Data Use Policy
Version v2026-07.1. This policy is part of the Terms of Service.
The commitment
We do not use customer content to train, fine-tune, evaluate, or otherwise improve machine-learning models or generalized products. Not our models, and not anyone else's. This is the only mode the service has: it applies to every account and every plan, it requires no opt-out, no flag, and no configuration, and no future change to this policy can reach content you have already given us.
What customer content covers
Customer content means everything you or your agents put into the service or produce on it, in every form we hold it:
- node disks, the files on them, and snapshots of them;
- context uploads and build contexts, inline or presigned, and the images built from them;
- objects in your organization's storage buckets;
- command strings, environment values, and anything typed at or returned by a running command;
- stdout, stderr, and every log line we capture or store on your behalf;
- job inputs and outputs, including declared results and exported artifacts;
- data imported through connections, whether from your own provider or from our object storage;
- metrics, traces, and telemetry, both what the platform emits about your workloads and what your workloads emit themselves;
- support tickets and everything referenced from them.
Contractual, and it binds subprocessors
This restriction is part of our Terms of Service, not a statement of current practice we could quietly revise. It also flows down: the vendors that store, transmit, or process customer content for us may use it only to provide their service to us, under agreements that do not permit using it to train or improve machine-learning models. That covers every category of subprocessor we use, including infrastructure hosting, the control-plane database, object storage, web hosting, authentication, billing, email delivery, observability storage, and the datacenter operators whose machines run your nodes.
Narrow exceptions, none of them training
Three kinds of processing happen outside serving your requests back to you, and none of them trains, fine-tunes, or evaluates a model on your content:
- Security and abuse prevention. We examine operational signals such as network flow logs, resource telemetry, and, where necessary to investigate a specific incident, the content involved in it, to protect the platform and enforce the Acceptable Use Policy.
- Aggregated operational statistics. Counts, latencies, utilization, and spend, used to run and plan the service. These contain no customer content.
- Processing you direct. When you point us at your data, for example in a support ticket, we act on it for that purpose and that purpose only.
Data protection agreements
A signed data processing agreement incorporating this commitment is available to any customer on request through the contact form. Material changes to this policy bump the version above and are announced on the changelog.