PRIVACY

What we do with your data.

The question you send passes through us and is not written down. The conversation you have with Clint is kept, scrubbed and short-lived. We keep the bookkeeping and your account. We never train anything on your words. Some of the services that answer do keep them, and we publish exactly who.

Version 1.2 In effect September 12, 2026 Operator Scaled Minds

How to read this

Drafted by the engineering team so that every factual statement traces to running code. Not reviewed by a qualified data-protection lawyer. Last checked September 13, 2026. Where we cannot yet make a commitment, the document says so, dates it, and names what would close it. We would rather you found the gap here than found it yourself.

What would change that: A review is commissioned when the first controller who is not us signs the processing agreement, or at the first paid business customer — whichever comes first. It is deferred rather than skipped: today there is no customer to make these statements to.

What changed in this version: The old notice said flatly that we do not store what you write. That was true of the question we pass to a model and untrue of the conversation you have with Clint, which is kept, redacted and bounded. One sentence cannot cover both paths, so section 2 now names each store separately and section 3 gives each one its own clock.

A printed copy carries this version and its date, and leaves the navigation behind.

1. Who we are

Host.Rodeo is an AI gateway operated by Scaled Minds. You can reach a real person at [email protected]. We are the controller for your account, and a processor for anything you send through the service on behalf of your own users.

2. What we hold, one store at a time

A single sentence about "your data" cannot be true of six different things, so here is each one.

  • The request you send for inference. Passed to whichever service answers it and gone from us when the answer comes back. It is not written to our disks on the way through.
  • Your conversation with Clint. Kept, so that moving between pages does not restart the thread. Each turn is scrubbed of anything shaped like an email address, a key or a card number before it is written, both the turn and the thread are bounded in size, and the whole thread ages out on its own. A conversation you have not returned to is not a conversation.
  • Anything you tell Clint while setting up — where you are, what you are trying to do. Kept short, scrubbed the same way, and used to answer you rather than to profile you.
  • Files and artifacts you upload or that Clint produces for you, for as long as you keep them. Deleting one deletes it.
  • The bookkeeping. For each request: which services were considered, which one answered, whether it worked, how long it took, what it cost. Tied to an account number, not to your email address.
  • Your account: email address, a scrambled password that cannot be turned back, your role, and your sign-in sessions. Your API keys are kept only as one-way scrambles, never the key itself.
  • Your machines, if you connect any: what hardware they have, what they can run, whether they are healthy. Never what is on their disks.
  • Feedback you send us, scrubbed the same way.

A scrub reduces what is exposed. It does not make what is left non-personal, and we do not describe it as anonymous. An account number is a pseudonym, not anonymity, and text you wrote can identify someone even when no name is attached to it.

3. How long each one lasts

WhatHow long
The request you send for inference, and the answer that comes back
A negative claim, so there is no constant to bind it to. It is held by there being no writer: the request body is never handed to a store on the way through.
Not written down at all. It passes through and is gone when the answer is.
Your conversation with Clint, signed in
Scrubbed before it is written, bounded per turn and per thread, and dropped on the next read or write after it expires — an idle thread ages out with nothing having to sweep it.
7 days after you last add to it
A visitor's thread, before there is an account
Filed under a one-way digest of a handle that lives only in your own browser. We hold no name for it, and signing up claims it into your new account exactly once.
24 hours
What you told Clint while setting something up7 days
The notes Clint keeps so a follow-up makes sense
Tell Clint something while you are setting up — keep this one private, bill it to the ranch — and he writes a short note so the next thing you say still makes sense. Every time he reads or writes one, anything older than this goes; a note is dropped for you even if you never come back.
30 days
Files and artifacts you uploaded or Clint produced
Backup copies expire on their own 7-day clock, and the record that an artifact existed at all is kept 15 days so a deletion can be proved rather than assumed.
7 days
The record of a task Clint ran for you7 days
Your sign-in7 days, then you sign in again
Notices waiting for you in your own ranch30 days
The detailed record of how one piece of work was handled
Which places were tried for you, which one answered, what each attempt took and what it cost. Never what you wrote and never what came back — neither is written here at all, and a test asserts it. Filed under an account number rather than your email address. It is how we can tell you what actually happened when something goes wrong.
14 days
The bookkeeping behind your Trail and your receipts
Which services were considered, which answered, whether it worked, how long it took and what it cost — filed under an account number rather than your email address.
365 days
Your account, your keys, and the machines you connected
Closing the account revokes every key immediately and removes the account record.
Until you remove them or close the account

"Ages out" here means it stops being returned AND is dropped from the store — both are enforced when the row is next read or written, so an idle thread expires without anything having to sweep it. Backups are a separate clock and we do not claim an instant physical erasure everywhere; if you need the exact position for your own record, ask and we will tell you what is true on the day.

