Privacy Policy
Last updated: August 27, 2026
1. What this covers
This Privacy Policy describes how Comitas AI, Inc. ("Comitas," "we," "us") handles personal information collected through the Comitas.ai website and the Comitas agentic AI platform (the "Service"). It applies to visitors, people who request access, and account holders.
2. What we collect
- Access requests and account information: name, email address, and what you tell us about how you'd use the Service, when you request access or create an account.
- Content you submit: documents, prompts, and other material you provide to run a workflow, and the outputs the Service generates for you.
- Usage and billing data: the compute, storage, and model usage your account incurs, used to bill you accurately and transparently.
- Feedback: anything you submit through our feedback tools, including its category and free-text content.
- Technical data: standard request metadata (timestamps, error logs) needed to operate and secure the Service.
We don't ask for information we don't need. For example, rather than ask you to estimate the value of your time or how long a task would normally take you as form fields that we carry through the on-boarding wizard, we provide UI controls for you to estimate and calculate live in your own browser from numbers you choose to enter, and isn't sent to us unless you explicitly opt-in to save it for the convenience of future ROI calculations.
3. How we use it
- To provide, maintain, and bill for the Service.
- To evaluate and respond to access requests.
- To communicate with you about your account or requests you've made.
- For security and abuse monitoring, as described in Section 5.
- To improve the Service — in the aggregate, and never by using your content to train models (see Section 4).
4. Third-Party Providers
Comitas is model-agnostic: we rely on third-party infrastructure and AI model providers ("Third-Party Providers") to deliver the Service, rather than operating our own models. When your usage requires it, your content is transmitted to the relevant Third-Party Provider to generate a result.
Comitas does not use your content to train any model, ours or anyone else's. We go a step further on behalf of our customers: as a condition of working with a Third-Party Provider, its own applicable terms must already commit not to use your data to train its models, either directly or through the specific serving layer we access it through. We verify this before selecting a provider, and will continue to monitor for policy changes. If a Third-Party Provider we rely on changes its terms in a way that no longer meets this standard, we stop routing your data to it and look for a path that does. These policies have not historically changed often, because of strong customer sentiment for this requirement. We mirror that sentiment and proactively protect it on our customers' behalf.
This matters more than it might sound: the same underlying model can be reached through more than one path, and those paths don't always carry the same commitment. A model made available through a well-governed hosting layer can inherit that layer's stronger data-handling terms, even where the model developer's own separate consumer product doesn't make the same promise. We choose the path that carries the commitment, not just the model that's cheapest or most capable in isolation.
If a Third-Party Provider we rely on changes its terms in a way that no longer meets this standard, we stop routing your data to it and switch to another provider.
We don't currently name every Third-Party Provider we use in this policy, since that mix may change as we evaluate cost, capability, and fit with our own environmental and data-handling commitments. As those relationships stabilize, we intend to publish a list here.
5. Data retention
We keep the inputs and outputs from your use of the Service for up to 30 days, solely for abuse monitoring and ongoing security purposes, and delete them after that window in the ordinary course.
If your account or a specific request is flagged by our automated systems as violating these terms, we may retain the related content longer than 30 days to investigate and enforce our policies. Account and billing records are kept as long as needed for legal, tax, and accounting purposes.
6. Data security
Your data is isolated from other customers' data. We enforce multi-factor authentication by default and design the Service with the smallest reasonable retention footprint for the kind of data involved. No system is perfectly secure, and we can't guarantee absolute security, but we treat this as a first-class design constraint and have world-class talent working on it.
7. Your choices and rights
- You can access and update your account information at any time.
- You can delete your account and associated data directly through the Service without contacting us for support.
- If a feature lets you opt in to save additional data (like your hourly value for ROI calculations), it defaults to off, and you can turn it back off at any time.
8. Children's privacy
The Service isn't directed at children, and we don't knowingly collect personal information from anyone under 18.
9. Changes to this policy
We may update this policy as the Service evolves. We'll post the revised policy here with an updated date.
10. Contact
Questions about this policy or your data? Reach out to us.