PhaseoPhaseo

Last updated: August 30, 2026

Privacy Policy

This Privacy Policy explains how Daniel Butler operating under the name Phaseo ("Phaseo", "we", "us" or "our") collects, uses and protects personal data when you use our websites, dashboards and API gateway (together, the "Service").

This page is a high-level description of how we handle personal data. It is not legal advice. Capitalised terms not defined here have the meaning given in our Terms of Service.

By using the Service, you agree that we may process your personal data as described in this Privacy Policy and the Terms of Service. If you do not agree, you should not use the Service.

1. Who we are and how this Policy applies

For the purposes of UK and EU data protection law, Daniel Butler, trading as Phaseo, is the data controller responsible for personal data collected through Phaseo.

This Privacy Policy applies when you:

  • browse the Phaseo website or documentation;
  • create and use a Phaseo account;
  • use the Phaseo Gateway to route requests to third-party model providers;
  • connect Phaseo to ChatGPT, Codex, or another compatible MCP client;
  • interact with us via email, support channels or other communications.

Third-party model providers have their own privacy and data handling practices. A provider used through Phaseo-managed credentials is intended to act as our subprocessor for inference where the applicable contract supports that role. A provider used with your credentials or direct agreement is normally a customer-directed recipient or your processor. A provider may separately act as a controller where it processes data for its own purposes, such as training where its terms permit that use. Our current role review is published in the Phaseo subprocessor schedule.

2. Data we collect

2.1 Information you provide to us

We collect information that you choose to provide directly, such as:

  • Account details – for example your name, email address, organisation name, and password (stored as a hashed value) when you register.
  • Profile and team information – details you add to your account or team profile, such as display names or project labels.
  • Billing information – records relating to your purchases of Credits or subscriptions (for example currency, amount paid, timestamps). Card details are handled by our payment providers (such as Stripe) and are not stored in full on our servers.
  • Support and communication – emails, messages and other communications you send to us (for example bug reports, feedback, or feature requests).
  • Optional public data – if you opt in to sharing certain usage or app information publicly (for example, public app-usage pages or sponsor listings), we will process and display that information in accordance with your choices.

2.2 Inputs and Outputs sent through the Gateway

When you call models through Phaseo Gateway, you send requests (“Inputs”) and receive responses (“Outputs”). These may contain personal information, depending on what you choose to send.

We aim to store as little as possible:

  • We do not persistently store the raw text of prompts or full model Outputs in our primary database or analytics tools.
  • Eligible non-streaming text Outputs may be kept in a workspace-scoped response cache for five minutes by default. A configured preset can set a period from 30 seconds to 24 hours. The request contributes to a one-way cache-key digest; the cache record stores the Output and response metadata, not the raw request body.
  • If you enable private I/O logging, we may keep Inputs, Outputs and optional provider payloads for 90, 180 or 365 days. If you opt into data contribution, we may apply best-effort redaction and keep eligible Inputs and Outputs for no more than 30 days. These features are separate from provider retention.
  • We send the necessary request content to the relevant third-party provider so it can generate an Output. Those providers may log or store the data under their own policies.

Because you control what you send, avoid including sensitive personal data in prompts or Outputs unless it is strictly necessary and you are satisfied with the relevant model providers’ privacy practices.

2.3 Telemetry and technical data

We automatically collect certain technical and usage information when you use the Service, including:

  • Log and device data – IP address, browser type, operating system, device identifiers, pages visited, features used, timestamps and referrer URLs.
  • Gateway metrics – model and provider identifiers, request and response timestamps, token usage, latency, error codes and similar metadata needed for billing and health checks.
  • Location indicators – a rough geographic estimate, such as country or region, derived from your IP address or other signals for analytics and abuse prevention.
  • Configuration data – your selected theme or appearance, feature flags and other preferences stored in local storage or cookies.

We use this telemetry to operate, secure and improve the Service, calculate usage and pricing, and provide analytics and observability dashboards. We design telemetry to exclude raw prompt and Output text.

