Legal
Privacy Policy
Last updated: 30 September 2026
This policy explains what personal data we process when you visit system1models.ai, create an account, or use the System1 Models API, dashboard, MCP server or status page (together, the "Service"). It follows Article 13 of the EU General Data Protection Regulation (GDPR).
Short version: we host in the EU, and at present all API requests, in both tiers, are processed in the EU. We do not store the content of your API requests. We use no website analytics, no tracking cookies and no advertising. We keep account, billing and technical usage data only as long as needed or required by law.
1. Who is responsible
The controller is productivity-boost.com Betriebs UG (haftungsbeschränkt) & Co. KG, Reichenberger Str. 2, 94036 Passau, Germany, represented by its general partner productivity-boost.com UG (haftungsbeschränkt), itself represented by its managing director Florian Standhartinger. Email: info@productivity-boost.com, phone +49 178 1981631. Full details: Imprint.
We have not appointed a data protection officer because we are not legally required to. For all privacy questions, write to info@productivity-boost.com.
Content you send to the API is different. When our customers send data to the API (states, questions, images), they decide what data is processed and why. For that data, the customer is the controller and we are its processor under our Data Processing Agreement. If you are affected by such processing, please contact the customer that uses our Service; we will support them. This policy covers the data we process for our own purposes.
2. What we process, why, and on what legal basis
2.1 Delivering the website (server logs)
When you open a page or call the API, your client sends technical data to our servers: IP address, date and time, requested address, referrer, HTTP status, amount of data transferred, and user agent. We need it to deliver the Service and to detect and fend off attacks, abuse and errors.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is a secure and working Service.
- Retention: logs containing IP addresses are deleted after 14 days at the latest, unless a specific security incident requires us to keep individual entries longer to investigate it.
2.2 No website analytics
We do not analyse visits to this website and do not use any analytics or tracking service. There are no analytics cookies or beacons, no visitor identifiers, no device fingerprinting and no IP-derived location data. The only technical record of a page view is the server log described in section 2.1.
2.3 Your account
When you create an account, we process your email address, and, if you provide them, your name, company name, billing address, VAT ID and the settings you choose (for example, the per-key default tier and the data retention setting). When you sign in, we process sign-in timestamps and a session identifier.
- Sign-in by email (when enabled; not offered at present): we send a one-time sign-in link to your email address. The link expires after 15 minutes.
- When Google sign-in is enabled, we request only the
openidandemailscopes. Google returns a stable account identifier and your verified email address; we do not request profile, Gmail or Drive data and we never receive your password. We store the identifier and email with your account, but do not store the OAuth access token or ID token. We use Google sign-in data to create, authenticate and secure your account, and to contact you about your account, including service emails and invoices. We do not use it for advertising, model inputs or unrelated profiling. Our use follows the Google API Services User Data Policy, including its Limited Use requirements. Google Ireland Limited (Ireland) provides sign-in under its own privacy policy; transfers to Google LLC in the United States may occur as described in section 4. - Legal basis: Art. 6(1)(b) GDPR (performance of the contract).
- Retention: for as long as the account exists. After you close your account, we delete account data within 30 days, except data we must keep under commercial and tax law (see section 5).
2.4 API keys and usage records
For every API request, we record metadata: request ID, time, API key ID, account, model, tier, number of input tokens, number of decisions, response time, processing status and the price charged. We do not record the content of requests or responses (states, questions, images, probabilities) in logs or databases. API keys are stored only as a cryptographic hash; the full key is shown to you once.
If a request carries the optional Idempotency-Key header, we additionally keep, for 24 hours, a keyed (HMAC) digest of the request body, the request ID, the processing status and the usage receipt, so that a retried request is not processed or charged twice. This record never contains the content of the request or the answer. Legal basis: Art. 6(1)(b) GDPR.
- Purposes: billing, showing you your usage, rate limiting, capacity planning, and detecting misuse.
- Legal basis: Art. 6(1)(b) GDPR for billing and usage display; Art. 6(1)(f) GDPR for security and capacity planning (legitimate interest: a stable and secure Service).
- Retention: detailed usage records for 13 months, then aggregated per day, model and tier without request IDs. Records needed as accounting evidence for an invoice are kept as long as the law requires (section 5).
2.5 Payments and invoices
Top-ups are paid through Stripe. You enter payment details directly with Stripe; we never see your full card number. Stripe tells us the payment status, amount, currency, card brand, the last four digits and the country, and calculates VAT (Stripe Tax). We create invoices with your billing details.
- Stripe Payments Europe, Ltd., 1 Grand Canal Street Lower, Dublin 2, Ireland, processes payment data. For payment processing and for its own legal duties (such as anti-money-laundering and fraud prevention), Stripe acts as an independent controller; see stripe.com/privacy.
- Legal basis: Art. 6(1)(b) GDPR (payment for the contract) and Art. 6(1)(c) GDPR (tax and commercial law obligations).
- Retention: see section 5.
2.6 Promotional credit and abuse prevention
While the promotional credit offer in section 5.3 of the Terms is active, we store a one-way hash of the verified email address and of the email domain to prevent the credit from being claimed more than once, including through deleted and re-created accounts. While the offer is switched off, this processing does not take place.
- Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest is preventing fraud and abuse of promotional credit.
- Retention: the hashes are kept for 24 months after the credit is granted.
2.7 Service emails
We send emails that are necessary for the Service: sign-in links, payment receipts, invoices, security notices, and notices of changes to the Service, prices or these documents.
- Legal basis: Art. 6(1)(b) GDPR; for security and legal notices also Art. 6(1)(c) and (f) GDPR.
- We do not send newsletters or marketing emails unless you have opted in separately. You can withdraw that consent at any time via the link in each email.
2.8 Support and business enquiries
If you write to us, we process your contact details and the content of your message to answer you. If you send us a letter of intent or a request for an individual contract, we process the contact details of the people involved.
- Legal basis: Art. 6(1)(b) GDPR where the message relates to a contract or a request before a contract; otherwise Art. 6(1)(f) GDPR (legitimate interest: answering enquiries and maintaining business relationships).
- Retention: normally three years after the end of the calendar year of the last contact (standard limitation period, § 195 BGB), longer where section 5 requires it.
2.9 Status page
The status page at system1models.ai/status is part of our website; it does not yet report live availability. It is covered by sections 2.1 and 2.2. We do not currently offer email subscriptions to status notifications. If we introduce them, we will process your email address on the basis of your consent (Art. 6(1)(a) GDPR) until you unsubscribe, and we will update this policy first.
3. Recipients
We use the following service providers. Those marked "processor" process data on our instructions. We require an Art. 28 GDPR agreement for customer-data processing before opening that service.
| Provider | Purpose | Location | Role |
|---|---|---|---|
| Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany | Hosting of the websites, API gateway and database; encrypted backups | EU (data centre in Helsinki, Finland) | Processor |
| DataCrunch Oy (Verda), Helsinki, Finland | GPU servers for inference (both tiers) | EU (Finland) | Processor |
| Scaleway SAS, 8 rue de la Ville-l'Évêque, 75008 Paris, France | Sending service emails (planned; not in use at present) | EU (Paris, France) | Processor, once enabled |
| Stripe Payments Europe, Ltd., Dublin, Ireland | Payments, tax calculation, invoices | EU; transfers to Stripe, Inc. (USA) possible | Independent controller for payment processing; processor for invoicing |
| Google Ireland Limited, Dublin, Ireland | Optional "Sign in with Google" | EU; transfers to Google LLC (USA) possible | Independent controller |
The current list of sub-processors that may process API content is at /legal/subprocessors.
Global tier: at present, Global-tier requests are processed only in the EU, on the same infrastructure and by the same processors as the EU tier. Before any Global-tier traffic is processed outside the EU, we will update this policy and the sub-processor list, and customers must explicitly opt in per API key.
We do not sell personal data and do not share it with anyone for advertising. Where the law requires it, we pass data to public authorities.
4. Transfers outside the EU/EEA
Our own servers and all servers that process API requests are located in the EU. A transfer to a third country can happen only in these cases:
- Stripe: Stripe may transfer data to Stripe, Inc. in the USA. Stripe, Inc. is certified under the EU-U.S. Data Privacy Framework (adequacy decision of the European Commission of 10 July 2023, Art. 45 GDPR); Stripe also uses the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
- Google sign-in (only if you choose it): Google LLC is certified under the EU-U.S. Data Privacy Framework (Art. 45 GDPR).
5. Retention required by law
We keep invoices and accounting records for the periods set out in German commercial and tax law: currently eight years for accounting vouchers such as invoices and payment records, and ten years for books, annual financial statements and related records (§ 257 HGB, § 147 AO); six years for business letters. During these periods the data is restricted to these legal purposes.
6. Is providing data required?
To use the Service, you must provide an email address; without it we cannot create an account. For paid top-ups, billing details are required by tax law. Everything else is optional.
7. Automated decision-making
We do not make decisions about you based solely on automated processing, including profiling, within the meaning of Art. 22 GDPR. Automatic limits — for example, rate limits or rejecting requests when the prepaid balance is exhausted — only apply the rules set out in our Terms.
8. Your rights
You have the right to:
- access your personal data (Art. 15 GDPR),
- have incorrect data corrected (Art. 16),
- have your data erased (Art. 17),
- restrict processing (Art. 18),
- receive your data in a portable format (Art. 20); you can also view your usage data in the dashboard,
- object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(f) GDPR (Art. 21). We will then stop processing unless we can show compelling legitimate grounds or need the data to establish, exercise or defend legal claims,
- withdraw any consent at any time, with effect for the future (Art. 7(3)); this does not affect processing that happened before you withdrew it.
To use these rights, email info@productivity-boost.com.
You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), for example the one where you live or work, or the one responsible for us: Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.
9. Security
We protect data with the technical and organisational measures described on our Security page: encryption in transit (TLS), hashed API keys, strict separation of customer accounts, minimal logging, and access limited to the people who need it.
10. Cookies
We use no tracking cookies. The dashboard uses strictly necessary cookies to keep you signed in. Details: Cookie statement.
11. Changes
We update this policy when the Service or the law changes. The current version is always available here, with its date at the top. We inform account holders of material changes by email.