Last updated 13 August 2026
UltimateModel AI lets you fine-tune and serve your own AI model on your own data. This policy explains what we collect, where it goes, who else processes it, and how to get it deleted.
Two distinct groups of people are covered. You, our customer, and your end users — the people who talk to a model you have deployed, including through our embeddable chat widget. The section on captured traffic is the important one for them, and it is your responsibility to disclose it to them.
Each customer gets a dedicated, access-isolated Google Cloud Storage bucket. Your training data and model weights are not commingled with any other customer’s. Data is encrypted at rest (AES-256) and in transit (TLS 1.3). Our infrastructure runs in Google Cloud, region us-central1 (United States).
Your data is never used to train another customer’s model, and never used to train a general-purpose model of ours.
When you deploy a model, we can capture the prompts sent to it and the responses it returns. This is the “flywheel” feature: captured traffic is scored for quality and can be promoted into future training runs so your model improves.
You should know two specific things about this. First, capture is enabled by default on new projects; you can turn it off per project at any time, and turning on compliance mode disables it. Second, quality scoring of captured traffic runs on our own infrastructure — captured prompts and responses are not sent to a third-party AI provider for scoring.
If your end users are members of the public — for example through the embeddable widget — you are the controller of their data and you are responsible for telling them that their messages may be stored and processed as described here.
We share data with the following processors, and only for these purposes:
| Processor | Purpose | What it receives |
|---|---|---|
| Google Cloud | Hosting, storage, compute | All data, encrypted |
| OpenAI | Synthetic data generation; document search indexing (opt-in); evaluation judging (when you run one) | Document excerpts when generating training data; document chunk text and your playground chat queries for embedding when you enable Living Memory retrieval; your project’s stated perspective and model outputs when you run an evaluation or benchmark. Not captured end-user traffic — that is scored on our own infrastructure. |
| Stripe | Payments | Billing details, email |
| Resend | Transactional email | Email address, message content |
| Hugging Face | Base model weights; optional publishing you initiate | Nothing about you, unless you publish a model yourself |
You can access, correct, export or delete your data. Model weights and training data can be exported from the app. To request erasure, or to exercise any right under the GDPR or the CCPA, email privacy@ultimatemodel.ai. Deleting your account removes your projects, training data and weights from our storage.
Captured traffic is covered by erasure: deleting a project deletes its captured logs, and deleting your account hard-deletes every captured log under all of your projects in the same operation — the deletion fails loudly rather than reporting success over remaining data. For narrower requests (for example, one specific end user’s messages), email us and we will remove them.
We keep your data for as long as your account is active. After you delete your account or cancel, exports remain available for 30 days and then data is removed. Backups age out within 90 days.
Questions about this policy: privacy@ultimatemodel.ai. See also our Terms of Service.