Privacy Policy.
Last updated: 9 August 2026
Who we are
Trifrost (trifrost.tech) is a cloud-hosted control plane for AI inference. This policy explains what data we collect when you use the Trifrost service and website, why we collect it, and the rights you have over it. Questions? Email cory+trifrost@hawkvelt.id.au.
What we collect
- Account data — name, work email, organization membership, and role claims, provided by your identity provider at sign-in. We do not collect or store your IdP password.
- Usage and telemetry data — request metadata for every inference call: model, provider, token counts, cost, latency, timestamps, and the requesting user, key, and department. This powers billing, budgets, and the audit log.
- Billing data — plan, invoices, and payment status.
What we never do
- We never train on your prompts. Your prompt and completion data is not used to train or fine-tune any model — ours or anyone else's.
- We never capture prompt or response bodies by default. Bodies are only stored when your organization's administrators explicitly enable a request_body_logging policy, and every captured body carries a provenance stamp naming the policy that enabled it.
- We never sell your data — to anyone, for any reason.
Data residency
Your tenant runs in the region you choose — AU, APAC, EMEA, UK, or Germany — and your data stays in that region. Prompt data flows only to the LLM providers your administrators configure. If you need a region we don't list, contact us and we'll scope it.
Sub-processors
We use a small number of sub-processors to deliver the service — cloud infrastructure, customer-configured LLM providers, and transactional email. The current list is at Sub-processors.
Retention
Account data is kept while your account is active. Usage and audit event retention follows your plan and contract. On termination, your data is deleted as described in the Data Processing Addendum.
Your rights
You can request access to, deletion of, or an export of your personal data at any time by emailing cory+trifrost@hawkvelt.id.au. If your organization operates the tenant, some requests are handled by your administrator — we'll tell you when that's the case.
Security
Encryption in transit and at rest, server-side sessions, per-organization isolation, and a tamper-evident, HMAC-signed audit log. Details live in the trust center.
Changes to this policy
If we make material changes, we'll update the date above and notify customers through the console. The current version is always at this URL.
Contact
Privacy questions, requests, or complaints: cory+trifrost@hawkvelt.id.au.