Legal
Privacy Policy
What we collect, what we do with it, and what we never do with your prompts.
Effective 9 October 2026.
1. Who we are
MarsCompute Inc. (“MarsCompute”, “we”)
operates this website, the console at
console.marscompute.ai and the API at
api.marscompute.ai. This policy covers all three.
The service is for organisations and the people who work for them. It is not meant for anyone under 18.
If you send personal data about other people through the API, you decide why it is processed. We process it only to return the response you asked for.
2. Your prompts and outputs
- We do not train on them. Prompts and outputs are never used to train or improve any model.
- We do not store them. A request is held in memory while the model produces its response. Neither the prompt nor the output is written to our database or our logs.
- We do not read them. Because nothing is stored, there is no content for anyone at MarsCompute to review.
- We do not sell them or use them for advertising.
Every model we offer runs on GPU servers that MarsCompute operates. Your prompts and outputs are not sent to any other company’s model API.
If that ever changes for a model, we will say so on this page before it does.
For each request we keep a record without its content, described in the next section.
3. What we collect
| Kind | What it is |
|---|---|
| Account | Your name, work email, organisation, and the use case you describe when you request access. For members you invite, their name and email. |
| Sign-in | We email you a one-time code. There are no passwords. The console keeps your session in your browser’s storage. |
| Billing | Legal name, billing address and country. Card details are entered in a form hosted by Stripe and never reach us. We keep Stripe’s reference to your payment method, your invoices and their payment status. |
| Usage records | For each API request: the time, the model, the account and key that made it, token counts, cost, outcome, a request identifier, and a one-way fingerprint of the request that lets us detect an accidental repeat. The fingerprint cannot be turned back into the request. |
| API keys | A keyed hash of each key, plus its first and last characters so that you can recognise it. We cannot recover a key. |
| Technical logs | Our servers and our network provider record the IP address, time and address of each request to the console and the API, for security and troubleshooting. These logs do not contain request bodies. |
| This website | It sets no cookies of its own and has no advertising trackers. We may use cookie-free traffic statistics from Cloudflare. |
Forms for requesting access and signing in include a Cloudflare Turnstile check, which tells people from automated traffic.
4. How we use it
- To run the service: sign you in, route your requests, and show you your usage.
- To meter and bill your usage, and to apply your spending limit.
- To enforce rate limits and stop abuse.
- To answer you when you contact us.
- To meet legal, accounting and tax obligations.
We do not use personal data for advertising, and we do not sell it.
5. Who processes it for us
| Provider | What it does for us | Data involved |
|---|---|---|
| Cloudflare | Network, API gateway, bot check, storage of usage export files | Requests in transit, technical logs, export files |
| Supabase | Database and sign-in | Account details, billing profile, usage records |
| Stripe | Payments, invoices, tax calculation | Billing details, payment method |
| Resend | Sends sign-in emails | Email address, sign-in code |
| GPU infrastructure providers | Host the servers that run our models | Prompts and outputs, in memory during a request |
We may also disclose information when the law requires it, or to a successor if the business is merged or sold, on terms that honour this policy.
6. Where it is processed
- Our database is hosted in Japan.
- Cloudflare handles requests in data centres around the world, close to where each request starts.
- The GPU servers that run our models are rented, and their location can change. Ask us for the current one.
- Stripe and Resend process data in the United States and other countries.
Your data may therefore be processed outside the country you are in.
7. How long we keep it
| Data | Kept for |
|---|---|
| Prompts and outputs | Not kept. |
| Account details | Until you ask us to close the account. |
| Usage and billing records | As long as accounting and tax rules require. |
| Usage export files | Available for download for 24 hours. |
| Technical logs | A short period, measured in days. |
8. Your choices
- You can ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it.
- A workspace administrator can remove a member at any time in the console.
- Records we must keep for accounting and tax reasons cannot be deleted on request.
Write to [email protected]. We answer within 30 days. You may also complain to the data protection authority where you live.
9. Security
- Traffic to the website, the console and the API is encrypted in transit.
- API keys are stored only as hashes.
- Each part of the service reaches the database with its own credentials and only the access its job needs.
- Payment details are handled by Stripe, not by us.
No system is perfectly secure. If you think a key has leaked, revoke it in the console at once and tell us.
10. Changes to this policy
When we change this policy we change the date at the top. Before a change that affects how we handle your data takes effect, we tell account holders by email.
11. Contact
MarsCompute Inc.
[email protected]