4. Who else sees it

To answer your question we have to send it to something that can answer it. That is the whole service and it is the part worth understanding. The complete current list of every company involved is generated from the running system rather than from a document somebody remembers to update.

For each one we say where it is based, whether it keeps what you sent, and whether it learns from it. Where a company has not published a clear answer we say not known, rather than guessing in our own favour.

Two things from that page deserve saying here as well. Some free services do learn from what you send them, and say so in their own terms. And some of the services are themselves middlemen who choose another company per request without telling us which — for those we genuinely cannot name the final destination in advance, and saying so is the only true answer available.

The live list

5. How to make sure nobody else sees it

Mark the work private. Private work only ever runs on machines you own. If none of yours can take it we refuse the request and tell you — we never quietly send it somewhere else. Every answer comes back with a signed receipt naming who handled it, and you can check that signature yourself without trusting us. It is the one guarantee in this document that is a mechanism rather than a promise.

6. Training

We never train, tune or test any model on your data. Nor do we let your words judge how good a model is — that comes only from our own frozen test set, so one person's activity cannot shape another person's answers. We do notice when a service breaks and route around it, but that is read from the service's behaviour, never from what you wrote.

What we cannot promise for you is what a third-party service does once your words reach it. That is why section 4 exists, and why private routing exists.

7. Where your data goes

Our own servers are in the United States. The services that answer questions are mostly in the United States, with some elsewhere, and a few whose location we cannot establish. Most do not publish where the computer running the model physically sits, so we report that as not known instead of inventing an answer. The live list shows the current position for each one.

If you are in the UK or the EU, using this service means your data leaves the UK and the EEA. For businesses, the transfer terms are in the processing agreement. If you need a guaranteed location, use private routing on a machine in the location you want — it is the only mechanism that actually guarantees it.

8. Why we are allowed to do this

  • To give you the service you asked for: running your requests, keeping your account, keeping your conversation, showing your receipts.
  • Because we have to: keeping enough of a record to bill honestly and to answer a regulator.
  • Because it is in our legitimate interest, balanced against yours: keeping the service secure, stopping abuse, and knowing when something is broken.

We do not run advertising, we do not profile you, we do not sell or share your data, and nothing here makes an automated decision with a legal effect on you.

9. Your rights

You can ask us for a copy of what we hold, to correct it, to delete it, to limit what we do with it, or to object. If you are signed in you do not have to ask at all: your account page hands you the whole file, now, with a list of every place we looked. There is no charge and you do not need a working account — these rights outlive the account, which is why the contact page needs no sign-in.

Closing your account removes the account record, revokes every key, and deletes your settings and usage totals. The bookkeeping ages out on the schedule above; ask and we will remove it sooner. We will not delete a record we are legally required to keep — an unresolved payment obligation, for instance — and if that applies to you the deletion receipt says which record, why, and when it goes.

If you are unhappy with how we have handled your data you can complain to your data-protection regulator — in the UK, the Information Commissioner's Office.

Make a request

10. Security

Passwords are stored scrambled with a slow, deliberately expensive algorithm. Keys are stored as one-way scrambles. Sign-ins expire. Secrets live in a sealed vault rather than in the code. Everything travels over encrypted connections, and the administrative parts of the service are not reachable from the public internet at all.

The full list, including what we have not done, is in Annex II of the processing agreement. We would rather you saw the gaps from us than found them yourself.

11. Children

Host.Rodeo is not for under-16s and we do not knowingly hold data about them.

12. Clint is an AI

Clint is a machine, not a person, and every surface he speaks on says so. He can be wrong. He acts only inside boundaries you set, he never commits money without your explicit yes, and anything consequential is shown to you exactly as it will be done before it is done. When he produces an image, audio or video, whatever mark the tool put in the file to say a machine made it stays there — we do not strip it.

13. Changes

A new version is posted here with a new number and date, and the previous version stays listed. We tell account holders by email when a change matters. Changes to the list of companies that can receive your data get 30 days' notice.

Earlier versions

Every version this document has had. The one above is what you are reading now.

  • Version 1.2 took effect September 12, 2026— current
  • Version 1.1 took effect August 21, 2026

We do not publish the superseded text, because a stack of old contracts on a public page is a way to be read out of context. The version you accepted stays retrievable: ask us naming the version and we will send you that exact text.

The rest of the shelf

Questions about any of this reach a real person at the contact page, with or without an account — [email protected] for anything about your own data, [email protected] for a security report. We answer within 10 working days.