earthruntimeby Provocative

Privacy Policy

Effective: 2026-08-06

Last updated: 2026-08-06

This policy describes how Provocative Science Holdings, Inc ("Provocative", "we", "us", "our") collects, uses, and protects information when you use earthruntime β€” the website at earthruntime.com and the inference API at api.earthruntime.com (together, the "Service"). earthruntime is a product of Provocative Science Holdings, Inc β€” the same company owns and operates this website and the Service, and is the advertiser named on any advertising that links to them.

at a glance
  • We do not train models on your prompts, completions, or any other content you send to or receive from the Service.
  • We do not store prompt or completion content. We meter token counts, not text.
  • We do not sell your data and do not share it with third parties except to operate the Service or where required by law.
  • Payments are handled by Stripe. Your card details never touch our servers.
  • Inference runs on hardware we own and operate in Massachusetts, United States.
the policy

1. Information we collect

1.1 Signup and verification

To issue an API key we collect the email address you enter, and we send it a short-lived verification code (codes expire after 15 minutes). We also record basic request metadata β€” timestamp and source IP address β€” used for rate limiting and abuse prevention. We use your email to deliver your verification code and API key, to credit payments to the right account, and to send service messages about your account. We do not sell it or share it for advertising.

1.2 API request metering (collected for every request)

For every request to the API we record:

  • A unique request identifier and timestamp
  • The model called and the account and API key that called it
  • Input and output token counts (this is how usage is billed against your credit)
  • Latency and other performance measurements
  • The error class, if the request failed
  • The source IP address (for rate limiting and abuse prevention)

We do not record the contents of prompts or completions.

1.3 Payments and billing

Credit purchases are processed by Stripe. Checkout happens on Stripe's payment pages: your card number and other payment-instrument details go directly to Stripe and never touch our servers. From Stripe we receive and retain the email address associated with the payment, the amount, and transaction identifiers, along with records of credits and receipts we are required to keep for tax and accounting purposes.

1.4 Website analytics

We measure website traffic with self-hosted, first-party analytics (Umami) running on our own infrastructure. It collects aggregate page-view statistics and is not shared with any third-party analytics or advertising vendor. We do not place advertising or behavioral-tracking scripts on this site.

2. How we use information

  • Operate the Service: authenticate requests, route them to inference workers, return responses, enforce rate limits, and meter usage against your credit balance.
  • Run signup: deliver verification codes and your API key to the email you provide.
  • Process payments, apply credits, and keep required billing and tax records.
  • Investigate operational issues, abuse of the Service, and security incidents.
  • Communicate with you about your account, material changes to this policy, and incidents that affect you.

What we will not do

  • We will not use prompts, completions, or any other customer content to train, fine-tune, evaluate, or benchmark any model, whether ours or a third party's.
  • We will not sell customer data.
  • We will not disclose customer data to third parties for advertising or marketing.

3. Data sharing

We share information only with the service providers that help us operate the Service: Stripe for payment processing, Resend for transactional email (verification codes and key delivery), and the infrastructure providers that host our website and control-plane databases. These providers are bound by contract to use the information only to deliver services to us, and they are not permitted to use it for their own purposes. A current list of subprocessors is available on request.

We may disclose information when we are required to by law β€” for example in response to a subpoena, court order, or valid governmental request. Where we are legally permitted to do so we will notify the affected customer before responding.

4. Data retention

CategoryRetention
Prompt and completion contentNot stored
Verification codesExpire after 15 minutes
Request metadata (tokens, latency, model, account, error class)13 months
Account, credit, and billing recordsLifetime of the account, plus the period required by applicable tax and accounting law

Backups follow the same schedule and age out on the same cadence as the primary records they protect.

5. Data residency

All inference workers run on hardware we own and operate in Massachusetts, United States. Prompts and completions are processed within that footprint; we do not route inference requests through third-party cloud regions. Supporting services β€” website hosting, control-plane databases, email delivery, and payment processing β€” are provided by United States–based cloud providers.

6. Security

  • Customer connections are protected with TLS.
  • API keys are stored as hashes; we never store them in plaintext.
  • Access to production systems is limited to authorized personnel.

We do not currently hold a SOC 2 or ISO 27001 certification. We are happy to discuss our controls with customers who need formal assurance.

7. Your rights

  • You can query your own usage at any time via the GET /v1/usage endpoint, authenticated with your API key.
  • You can ask us to revoke your API key or delete your account. When an account is deleted we remove account records and request metadata within 30 days, subject to the legal retention requirements described above for billing and tax records.

If you live in a jurisdiction that grants additional privacy rights β€” including, for example, the European Union, the United Kingdom, or California β€” you may have the right to request access to, correction of, deletion of, or portability of your personal information, or to object to certain processing. You can exercise these rights by emailing us at the address in section 10. We will respond within the period required by the applicable law.

8. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from them.

9. Changes to this policy

If we make a material change to this policy we will email the address on your account and post the updated policy on this page at least 30 days before the change takes effect. Non-material clarifications may be made without notice; the "Last updated" date at the top of this page will always reflect the most recent revision.

10. Contact

Questions about this policy, or requests to exercise a right described above, can be sent to privacy@provocative.earth.

← Back to earthruntime
Β© 2026 Provocative Science Holdings, Inc Β· earthruntime.com