Conifer Solutions, Inc.
Privacy Policy
How Conifer Solutions, Inc. collects, uses, discloses, and retains personal data, and the choices available to you.
Conifer Solutions, Inc. · Effective 2026-08-13
This Privacy Policy explains how Conifer Solutions, Inc. ("Conifer", "we", "us") collects, uses, discloses, and retains personal data in connection with the Conifer command-line interface, the desktop application, the cloud routing gateway, the marketplace, and conifer.build (together, the "Service"). It applies to any person who uses the Service ("you").
Most of the processing described in this policy takes place on your own device. Where data is transmitted to us or to a third party, the section describing that system states so.
The short version
| Local inference | Prompts, responses, files, and execution remain on your device. Nothing is transmitted for a turn that runs locally. |
| Cloud inference | The serving endpoint selected for a turn receives that turn's prompt and context. We do not log it and do not retain a second copy. |
| Usage data | Categorical metadata only: which application areas were used, which model class ran, which error category occurred. On by default, with a single setting to disable it. It carries no text you write. |
| Prompt samples | A separate channel that transmits your prompt text. Off by default; it is enabled only by you. |
| Training | We do not use your content to train models, whether our own or a third party's. There is no opt-in because there is no such program. |
| Cookies | None, for analytics, advertising, or any other purpose. |
| Sale of data | We do not sell personal information and do not share it for cross-context behavioural advertising. |
Who we are
Conifer Solutions, Inc., a Delaware corporation, is the controller of the personal data described in this policy.
- Notice address: 2418 Rogers Isle
- Contact: contact@conifer.build
The same address receives all privacy questions, data-subject requests, and security reports. We respond within two business days.
Information we collect
We collect personal data through five systems. Those systems share no identifier with one another: the anonymous install identifier used by the desktop application cannot be linked to your account, and the website visitor hash cannot be linked to either.
2.1 Website analytics
When you visit conifer.build, we record the page path, referrer, traffic source and campaign, clicks and scroll depth, coarse country, and browser user agent.
To count visitors without identifying them, we store a daily-rotating hash: the
SHA-256 of your IP address, your user agent, the date, and a secret salt.
- Your raw IP address is not stored. It exists only in memory, as an input to that hash.
- The hash changes every day by construction and therefore cannot link your activity from one day to the next.
- Where your browser sends a Do Not Track or Global Privacy Control signal, we discard the hash and the country and retain only an anonymous page count.
We set no cookies and use no third-party analytics service.
2.2 Application usage data
The desktop application records categorical facts about how it runs: device class
(platform, memory, CPU threads, GPU vendor, application version, power class);
which application areas and tools you used; which model architecture and
quantization ran on which lane; coarse error categories; timing buckets; and a
conversation topic label classified on your device into one of thirteen
categories, such as coding, writing, health, or finance.
This channel is on by default. You may disable it in Settings → Privacy & data, after which the application collects and transmits nothing on this channel. On desktop, your choice is recorded per machine and survives a reinstalled browser profile.
Events are buffered on your device, transmitted only when you are online, and the local copy is deleted once transmission succeeds.
This channel carries no text. That restriction is enforced by the server rather than by convention: the intake accepts a fixed list of fields and constrains every string to a closed set of permitted values, discarding any value not on that list. Only release builds collect data at all.
The topic label records that a conversation fell within a category such as health or finance. It does not record anything you wrote.
2.3 Prompt and search samples
This is the only channel that transmits text you write off your device, and it is off by default.
Enabling it requires a setting separate from the usage-data setting described in §2.2. Once it is enabled, samples of your prompt and search text may be transmitted together with your usage data. A sample is captured only where all four of the following conditions hold:
- usage data is enabled;
- the prompt-sample setting is expressly enabled;
- the application is not in offline or Local-only mode; and
- the text does not match our sensitivity filter.
Condition 3 means that text is not stored at all while you are offline, so a Local-only session cannot be transmitted after you reconnect. Condition 4 causes a sample to be refused rather than redacted where the text refers to passwords, secrets, API or private keys, social security numbers, credit cards, or passports.
