Privacy Policy
Last updated: July 7, 2026
This policy explains what Zorost Intelligence (“we”) collects when you use AlchemyLake, why, and the choices you have.
1. What we collect
- Account data — email address and authentication identifiers, managed by our sign-in provider. We never see your password.
- Usage data — generations you run (prompt, lane, model, credits, timestamps), credit ledger entries, API-key metadata, schedules, and admin actions (audit log).
- Bound data — governed sources you upload (CSV/Excel) or connect (Unity Catalog, Genie). What you choose to connect or upload is your decision; we store it only to serve the generations and schedules you request, and a SHA-256 fingerprint of bound rows is kept in provenance seals.
- Payment data — handled by our payment processor. We store only the checkout reference needed to credit your wallet, never card numbers.
- Diagnostics — server logs and error reports, with personal data minimized.
2. What we do with it
- Operate the Service: run generations, meter credits, deliver schedules.
- Provide provenance: seals, verification records, and audit trails.
- Protect the Service: safety moderation, rate limits, abuse prevention.
- Communicate: transactional email (receipts, scheduled deliverables).
We do not sell personal data and we do not use your prompts, sources, or outputs to train models.
3. Where data goes (processors)
Prompts are sent to model providers to produce your generation: general-purpose language models for text (or your own Databricks workspace, when you enable the workspace text tier — in that case your prompt and data stay in your workspace for the text step), and specialized media models for images, video, music, and voice. The underlying backend architecture is supported by a small set of infrastructure and processing vendors — covering compute and database hosting, artifact storage, authentication, payment processing, scheduled-delivery email, and error monitoring. Each processor receives only the minimum data needed to perform its function, and we do not publish the specific vendors we use, as our backend architecture is part of how we operate the Service. We select, and may change, these processors at our sole discretion, and require each of them to protect data under terms consistent with this policy.
4. Your data-sharing decisions
Connecting a Databricks workspace, selecting Unity Catalog tables, binding a Genie space, uploading a file, or sharing a deliverable with anyone else are actions you take, at your own discretion. We do not decide what you connect, what you upload, or who you share an output with, and we do not monitor those choices for appropriateness beyond the safety and acceptable-use screening described elsewhere in these policies. You are solely responsible for having the right to process any data you bind or upload, for the consequences of connecting any external account or workspace to the Service, and for anything you choose to share, forward, or publish — including deliverables that embed your bound data. We are not responsible for the outcome of decisions you make about what to connect, upload, or share.
5. Retention
- Generations and artifacts: kept until you delete them or your account.
- Uploaded sources: kept until you delete them (Studio → source → del).
- Credit ledger and audit log: kept for bookkeeping and integrity.
- Logs and diagnostics: rotated on short cycles.
6. Your rights
Depending on where you live (GDPR, CCPA, and similar), you may request access, correction, export, or deletion of your personal data, and object to or restrict processing. Write to info@zorost.com from your account email; we respond within 30 days. Deleting your account removes your sources, generations, and artifacts, subject to legal bookkeeping retention.
7. Security
API keys are stored as hashed values, never in plain text. Artifacts are served through short-lived signed links. Internal services authenticate to one another over private networking. No method of transmission or storage is perfectly secure, and we make no guarantee to that effect; report concerns to info@zorost.com.
8. Cookies
We use strictly necessary cookies to keep you signed in. No advertising cookies.
9. Changes
Material changes to this policy are announced on the site or by email before taking effect.