Privacy Policy.
1 · CONTROLLER
TheAI LTD, Innovation One, DIFC, Dubai, UAE (“TheAI”, “we”) is the controller of personal data processed in connection with the theai·cloud console at cloud.theai.com. We process personal data in accordance with the DIFC Data Protection Law No. 5 of 2020. Contact: cloud@theai.com.
2 · WHAT WE COLLECT
- Account data: email address, organization name, sign-in method (email link or Google).
- Verification data: information you provide for know-your-customer and export-control screening.
- Operational data: SSH public keys you upload, instance and node assignments, API token metadata.
- Billing data: ledger of top-ups and usage. Card payments are processed by Stripe; we do not receive or store card numbers.
- Technical data: server logs (IP address, user agent, timestamps) and a strictly necessary session cookie for signed-in users.
- First-party identifier: a random cookie
theai_sid(12 months) set on the product pages. It has one job — to count the steps of a quote request (visit → form → request) and to rate-limit form submissions. It is not shared with anyone and carries no personal data. - Analytics: self-hosted Umami (runs on our own server, no cookies, no data leaves it) and PostHog product analytics configured cookieless — page views, clicks, and session recordings with all typed input masked. No advertising trackers, no cross-site cookies — which is why there is no consent banner: nothing here needs one.
3 · WHY WE PROCESS IT
To provide and bill the Service (performance of contract); to meet legal obligations, including export-control and sanctions screening, accounting and record-keeping; and for our legitimate interests in securing and improving the Service (fraud and abuse prevention, debugging).
4 · WHO RECEIVES IT
Data is shared only with processors and recipients needed to run the Service:
- Stripe (payment processing)
- Resend (transactional email delivery)
- PostHog Inc., USA (product analytics; no advertising use). Umami is self-hosted — no recipient.
- Google (only if you sign in with Google — we receive your verified email address)
- Hosting and data-center providers operating the console and the GPU Nodes
- Public authorities where disclosure is required by law, including export-control and sanctions authorities.
Some recipients are located outside the DIFC (including the EU, USA and Canada); transfers rely on appropriate safeguards under DIFC law.
5 · RETENTION
Account and billing records are kept for the life of the account and thereafter as long as required by accounting, tax and export-control rules (typically 6 years). Verification records are kept for the period required by applicable sanctions and KYC obligations. Server logs are kept for up to 12 months. Instance data on Nodes is destroyed on termination and is not retained by us.
6 · YOUR RIGHTS
Subject to DIFC law, you may request access to, correction or deletion of your personal data, object to or restrict certain processing, and receive a copy in portable form. Deletion is limited by the retention obligations above. Write to cloud@theai.com; we respond within the statutory period. You may also lodge a complaint with the DIFC Commissioner of Data Protection.
7 · SECURITY
Traffic to the console is encrypted (TLS). Sign-in links and API tokens are stored as cryptographic hashes only. Access to production systems is restricted and logged. No method of transmission or storage is completely secure; you must protect your own credentials and instance contents.
8 · CHANGES
We may update this Policy; material changes will be announced via the console or email. The date above reflects the latest revision.