2.4 Connected AI assistants and MCP clients

If you connect the Phaseo plugin to ChatGPT, Codex or another compatible MCP client, you authorize that client through OAuth to request the read-only Phaseo information shown on its consent screen. Depending on the tool used, Phaseo may return:

  • model, provider, capability and pricing information;
  • credit balance and aggregated usage analytics; or
  • request metadata such as request identifiers, timestamps, models, providers, token usage, cost, latency, status and error codes.

The public Phaseo plugin does not return passwords, API key values, OAuth secrets, raw prompt or model Output content, workspace or user identifiers, storage details or replay payloads. The connected client receives only the result of a tool it invokes within the permissions you approved. The client provider’s privacy policy and retention practices apply to information it receives.

2.5 Cookies and similar technologies

We use cookies and similar technologies, such as local storage, pixels and scripts, to make our site work and understand how it is used. These may include:

  • Strictly necessary cookies – required for security and core features such as login and CSRF protection.
  • Preference cookies – used to remember settings such as dark mode or your most recently selected filters.
  • Analytics cookies – used to measure usage, performance and errors, for example through Google Analytics or PostHog.

You can control cookies in your browser settings. Blocking some types may affect your experience or prevent certain features from working.

2.6 Analytics and product telemetry

We may use third-party analytics and error-tracking tools, such as Google Analytics, PostHog or similar services, to understand how people use Phaseo and where we can improve it.

These tools collect information such as pages visited, actions taken, device and browser information, and approximate location such as country. We configure them so they are not used to store raw prompts, Outputs or other highly sensitive content sent through Gateway.

3. How we use personal data (and our legal bases)

We use personal data for the following purposes, under these legal bases (for UK/EU users):

  • To provide and operate the Service – including account creation, Gateway routing, usage dashboards, billing and customer support.
    Lawful basis: performance of a contract; legitimate interests.
  • To personalise and improve the Service – for example, by understanding which features are used most, testing new functionality and adjusting the UI.
    Lawful basis: legitimate interests.
  • To communicate with you – for example, by sending service announcements, responding to support requests and informing you about changes to our terms or policies.
    Lawful basis: performance of a contract; legitimate interests; legal obligations.
  • To send optional updates or product news – where you have signed up to receive them or local law allows us to do so.
    Lawful basis: consent (or legitimate interests, where permitted).
  • To prevent abuse, enforce our Terms and protect the Service – for example, by monitoring high-risk usage patterns, attempts to bypass rate limits or fraud.
    Lawful basis: legitimate interests; legal obligations.
  • To comply with legal obligations – such as keeping records for tax and accounting or responding to legitimate requests from authorities.
    Lawful basis: legal obligations.

We may also create aggregated, anonymised statistics about model adoption, benchmark results or API performance. These statistics do not identify individual users.

4. How we share personal data

We do not sell your personal data. We may share personal data in these limited situations:

  • Service providers – We use trusted third parties to help operate the Service, such as hosting and database providers (including Supabase), analytics platforms, payment processors (including Stripe), email providers and customer support tools. They may access personal data only to perform services for us and must protect it under contract.
  • Third-party model providers – When you send requests through Gateway, we share your Inputs and necessary metadata with the model providers you choose or to which we route requests. Those providers process the data under the applicable provider contract, terms and privacy policy. A provider’s role depends on whether Phaseo or the customer supplies the provider account and whether the provider processes data for an independent purpose.
  • Connected AI assistant or MCP providers – When you connect Phaseo and ask a connected client to use a Phaseo tool, we return the requested read-only tool result to that provider, such as OpenAI for ChatGPT or Codex. The provider processes the result under its own terms and privacy policy.
  • Public data you choose to share – If you opt into public usage pages, share integrations or otherwise choose to publish information through AI Stats, we display it according to your settings.
  • Legal and safety reasons – We may disclose data if we reasonably believe this is necessary to comply with a law, court order or other legal request, or to protect our rights, property or safety, or those of our users or others.
  • Business transfers – If we explore or undertake a merger, acquisition, reorganisation or sale of assets, personal data may be transferred as part of that process. We will take reasonable steps to ensure the recipient continues to protect your data in line with this Policy.
  • With your consent – We may share your information for other purposes if you explicitly ask us to or consent to it.

5. International transfers

We are based in the United Kingdom, but use service providers and infrastructure in other countries, including the European Economic Area and the United States. Your personal data may therefore be transferred to and processed in countries whose data protection laws differ from those in your home jurisdiction.

