1. Scope
This policy explains how OpSpot collects, uses, and shares information when you visit gyld.dev, create a Gyld account, use the hosted API, buy a plan or credits, or choose to contribute data to model training.
2. Information we collect
- Account information: business name, email address, password hash, memberships, and account settings.
- Billing information: Stripe customer, subscription, price, invoice, and payment-status identifiers. Stripe processes card details; Gyld does not receive full card numbers.
- API information: API-key identifiers and status, model or niche used, token counts, timestamps, rate-limit state, and billing allowance.
- Service content: prompts and conversation context are processed transiently by our model-serving infrastructure to return a response. We do not intentionally write prompt or completion text to Gyld’s hosted-API usage ledger.
- Optional training data: content sent through the separate consented-ingest flow, consent records, scrubbed examples, provenance, and deletion requests.
- Technical information: our hosting and security providers may receive IP address, browser or device details, request timestamps, and server logs needed to deliver and protect the service.
3. How we use information
We use information to:
- create accounts, authenticate users, serve model requests, meter usage, and provide billing;
- secure Gyld, prevent abuse, debug failures, and enforce plan and rate limits;
- respond to support, deletion, and legal requests; and
- improve models only when the organization has made the separate affirmative training choice required by the consent flow.
Hosted API use by itself does not opt you into training. Turning on private or shared training is a separate action, and the DPA acceptance control remains unavailable until its full agreement is posted.
4. When we share information
We share information only as needed with service providers that operate Gyld, including Stripe for payments, Vercel for web hosting, Supabase for database hosting, Modal for model inference, and PostHog for product analytics. We may also disclose information when required by law, to protect rights or safety, or in connection with a business transfer subject to appropriate protections.
We do not sell personal information or share it for cross-context behavioral advertising.
5. Cookies
Gyld uses a strictly necessary fw_session cookie to keep you signed in. Stripe may use its own cookies when you open Stripe Checkout or the billing portal. PostHog sets its own analytics cookies and/or local storage for product analytics. Gyld does not currently use advertising cookies.
6. Retention and security
We keep account, billing, usage, consent, and security records for as long as reasonably needed to provide Gyld, meet legal and accounting obligations, resolve disputes, and prevent abuse. Sign-in sessions expire after 30 days. Raw content submitted through the optional training-ingest flow is held only until the scrub process classifies, redacts, quarantines, or deletes it. We use technical and organizational safeguards designed for the information we handle, but no system is completely secure.
7. Your choices and rights
You can manage training consent, request deletion of contributed training data, revoke API keys, and delete your account from the account and consent pages. Depending on where you live, you may also have rights to access, correct, delete, or receive a copy of personal information, or to appeal a request decision. Email us to exercise a right. We may need to verify your identity and authority for the organization.
8. International use and children
Gyld and its providers operate primarily in the United States, so information may be processed there. Gyld is a business service for adults and is not directed to children under 18.
9. Updates
We may update this policy as Gyld changes. The effective date above shows the latest version. We will provide additional notice when a material change requires it.