Before a sample is stored, we apply best-effort redaction to the remaining text, removing credential assignments, bearer tokens, recognisable API-key formats, email addresses, long digit sequences, and long opaque tokens. The same redaction is applied again on our servers.
That redaction is best-effort. Pattern matching cannot identify a secret or a personal detail expressed in ordinary prose, such as "my password is …", a name, an address, or a description of your health or finances. You should treat any text for which you enable this setting as text we may hold. If that is not acceptable, leave the setting disabled; it is disabled unless you change it.
Samples are truncated at 4,000 characters. Samples are readable by Conifer staff through an internal dashboard that displays recent samples in full, and we use them to understand what users ask for. Disabling the setting purges buffered samples that have outlived your consent.
2.4 Accounts, forms, and purchases
- Account. Your email address. Authentication uses emailed magic links, so we do not collect a password. Your session is held in your browser's local storage or, on desktop, in your operating system keyring, and not in a cookie.
- Forms. Feedback, waitlist, and letter-of-intent forms store your email address together with any name, company, and message you provide. A contact-form message is emailed to us and is not written to any database.
- Newsletter. You are added to the newsletter only where you expressly select that option; a waitlist signup alone does not subscribe you. Our email provider records opens and clicks. Every email contains an unsubscribe link.
- Purchases. Payment is handled by Stripe on Stripe's own pages. Card numbers do not reach Conifer. We receive a signed confirmation that a purchase completed, which grants you what you bought.
- Marketplace. Listings and media you publish are content you provide and are visible according to the listing's status.
2.5 Cloud inference
Where a turn runs on a cloud model, the prompt and the conversation context required to answer it are sent to the exact serving endpoint selected for that turn.
We do not log your prompts or the model's responses. We do not create a second copy for training, evaluation, reward modelling, or routing feedback; no such transmission occurs. We do not use your content to train any model.
We retain metering records — account identifier, request identifier, model, token counts, cost, and latency — so that we can bill correctly and so that you can cite a request identifier to us when reporting a problem. Signed-in clients also transmit per-turn metadata observations (where the turn ran, which model, token counts, latency). That transmission is on by default and your client can disable it.
After a request settles, the response body is held briefly in the gateway's working memory so that a retry of the same request returns the same result rather than incurring a second charge. It is held in RAM, never in a database, is discarded when the process restarts, and never includes your prompt, your credentials, or any secret.
Your own API keys (BYOK). Where you supply a provider key, we encrypt it using authenticated encryption under a master key, store only the ciphertext, and cryptographically bind each stored key to your account and to that provider, so that an attacker with database-level access cannot use your key under another account. It is decrypted only in memory at the moment of a call, and it is never displayed back to you except for its last four characters.
Provider terms. The provider that serves a turn handles that request under its own policy, including where you use your own key. We do not control its retention. Turns that run on local models are not subject to this.
Purposes and legal bases
For users in the EU, the UK, and other regions with equivalent law, our legal bases under the GDPR are as follows.
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the Service you requested | Account, inference requests, purchases | Contract (Art. 6(1)(b)) |
| Bill accurately and prevent abuse | Metering, request metadata | Contract and legitimate interests (Art. 6(1)(f)) |
| Keep the Service secure and operational | Error categories, diagnostics | Legitimate interests (Art. 6(1)(f)) |
| Understand aggregate product usage | Usage data (§2.2) | Legitimate interests (Art. 6(1)(f)); you may object at any time using the off switch |
| Understand what users ask for | Prompt samples (§2.3) | Consent (Art. 6(1)(a)); off unless you enable it, and withdrawable at any time |
| Send the newsletter | Email address | Consent (Art. 6(1)(a)) |
| Meet legal and tax obligations | Purchase records | Legal obligation (Art. 6(1)(c)) |
We do not carry out automated decision-making that produces legal or similarly significant effects concerning you.
How we share information
We share personal data only with the subprocessors listed on our subprocessors page, which identifies each one, the data it receives, and the reason. We update that page before adding a subprocessor.
Otherwise, we disclose personal data only:
- where you direct us to do so;
- to comply with a valid legal obligation; or
- in connection with a merger or acquisition, in which case this policy continues to apply until you are given notice of a replacement.
