About this policy
This Privacy Policy explains how Spice Finance Inc, a Delaware corporation doing business as Pareto Inference ("Pareto Inference," "we," "us," or "our"), collects, uses, discloses, and protects personal information when you visit paretoinference.com, create or use an account, use our dashboard or documentation, submit requests to our application programming interface (the "API"), participate in our referral program, or otherwise use our services (collectively, the "Service").
This Policy does not govern third-party products, websites, or services that we do not control, even if they link to or integrate with the Service.
Information we collect
We may collect information you provide, including:
- Account and contact information, such as your name, email address, account identifier, and sign-in information.
- Billing information, such as subscription status, transaction amounts, invoices, discounts, refunds, disputes, payment status, and payment-processor identifiers. Stripe processes payment-card details; we do not store full card numbers.
- Prompts, messages, tool definitions, model settings, files, and other content in validated API request bodies ("API Content"). The Service is not a no-storage service. Our request-capture system does not capture model responses or model reasoning.
- Support requests, feedback, and other communications you send us.
- Referral codes, attribution, reward status, and credit history. User-facing reward history does not display another user's account details.
We and our providers may also collect information automatically, including:
- IP address, browser and device type, operating system, language, and approximate location derived from IP address.
- Pages viewed, actions taken, timestamps, request and error logs, API-key activity, selected model, token and usage measurements, latency, availability, and performance data.
- Cookie and similar-technology information used for authentication, security, preferences, billing, analytics, and referral attribution. A referral visit may set a secure, HTTP-only cookie lasting up to 30 days.
We may receive information from identity providers, including Clerk and Google; Stripe; people who refer you; and analytics, infrastructure, model-routing, model-provider, security, and marketplace partners involved in providing the Service.
How we use information
We may use personal information to:
- Provide, operate, maintain, secure, troubleshoot, and improve the Service.
- Authenticate users and manage accounts, subscriptions, and API keys.
- Process payments, credits, refunds, disputes, and customer support.
- Route API requests to upstream model providers and return model outputs.
- Monitor usage, enforce budgets and technical limits, and calculate service-level performance statistics.
- Attribute referrals, prevent self-referrals and fraud, and maintain reward records.
- Detect and investigate abuse, security incidents, and violations of our Terms of Service.
- Send administrative, security, billing, support, and policy notices.
- Comply with law, enforce agreements, and protect the rights, safety, and property of users, Spice Finance, and others.
We may aggregate or de-identify information so it no longer reasonably identifies you and use it for lawful purposes, including service analytics and research. We will not attempt to re-identify de-identified information except to test our safeguards.
API Content and AI providers
API Content may contain personal, confidential, or sensitive information. Do not submit API Content unless you have the rights and permissions necessary to do so.
To provide inference, we may transmit API Content and related technical information to routing, model, and infrastructure providers. Our current routing may involve OpenRouter and downstream providers selected for the requested model. A marketplace or integration partner may also process requests made through that partner.
We use API Content to provide, secure, monitor, troubleshoot, and improve the Service and product experience. We do not use API Content to train or evaluate AI models.Upstream providers process API Content under their own terms, notices, and technical configurations. Do not submit regulated or sensitive information requiring particular data-location, retention, no-training, or confidentiality commitments from every provider unless we have agreed to those commitments in writing.
How we disclose information
We may disclose personal information to:
- Providers that support authentication, hosting, databases, storage, analytics, security, communications, payments, model routing, and inference. These may include Clerk, Google, Stripe, Vercel, Hetzner, Cloudflare, Mixpanel, OpenRouter, and downstream model providers.
- Marketplace and integration partners when you use an integration or disclosure is needed to operate it, complete a transaction, or prevent abuse.
- Professional advisers subject to appropriate confidentiality obligations.
- Authorities or others when reasonably necessary to comply with law, enforce our agreements, address fraud or security issues, or protect rights, property, and safety.
- Parties to a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law.
- Other parties at your direction or with your consent.
We do not sell personal information for money, and we do not use personal information for cross-context behavioral advertising. We use analytics providers to understand use of the Service.
Our use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Cookies and analytics
We and our providers use cookies and similar technologies for authentication, session management, security, billing, referral attribution, and product and website analytics, including Mixpanel and Vercel Analytics.
In production, analytics may receive page paths, button and link actions, IP addresses, and, after sign-in, your account identifier. Session recording may capture page text and non-sensitive input values; fields the analytics software identifies as sensitive are masked.
You can control many cookies through your browser settings. Blocking necessary cookies may prevent sign-in, billing, referral attribution, or other features from working.
Data retention
We retain personal information for as long as reasonably necessary for the purposes in this Policy, including while your account is active, and as needed to comply with law, resolve disputes, prevent abuse, maintain security, and enforce agreements. Retention periods vary by data type and may reflect backup and disaster-recovery cycles.
API request bodies may be stored in private object storage, with a bounded local spool used to buffer uploads. Successfully uploaded batches are removed from the local spool. In the ordinary course, we retain captured API Content for up to 14 days. We may retain particular records longer where reasonably necessary to investigate abuse or a security incident, comply with law, resolve a dispute, enforce our agreements, or at your request. Deletion from backups may occur on a delayed cycle.
The request-capture system is designed to exclude API keys, request headers, cookies, raw IP addresses, the OpenAI user field, request metadata, model responses and reasoning, and raw errors. Other systems and providers may separately process limited network, account, error, or usage information as described in this Policy.
We may retain billing, transaction, referral-ledger, fraud-prevention, and legal records after account deletion when required or permitted by law. We may retain aggregated or de-identified information that cannot reasonably identify you.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, transport encryption, private storage, signed payment-event validation, and monitoring. No system is completely secure, and we cannot guarantee that information will never be accessed, used, or disclosed without authorization.
You are responsible for keeping API keys and account credentials confidential. If you believe either has been compromised, rotate the key where available and contact us.
International transfers
We and our providers may process information in the United States and other countries, which may have different data-protection laws than your country. Where required, we use an approved transfer mechanism or other safeguard for international transfers.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information; request portability; object to or restrict processing; withdraw consent; opt out of certain sales, sharing, targeted advertising, or profiling; appeal a decision; or complain to a data-protection authority.
You may manage some account and billing information through the dashboard and Stripe billing portal. To make a request, email admin@paretoinference.com from the address associated with your account. We may verify your identity and authority. We will not discriminate against you for exercising a privacy right.
If we process information on behalf of a business customer, direct your request to that customer first. We may assist the customer as required by our agreement and law.
Legal bases
Where law requires a legal basis, we rely on contract when processing is necessary to provide the Service; legitimate interests such as securing, analyzing, and improving the Service; legal obligations; or consent where we ask for and receive it. You may withdraw consent without affecting processing already completed.
Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13, or under a higher minimum age required by local law. If you are under the age of legal majority where you live, you may use the Service only with the permission and supervision of a parent or legal guardian. Contact us if you believe a child has provided information without the required permission.
Changes and contact
We may update this Policy. We will post the updated version and revise its effective date. If changes are material, we will provide additional notice as required by law.
Questions and privacy requests may be sent to admin@paretoinference.com.
Spice Finance Inc
4 Sycamore Ave
Berkeley Heights, New Jersey 07922
United States