Legal

Privacy,
without vague promises.

This policy explains what MaxLabs receives, why we process it, when people may access it, and how our global model infrastructure works.

Effective 8 October 2026 · Last updated 8 October 2026

Server Host Inc. ("MaxLabs", "we", "us", or "our") provides AI models and developer tools. This Privacy Policy applies to all MaxLabs products and services, including our websites, desktop and command-line harnesses, subscriptions, enterprise services, support channels, and application programming interfaces (the "Services").

1. Information we collect

The information we collect depends on how you use the Services. It may include:

  • Account and contact information, such as your name, email address, organisation, authentication details, and account preferences.
  • Billing information, such as your plan, invoices, transaction status, and payment-related records. Payment card details may be collected directly by our payment providers rather than by MaxLabs.
  • Customer Content, including prompts, model responses, conversations, uploaded files, code or repository context, configuration, terminal or tool output, diffs, and content sent through the API.
  • Usage and technical information, including model and feature usage, token counts, cache activity, request timing, approximate location derived from an IP address, device and browser information, diagnostics, and security or anti-fraud signals.
  • Communications, including support requests, feedback, survey responses, and other messages you send to us.
  • Login data and necessary cookies, used to authenticate you, keep your session active, remember essential preferences, and protect the Services.

2. What leaves your device

The MaxLabs harness performs tool actions—such as reading files, editing code, and running commands—on your device or in your chosen environment. To generate a response, it sends your prompt and the context selected for that request to our model infrastructure. The harness is designed not to read unrelated files arbitrarily, but it may transmit any content required by your instruction or task.

This means source code, configuration, environment files, credentials, secrets, or terminal output can be transmitted if you ask the harness to read them or if they are included in the context needed to complete a task. Review your workspace, permissions, instructions, and selected context before submitting a request. Request content may remain temporarily in operational caches until those caches expire.

3. How we use information

We use information to:

  • provide model responses and operate the Services;
  • authenticate users, manage subscriptions, process payments, and administer accounts;
  • measure usage, allocate quota, maintain caches, and route requests;
  • diagnose failures, investigate anomalies, improve reliability, and develop service features;
  • detect abuse, fraud, and security threats and enforce our agreements;
  • respond to support requests and service communications; and
  • meet legal, tax, accounting, and regulatory obligations.

4. Model processing and service improvement

Automated systems parse prompts and context so that our models can respond. We do not routinely retain every prompt or use Customer Content to train foundation models. In limited cases, we may retain prompts or relevant excerpts to investigate an error, failure, suspected abuse, or unusual usage pattern, and to improve the safety, quality, and reliability of the Services. Most request content is not kept as a permanent log and is pruned after the applicable operational period.

Service improvement and model training are not the same activity. If we propose using identifiable Customer Content for model training, we will request separate permission where required. Feedback you deliberately submit may be used to improve the Services. Where processing relies on consent, you may withdraw that consent, although withdrawal does not affect processing already completed lawfully.

5. GPU providers and zero data retention

We use external GPU and infrastructure partners to run our models. Those providers receive the prompts and context needed to process a request. We select providers carefully and require zero data retention (ZDR) arrangements for model inference, so providers are not permitted to retain request content after processing under the applicable arrangement. ZDR at a provider does not prevent the temporary caching or limited anomaly retention described in this policy by MaxLabs.

6. Human access

Authorised personnel may access limited Customer Content only when reasonably necessary—for example, to investigate a failure, resolve a support request, address abuse, or meet a legal obligation. We do not usually maintain complete prompt logs. Access is restricted, audit logged, and subject to reasonable security controls.

7. When we share information

We do not sell personal information and do not share it for third-party behavioural advertising. We may share information with:

  • GPU and model infrastructure providers, which receive prompts and context to process requests under ZDR arrangements;
  • payment gateways and billing providers, which process payments and help manage subscriptions;
  • hosting, network, monitoring, support, and anti-fraud providers, where needed to operate and protect the Services;
  • GPU partner networks, which may receive aggregated or de-identified prompt-derived information for service improvement;
  • professional advisers, authorities, or other parties, when reasonably necessary to comply with law, protect rights and safety, or establish or defend legal claims; and
  • a successor in a corporate transaction, such as a financing, merger, reorganisation, or sale, subject to appropriate confidentiality protections.

8. International processing and regional packages

By default, requests may be securely transmitted to and processed in different countries or continents based on GPU availability, performance, and reliability. Data protection rules in those locations may differ from those where you live.

EU-only and US-only processing packages are available for eligible customers and must be explicitly selected. Unless a regional package is included in your agreement and enabled for your account, you should not assume that a request will remain in a particular country or region.

9. Retention

We retain information only for as long as reasonably necessary for the purposes described in this policy, including to provide the Services, keep accounts secure, investigate anomalies, comply with law, resolve disputes, and enforce agreements. The period depends on the type of information, why it was collected, its sensitivity, and applicable legal requirements.

Most prompt content is not stored as a permanent log. Content retained for caching remains until cache expiry, while limited anomaly or failure records are pruned when they are no longer needed. Account, billing, security, backup, and legal records may be kept longer. Deletion from active systems may not immediately remove information from protected backups or records we must retain by law.

10. Enterprise accounts

An enterprise customer owns and controls the Customer Content submitted through its organisation, subject to its agreement with MaxLabs. Organisation administrators may add or remove sub-users, allocate quotas, approve usage above a subscription, and access account or usage information. Your organisation may have its own rules governing your account and may be able to access or manage data associated with it.

Where MaxLabs processes personal information on behalf of an enterprise customer, the customer is responsible for its instructions and notices to users, and additional enterprise or data-processing terms may apply.

11. API customers

Customers that build applications, chatbots, or other products with the MaxLabs API decide what end-user data they send to us. They are responsible for providing appropriate privacy notices, obtaining any required permissions, securing their systems and API credentials, limiting the data they submit, and using the Services lawfully. This policy does not replace an API customer's own privacy policy.

12. Your privacy choices and rights

Depending on where you live, you may have the right to ask for access to, correction of, export of, or deletion of your personal information; to object to or restrict certain processing; to withdraw consent; and to receive portable data or complain to a privacy regulator. These rights may be limited by law.

Send a request to support@cenmax.in. We may verify your identity or authority before acting on a request. We will respond within the period required by applicable law.

13. Cookies

We do not use marketing or behavioural advertising cookies. We use login data and cookies or similar storage that are necessary to authenticate users, maintain sessions, remember essential settings, balance traffic, and prevent fraud. Blocking necessary cookies may prevent parts of the Services from working.

14. Security

We use reasonable administrative, technical, and organisational safeguards, including encryption in transit and at rest, access restrictions, and access auditing where applicable. No method of transmission or storage is completely secure. Our safeguards are a best effort and we cannot guarantee absolute security. You are responsible for protecting your credentials, devices, repositories, and API keys and for reporting suspected compromise promptly.

15. Age requirement

The Services are not intended for anyone under 19 years old. We do not knowingly collect personal information from anyone under 19. If you believe a person under 19 has provided personal information, contact us so we can review and, where appropriate, delete it.

16. Changes to this policy

We may update this Privacy Policy as our Services or legal obligations change. We will post the revised policy with a new "Last updated" date and may notify account holders by email. An update may take effect without advance notice unless applicable law requires notice in advance.

17. Contact us

For privacy questions, requests, or complaints, contact:

Server Host Inc.
1309 Coffeen Ave.
Sheridan, WY 82801
United States
support@cenmax.in