Legal
Privacy policy
Privacy policy for Frontière AI (FLEECE AI SASU). GDPR-compliant data processing, zero prompt retention, data retention, and your rights.
Read in Français
Last updated: September 2026
Introduction
This privacy policy explains how Frontière AI (operated by FLEECE AI SASU) collects, uses, and protects your personal data when you use our services. We are committed to transparency, data minimisation, and full compliance with the EU General Data Protection Regulation (GDPR). Our policy is built around one principle: we collect only what we need to operate, we retain only as long as necessary, and we never use your data for anything beyond the purpose you gave us permission for.
Data controller
FLEECE AI SASU is the data controller for all personal data processed through Frontière AI's services. FLEECE AI SASU is a French limited liability company (SASU) registered in France, with its registered office at 10 rue Pierre Poisson, 63400 Chamalières, France. You may contact us about your data at contact@fleeceai.app.
Data we collect and why
Zero prompt retention
We do not store your prompts or responses. When you make an API call, your input is processed and the result is returned to you — both are discarded immediately after the response is sent. We do not log your prompts, we do not archive your conversations, and we do not keep them for debugging, monitoring, or any other purpose. This applies to all models, both sovereign and fast access. Your prompts are transient by design.
No data used for training
Your prompts, responses, and any data transmitted through our API are never used to train, fine-tune, or improve any model. Neither the model providers nor Frontière AI use your data for model training. Your inputs are strictly for inference — nothing more.
Data retention
We retain data only as long as necessary. Usage events (models called, tokens consumed, timestamps) are kept for billing reconciliation and are retained for 24 months after your last API call. If you close your account, usage data is retained for an additional 12 months to cover invoice validity periods, then permanently deleted. Authentication data (email, API keys) is deleted when you close your account, subject to the billing retention period above.
Your rights
Under the GDPR, you have the right to access, rectify, erase, restrict processing, and port your personal data. You also have the right to object to processing based on legitimate interest. To exercise any of these rights, contact us at contact@fleeceai.app. We will respond within 30 days. You also have the right to lodge a complaint with a supervisory authority.
To exercise your rights, contact us at contact@fleeceai.app
Third-party data sharing
We do not sell, rent, or trade your personal data. The only third parties we share data with are: Stripe, for payment processing (card data is processed entirely by Stripe and never reaches our servers); EU cloud providers (OVHcloud, Scaleway) for hosting and API inference. All subprocessors operate within the European Union under data processing agreements that comply with GDPR requirements.
Legal basis for processing
We process personal data on the following legal bases: consent (authentication via magic link), contractual necessity (provision of the API service, billing), and legitimate interest (service operation, security, and abuse prevention). Our legitimate interests do not override your fundamental rights and freedoms. We document all processing activities in our Record of Processing Activities as required by Article 30 of the GDPR.