When we transfer personal data outside the UK or EEA, we take steps to ensure an appropriate level of protection, for example by relying on:

  • countries that the UK or EU has deemed adequate;
  • standard contractual clauses or equivalent safeguards approved by the UK or EU; or
  • other lawful transfer mechanisms as they become available.

6. How long we keep your data

We retain personal data for as long as reasonably necessary to fulfil the purposes described in this Policy, including:

  • Request-level metadata for BYOK Gateway calls is kept for up to 90 days. Aggregated, non-content usage totals may be kept longer for billing, reliability and statistical purposes.
  • operating and maintaining your account and any paid features;
  • complying with our legal and regulatory obligations, such as keeping tax and accounting records; and
  • resolving disputes and enforcing our agreements.

When we no longer need personal data, we will delete it or irreversibly anonymise it. Aggregated and fully anonymised telemetry may be kept longer for statistical purposes.

  • Verified account-deletion requests remove account access and active database records immediately. Private object-storage and Gateway cache data are then purged through a retryable workflow that must finish within 30 days.
  • Eligible cached model Outputs are kept for five minutes by default and no more than 24 hours under a configured cache policy.
  • Private I/O logs, when enabled, are configured for 90, 180 or 365 days.
  • Raw data contributions that you opt into are kept for no more than 30 days; aggregate classification statistics may be kept longer.
  • AI providers and destinations configured by customers apply their own retention terms.

We have not yet consolidated every account, request-metadata, billing, support, backup and operational-log category into one fixed retention schedule. See the Security whitepaper for the currently verified content-handling periods and their limitations.

Using the Phaseo plugin does not create a separate long-term copy of your Gateway records within Phaseo. Tool requests read or compute against Phaseo data available to the authorised service, including already-retained account and Gateway records where applicable. A connected client may retain tool results under its own retention policy.

7. Your rights and choices

Depending on where you live, you may have certain rights relating to your personal data. Subject to limits and exceptions under applicable law, these may include:

  • Access – ask whether we process your personal data and request a copy.
  • Correction – ask us to correct inaccurate or incomplete personal data.
  • Deletion – ask us to delete certain personal data.
  • Restriction – ask us to restrict how we process your data in certain circumstances.
  • Portability – receive your personal data in a structured, commonly used, machine-readable format and, where technically feasible, have it sent to another controller.
  • Objection – object to certain types of processing, including direct marketing or processing based on legitimate interests.
  • Withdraw consent – where we rely on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.

You can exercise many of these rights by signing in to your account (settings, profile and API keys), or by contacting us at [email protected]. We may ask you to verify your identity before responding.

You can opt out of non-essential emails using the unsubscribe link in the message or by contacting us. We may still send administrative messages about your account or important changes to the Service.

8. Children

The Service is intended for users aged 13 and over. We do not knowingly collect personal data from children under 13. If you believe a child has provided us with personal data without appropriate consent, contact us and we will take steps to delete it.

9. How we protect your data

We use technical, organisational and administrative security measures to protect personal data, including encryption in transit, role-based access controls and monitoring for unusual activity.

However, no online service can be completely secure. You are responsible for keeping your password, API keys and other credentials confidential, and for rotating keys if you suspect they have been compromised. If you believe your account has been compromised, contact us immediately at [email protected].

10. Third-party sites and services

The Service may contain links to third-party websites or integrations, including AI model providers, documentation, payment, analytics and developer-tool providers. We are not responsible for their privacy practices. We recommend reviewing their privacy policies before providing personal data to them.

11. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If changes materially affect your rights or how we use personal data, we will take reasonable steps to notify you, for example by email, a notice on the site or in-app messages.

If you continue to use the Service after changes take effect, you accept the updated Policy.

12. Contact and complaints

If you have questions about this Privacy Policy or how we handle personal data, contact us:

  • Email: [email protected]
  • Support: [email protected]

If you are in the UK, you also have the right to lodge a complaint with the Information Commissioner’s Office (ICO), or with your local data protection authority if you are in the EU. We would appreciate the chance to address your concerns first, so please consider contacting us before doing so.