law No. 5 of 2020. Contact: cloud@theai.com.
- Account data: email address, organization name, sign-in method (email link or Google).
- Verification data: information you provide for know-your-customer and export-control screening.
- Operational data: SSH public keys you upload, instance and node assignments, API token metadata.
- Billing data: ledger of top-ups and usage. Card payments are processed by Stripe; we do not receive or store card numbers.
- Technical data: server logs (IP address, user agent, timestamps) and a strictly necessary session cookie. We collect first-party product analytics (page views, clicks, session recordings with all typed input masked) via PostHog, configured cookieless — no advertising trackers or cross-site cookies.
To provide and bill the Service (performance of contract); to meet legal obligations, including export-control and sanctions screening, accounting and record-keeping; and for our legitimate interests in securing and improving the Service (fraud and abuse prevention, debugging).
Data is shared only with processors and recipients needed to run the Service:
- Stripe (payment processing)
- Resend (transactional email delivery)
- PostHog Inc., USA (product analytics; no advertising use)
- Crisp IM SAS, France (live-chat widget)
- Google (only if you sign in with Google — we receive your verified email address)
- Hosting and data-center providers operating the console and the GPU Nodes
- Public authorities where disclosure is required by law, including export-control and sanctions authorities.
Some recipients are located outside the DIFC (including the EU, USA and Canada); transfers rely on appropriate safeguards under DIFC law.
Account and billing records are kept for the life of the account and thereafter as long as required by accounting, tax and export-control rules (typically 6 years). Verification records are kept for the period required by applicable sanctions and KYC obligations. Server logs are kept for up to 12 months. Instance data on Nodes is destroyed on termination and is not retained by us.
Subject to DIFC law, you may request access to, correction or deletion of your personal data, object to or restrict certain processing, and receive a copy in portable form. Deletion is limited by the retention obligations above. Write to cloud@theai.com; we respond within the statutory period. You may also lodge a complaint with the DIFC Commissioner of Data Protection.
Traffic to the console is encrypted (TLS). Sign-in links and API tokens are stored as cryptographic hashes only. Access to production systems is restricted and logged. No method of transmission or storage is completely secure; you must protect your own credentials and instance contents.
We may update this Policy; material changes will be announced via the console or email. The date above reflects the latest revision.