We have never sold personal information, and we do not share it for cross-context behavioural advertising. We use no advertising networks, no data brokers, and no session-replay tools.
Retention
| Data | Retention |
|---|---|
| Usage telemetry and prompt samples | 180 days, then deleted |
| Website analytics events | 24 months |
| Account records | For as long as your account is open, then 30 days |
| Purchase and billing records | 7 years (tax and accounting law) |
| Form submissions and contact emails | Until you ask us to delete them |
| Gateway response cache | Minutes, in memory only; cleared on restart |
You may ask us to delete data sooner, and we will do so unless the law requires us to retain it, as it generally does for billing records.
Your rights
All users. Wherever you live, you may ask us to access, correct, delete, or export your data, or to cease a particular use. Write to contact@conifer.build. We reply within 30 days and will not charge you or degrade your Service for making a request.
GDPR and UK GDPR. Where the GDPR or UK GDPR applies to you, you have the rights of access, rectification, erasure, restriction, portability, and objection, together with the right to withdraw consent at any time. Withdrawal does not affect processing already carried out. You may also lodge a complaint with your national data protection authority, although we ask that you raise the matter with us first.
California. The CCPA and CPRA give you the rights to know, to delete, to correct, and to opt out of the sale or sharing of personal information, and the right not to be discriminated against for exercising them. We do not sell or share personal information, so there is no opt-out to exercise; the Global Privacy Control signal is honoured on our website in any event. In the preceding 12 months we collected the categories described in §2 and disclosed them only to the subprocessors identified in §4.
Other US states. Virginia, Colorado, Connecticut, Utah, Texas, and other states provide substantially the same rights. We extend the same process to all users.
Many requests can be completed without contacting us: usage data and prompt samples can be disabled in Settings → Privacy & data, and data held locally can be deleted on your device directly.
Security
- Encryption in transit is used throughout. Plaintext HTTP is refused for any endpoint carrying credentials.
- Provider keys are envelope-encrypted at rest, bound to your account, and never displayed back to you.
- Row-level security applies to every database table, deny-by-default for public keys. Administrative reads require a separate server-side credential that is never shipped to a browser.
- Payment card data does not reach our systems; Stripe collects it directly.
- The telemetry intake operates on an allowlist rather than a blocklist, so a compromised client cannot introduce unexpected data into our store.
- We do not collect passwords, because the Service does not use them.
No system is perfectly secure and we do not represent that ours is. If you identify a vulnerability, write to contact@conifer.build and we will work with you.
International transfers
Conifer is established in the United States and our providers are US-based, so data you send to us is processed in the United States. If you are in the EU, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, together with the UK Addendum, for those transfers, alongside the technical measures described in §7.
A turn that runs on your device does not cross a border at all.
Children
The Service is not intended for children under 13, and we do not knowingly collect personal data from them. If you are between 13 and 18, you may use the Service only with the involvement of a parent or guardian.
If you believe that a child under 13 has provided us with personal data, write to contact@conifer.build and we will delete it promptly.
Cookies and local storage
We set no cookies. We use no analytics cookies, no advertising cookies, and no third-party tags.
We do use your browser's local storage, on your own device, for functions the Service requires: your sign-in session, your theme, your settings, and the on-device telemetry buffer. That data remains on your machine and is not a tracking mechanism. Clearing your browser storage clears it.
Changes to this policy
Where we change this policy, we update the version date at the top of this page and publish the new version at this address. For a change that materially reduces your privacy protections, we will give at least 30 days' notice before it takes effect, by email where we hold your address and in the application, so that you may object, export your data, or stop using the Service beforehand.
We will not apply a materially different use to data already collected without first asking you.
Contact
Questions, requests, and complaints: contact@conifer.build
Conifer Solutions, Inc. · 2418 Rogers Isle
Version history: 2026-08-13 — first complete policy; replaces the 2026-08-04 summary. Adds legal bases, retention, rights, subprocessors, transfers, children's privacy, and full disclosure of the prompt-sample channel and the gateway response cache.