LEGAL
Privacy policy
Last updated 2026-10-03.
This policy explains what personal data systemonemodels.ai ("System One Models", the "Service") collects, why, who it is shared with, how long it is kept, and the rights you have under the EU and UK General Data Protection Regulation ("GDPR") and US privacy laws, including the California Consumer Privacy Act as amended by the CPRA ("CCPA") and other US state privacy laws.
1. Who is responsible
The Service is operated by Gilver.ai, Inc., a Delaware corporation, United States ("Gilver.ai", "we", "us"). Gilver.ai is the controller of your personal data for the Service under the GDPR and the "business" under the CCPA.
Contact. [email protected], or by post to Gilver.ai, Inc., 8 The Green, Suite R, Dover, DE 19901, United States.
The Service is a free public preview. If System One Models is incorporated as its own company, your data may transfer to it as described in section 11.
2. What we collect
Account data. Email address, username, display name, password (stored only as a hash), two-factor sign-in settings, and when you accepted these terms and this policy.
Profile and organisation data. Avatar, bio, links, organisation names and membership, and roles.
Published content. Models, files, manifests, model cards, evaluation results and comments you publish. Content you make public is visible to anyone, together with your username.
Course and certificate data. Lesson progress and, if you claim a certificate, the name you enter, the course, the completion date and a certificate number.
Playground and inference inputs. The inputs you send to models and the outputs returned. We use them to answer the request and do not store them. For each request we keep a usage record: the model, the time, the number of questions and tokens, how long it took, where it ran, and the account or API key that sent it.
Communications and preferences. Messages you send us, including support, takedown and privacy requests, and your email preferences and consent records.
Where it comes from. Directly from you; automatically from your browser, device or the CLI; and from sign-in providers you choose to connect.
What is required. An email address, username and password (or a sign-in provider) are needed to create an account, because we cannot provide an account without them. Everything else is optional, but some features will not work without it.
Sensitive data. We do not knowingly collect special categories of data under Article 9 GDPR, such as health, biometric, religious or political data. Please do not include it in your profile, content or playground inputs. Your password and API tokens are "sensitive personal information" under the CCPA; we use them only to authenticate you and secure the Service, never to infer characteristics about you.
3. Why we use it
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Run your account and the registry | Account, profile, content, credentials | Contract |
| Run the playground and inference | Inputs and outputs | Contract |
| Send your inputs to a third-party model provider you select | Inputs and outputs | Contract (at your direction) |
| Issue and verify certificates | Certificate data | Contract |
| Secure the Service and prevent abuse | Technical data, credentials | Legitimate interests |
| Show usage counts and improve the Service | Technical data, aggregated usage | Legitimate interests |
| Send service notices (security, policy changes, transfer notices) | Contract, legitimate interests | |
| Send product news | Email, consent record | Consent, withdrawable at any time |
| Meet legal obligations and handle complaints | Any relevant data | Legal obligation, legitimate interests |
Our legitimate interests are keeping the Service secure, preventing fraud and abuse, understanding aggregate usage to improve the Service, and establishing or defending legal claims. We have weighed these against your rights, and you can object to this processing (section 8).
Every product news email includes an unsubscribe link, and you can withdraw consent at any time without affecting processing that took place before.
We do not sell your personal data, "share" it for cross-context behavioral advertising, use it for targeted advertising, or use your private inputs and outputs to train models. We do not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on you.
4. Who we share it with and what is public
Public information. Content you make public is visible to anyone with your username. Certificate verification pages show the name you entered, the course, the completion date and the certificate number, and can be found by anyone with the number, link or QR code. You can ask us to remove a certificate page at any time at [email protected].
Service providers (processors). We use providers for cloud hosting, GPU computing and storage, databases, email delivery, authentication, error monitoring and analytics, and support tools. They process personal data only on our instructions under written contracts that meet Article 28 GDPR and the CCPA's service-provider requirements, and may not use it for their own purposes.
Third-party model providers. When you use a model hosted by another provider in the playground, your inputs are sent to that provider at your direction and handled under its privacy policy as an independent controller. The model page shows who the provider is.
Other disclosures. We may disclose data to professional advisers under confidentiality duties; to comply with law or valid legal process; to protect the rights, safety or property of users or others; or to a successor company as described in section 11.
5. International transfers
We are based in the United States, and our team and providers may access or process data in the United States, Nepal and other countries whose laws may not protect data to the same standard as your home country.
When we transfer personal data from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, we use the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where relevant), or rely on a recipient's certification under the EU-U.S. Data Privacy Framework, together with supplementary measures where needed. You can request a copy of these safeguards by contacting us.
6. How long we keep data
- Account and profile data: while your account exists, then deleted within 30 days of account deletion.
