Privacy Policy

Last updated: July 14, 2026

This Privacy Policy explains how Azul AI (“Azul AI,” “we,” “us,” or “our”) collects, uses, and protects your information when you use our platform for hosting and training AI models (the “Service”). Azul AI is currently offered as an invite-only beta. By using the Service, you agree to the practices described here.

1. Information We Collect

We collect the following categories of information:

  • Account information. Your name and email address, and a securely hashed version of your password. We do not store your password in plain text.
  • Content you provide. Datasets, documents, knowledge bases, prompts, model configurations, and other materials you upload or create to train, evaluate, or run models. This content may contain whatever information you choose to include, so please avoid uploading sensitive personal data you do not need.
  • Third-party credentials. If you choose to use AI-assisted features or connect an external account, you may provide API keys or access tokens (for example, an Anthropic API key or a Hugging Face token). These are encrypted at rest and used only to perform the actions you request. They are never returned to your browser after you save them.
  • Connected data sources. If you connect a source such as GitHub, S3, Dropbox, or Google Drive, we store the access credentials (encrypted) needed to import the specific data you select.
  • Payment information. If paid plans are enabled, payments are processed by our payment processor (Stripe). We do not receive or store full payment card numbers.
  • Usage and technical data. Log and diagnostic data such as your IP address, browser type, actions taken in the Service, training job status, and performance metrics, used to operate, secure, and improve the Service.

2. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the Service and your account.
  • Run the training, evaluation, hosting, and inference jobs you request.
  • Process transactions and manage subscriptions, where applicable.
  • Send you invitations, service notices, security alerts, and support messages.
  • Monitor for, prevent, and address security incidents, abuse, and technical problems.
  • Understand how the Service is used so we can improve it.
  • Comply with legal obligations and enforce our terms.

We do not use the private content you upload to train our own general-purpose models, and we do not sell your personal information.

3. AI Features and Your Own Provider Accounts

Certain features (such as AI-assisted dataset generation, model evaluation, and training guidance) run on your own connected provider account using the API key you supply. Similarly, if you choose to train on a cloud provider such as Hugging Face, that work runs under your account and is billed to you. When a feature relies on a third-party provider, the relevant content is sent to that provider and handled under their terms and privacy policy. You are responsible for reviewing those policies.

4. How We Share Information

We do not sell your personal information. We share it only in these limited circumstances:

  • Service providers (subprocessors). We rely on trusted vendors to run the Service, including Amazon Web Services (hosting, storage, and job queues), DigitalOcean (hosting and network), Stripe (payments), Anthropic (AI features), Hugging Face (model hosting and optional cloud training), and Google (analytics; see “Cookies and Local Storage” below). They may process data only to provide services to us.
  • Legal reasons. When required by law, legal process, or to protect the rights, safety, and security of Azul AI, our users, or the public.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • With your direction. When you connect a data source or otherwise instruct us to share your information.

5. Data Storage and Security

Your data is stored and processed on infrastructure located in the United States. We use technical and organizational measures to protect it, including encryption in transit (TLS), encryption at rest for stored provider credentials, and access controls. No method of transmission or storage is completely secure, and because the Service is in beta, you should not rely on it as your only copy of important data. Keep your own backups of critical datasets and models.

6. Data Retention

We retain your information for as long as your account is active or as needed to provide the Service. Some operational data has shorter lifetimes; for example, customer-visible training logs are retained for a limited period (by default, about two weeks) before being purged. When you delete content or your account, we delete or de-identify the associated data within a reasonable period, except where we must retain it to comply with the law, resolve disputes, or enforce our agreements. Residual copies may persist briefly in backups.

7. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can update your profile and delete your projects, datasets, models, and account from within the Service, or contact us to exercise these rights. We will not discriminate against you for exercising them. To make a request, email us at sblue@sanderblue.com.

8. Cookies and Local Storage

We use a small number of strictly necessary cookies and browser local storage to keep you signed in and remember basic preferences (such as light or dark theme). These are required for the Service to work and are always active.

We also use Google Analytics to understand how the Service is used so we can improve it. Google Analytics sets its own cookies and processes usage and device data (such as pages viewed and approximate location derived from your IP address) as our processor. Where local law requires consent (including the EEA, the United Kingdom, and Switzerland), analytics stays off until you accept it in our cookie banner; if you decline, it remains off. Elsewhere, analytics runs by default. We do not use advertising or cross-site tracking cookies. Wherever you are, you can opt out or change your choice at any time: . For more on how Google handles this data, see Google’s Privacy Policy.

9. Children's Privacy

The Service is not directed to children, and you must be at least 18 years old to use it. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

10. International Users

If you access the Service from outside the United States, you understand that your information will be transferred to, stored, and processed in the United States, where data-protection laws may differ from those in your country.

11. Changes to This Policy

We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, for material changes, provide additional notice where appropriate. Your continued use of the Service after an update means you accept the revised Policy.

12. Contact Us

If you have questions about this Policy or our privacy practices, contact us at sblue@sanderblue.com. See also our Terms of Service.