- Published content: until you delete it; backups are overwritten within 35 days.
- Playground and inference inputs and outputs: not stored; discarded once the answer is returned.
- Usage records of requests: while your account exists; after it is deleted they are kept with no link to you.
- API tokens and device-login sessions: until they expire, you revoke them or you delete your account.
- Server and security logs: 90 days.
- Certificate records: while the certificate exists, so it can be verified.
- Communications, support and privacy requests: 24 months after the request is closed.
- Records needed for legal reasons (such as takedown notices): as long as the law requires.
- Aggregated or de-identified data, which no longer identifies you, may be kept longer. We will not try to re-identify it.
7. Security
We use encryption in transit, hashed passwords, scoped access tokens and access controls to protect data. No system is completely secure. If a personal data breach occurs, we will notify the relevant supervisory authority within 72 hours where the GDPR requires it, and notify affected users without undue delay where the GDPR or US state breach-notification laws require it.
8. Your rights
Everyone. You can access, correct, delete or export your data, and delete your account and content directly in your account settings.
EEA, UK and Swiss residents (GDPR). You have the right to access your data; correct it; erase it; restrict its processing; receive it in a portable format; object to processing based on legitimate interests; object at any time to direct marketing; withdraw consent at any time; and not be subject to decisions based solely on automated processing. You also have the right to lodge a complaint with a data protection supervisory authority, in particular where you live or work or where you think your rights were infringed. EU authorities are listed at edpb.europa.eu; in the UK it is the Information Commissioner's Office (ico.org.uk).
US state residents. Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon and other states with comprehensive privacy laws may have the right to:
- know what personal data we collect, use and disclose, including its categories, sources, purposes and recipients, and get a copy of it;
- correct inaccurate personal data;
- delete personal data;
- receive it in a portable format;
- opt out of the sale or sharing of personal data, targeted advertising and profiling (we do none of these);
- limit the use of sensitive personal information (we already use it only for permitted purposes);
- not be discriminated against for exercising these rights; and
- appeal our decision on a request (see below).
Global Privacy Control. We treat a Global Privacy Control signal from your browser as a valid request to opt out of sale and sharing.
Authorized agents. You may use an authorized agent to make a request. We may ask the agent for signed permission from you and ask you to verify your identity directly.
Appeals. If we decline your request, you can appeal by replying to our decision with "Appeal". We will respond within the time your state's law requires (generally 45 to 60 days). If we deny your appeal, you may contact your state Attorney General.
How to make a request. Email [email protected] from your account email. We will verify your identity, normally by matching your account email, and may ask for more information if needed. We respond within one month under the GDPR and within 45 days under US state laws. Where the law allows us to extend this for complex requests, we will tell you why. Requests are free unless they are manifestly unfounded or excessive.
9. Additional notice for California residents
In the past 12 months we collected the categories of personal information below and disclosed them for business purposes to the recipients shown. We have not sold or shared personal information, and we have no actual knowledge of selling or sharing the personal information of consumers under 16.
| CCPA category | Examples | Disclosed for a business purpose to |
|---|---|---|
| Identifiers | Email, username, IP address, account IDs, API tokens | Hosting, authentication and email providers |
| Customer records | Name on a certificate, email address | Hosting and email providers |
| Professional or education information | Course progress, certificates, organisations and roles | Hosting providers |
| User content and inputs | Published content, playground inputs and outputs | Hosting providers; third-party model providers at your direction |
Sources, purposes and retention periods for each category are described in sections 2, 3 and 6. We use sensitive personal information only for purposes permitted under the CCPA regulations. We do not disclose personal information to third parties for their own direct marketing purposes.
10. Cookies and similar technologies
We use cookies and local storage that are strictly necessary to sign you in, keep your session and secure the Service. These do not require consent. We do not use advertising or cross-site tracking cookies.
If we use analytics cookies, we set them only after you consent through our cookie banner where the law requires it, including in the EEA and UK, and you can change your choice at any time.
Do Not Track. Browser "Do Not Track" signals have no agreed standard, so we do not respond to them. We do not track you across third-party websites, and we honor Global Privacy Control as described in section 8.
11. Transfer to a successor company
If System One Models is incorporated as a separate company, or if Gilver.ai is involved in a merger, acquisition or sale of assets, your data may be transferred to the new or acquiring company, which will become the controller of your data and will be bound by this policy. We will notify you by email at least 30 days before the transfer, name the new company, and you may delete your account before then.
12. Children
The Service is not directed to children under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
13. Changes
We will post updates here and change the "Last updated" date. For material changes, we will notify account holders by email before they take effect. Where a change requires your consent under applicable law, we will ask for it.
Contact
Gilver.ai, Inc., operator of System One Models · 8 The Green, Suite R, Dover, DE 19901, United States · [email protected]