Privacy Policy

Privacy Policy

LAST UPDATED AUGUST 26, 2026

  1. Scope

Freesolo is operated by Linkd Inc. (“Freesolo,” “we,” “our,” or “us”). Freesolo helps teams build, evaluate, train, and deploy AI models and AI features. This Privacy Policy explains how we process information through Freesolo websites, applications, APIs, model training, hosted inference, support, billing, analytics, and related services.

If you use Freesolo through a company or other organization, that organization may control the Customer Content submitted to the service and access to its workspace.

When Freesolo processes personal data in Customer Content on a customer's documented instructions, the customer generally determines the purpose and means of processing and Freesolo acts as a processor or service provider. For account administration, service security, billing, product operations, and Freesolo's own business records, Linkd Inc. may act as a controller or business.

Use of the service is also governed by the Terms of Service (https://freesolo.co/terms). This Privacy Policy states the privacy, inference-data, disclosure, retention, deletion, security, and rights information applicable to the service.

  1. Information we process

Account and organization information

We process identifiers and account information such as name, email address, user identifier, organization membership, organization role, authentication events, preferences, invitations, and account settings.

Customer Content

Customer Content includes information submitted to, generated through, or stored in the service, including prompts, messages, responses, images, tool definitions and calls, traces, datasets, evaluations, reward logic, environment code, support messages, and related metadata.

Customer Artifacts

Customer Artifacts include customer-specific adapters, checkpoints, evaluations, reward logic, environment code, and deployment metadata created, uploaded, or managed through the service.

Inference and trace data

The default Freesolo recording proxy stores complete request payloads after sanitization unless the caller sends X-Freesolo-Record: false. Non-streamed responses may be complete after sanitization. Streamed output is reconstructed from observed choices and usage and may be partial, especially on disconnect. Sanitization targets recognized credential fields and literal credential values. It does not remove ordinary confidential or personal content.

First-party hosted Flash uses synchronous engine.generate.remote.aio invocations whose inputs and outputs are not retained after result delivery. Operational logs, Modal settings and evidence, asynchronous calls, artifacts, and the complete production path have not been verified as zero retention. The /api/sample route has no intentional application content persistence, but forwards content to the selected deployment endpoint. First-party Flash may run on Modal, while imported or customer-owned deployments may use other endpoint paths.

Current hosted inference is not zero data retention, or ZDR. Disabling recording prevents the Freesolo trace insert for that request, but it does not prevent the selected upstream provider, hosted runtime, network service, or operational system from processing or retaining request content. A request using OpenRouter provider.zdr=true and provider.data_collection="deny" together with disabled Freesolo recording is only potentially request-specific and is not an advertised ZDR endpoint without verification of the exact endpoint and operational path.

Usage and technical information

We process logs, request times, network and device information, browser information, error details, security events, API key metadata, project and organization identifiers, model and provider identifiers, pages visited, product usage events, performance metrics, API request metadata, and similar diagnostic and service-interaction information.

Serving usage records may include token counts, cached-token counts, GPU seconds, request identifiers, deployment identifiers, replica identifiers, base model identifiers, and adapter or organization identifiers. These usage records are not designed to contain prompt or output content.

Billing information

We process prepaid balances, estimates, usage charges, ledger entries, corrections, payment status, transaction identifiers, and limited payment-method metadata. Payment-card details are handled through Stripe rather than being intentionally stored by Freesolo.

Analytics

We use PostHog for product analytics and error reporting when configured. PostHog is configured to US ingestion. PostHog session replay is disabled.

Cookies, local storage, and similar technologies

We use cookies to authenticate users, maintain sessions, preserve certain interface choices, and protect sign-in and account-recovery flows. We use browser local storage to remember walkthrough progress and preserve in-progress training drafts and intake state. We also use analytics technologies to measure site and product usage and report errors. Browser settings may allow you to control some of these technologies, but disabling them may prevent authentication or other features from working as intended.

Support information and staff access

We process support conversations, account context, diagnostic information, and related communications. Staff may access Customer Content for support and administration, and current staff membership is broad. We do not represent that all staff access is time-bound, customer-approved, read-only, or covered by a complete access-audit trail.

  1. Why we process information

We process information to:

• provide, authenticate, operate, and secure the service;
• route and record inference when requested or enabled by default;
• perform customer-requested training, evaluation, deployment, and sampling;
• create, store, and deliver Customer Artifacts;
• meter usage, calculate charges, reconcile billing, prevent duplicate charges, and process payments;
• provide support and administer organizations;
• detect abuse, investigate incidents, and enforce the Terms of Service (https://freesolo.co/terms), including its use restrictions;
• analyze reliability and product use;
• communicate service and account information; and
• comply with legal obligations and protect rights and safety.

Where applicable, processing may rely on performance of a contract, legitimate interests, consent, compliance with law, or another lawful basis. Customers are responsible for identifying an appropriate lawful basis for personal data they direct Freesolo to process as Customer Content.

  1. Generalized model training

We do not use Customer Content for generalized model training without the customer's affirmative opt-in.

Customer-requested training that creates Customer Artifacts for that customer is not generalized model training.

  1. How information is disclosed

We may disclose information:

• to infrastructure, database, hosting, inference, GPU, analytics, communication, repository, payment, and security vendors that support the service;
• to OpenRouter and downstream model providers selected by routing or configuration;
• to organization owners, members, and authorized staff according to service access controls;
• in connection with a corporate transaction, subject to appropriate protections;
• when required by law or valid legal process; and
• to protect the service, customers, users, or the public.

Service providers may include Supabase, Modal, PostHog, OpenRouter and downstream model providers, Hugging Face, Stripe, Resend, GitHub, secret-management services, frontend hosting, Microsoft Azure or another backend host, and active GPU providers. The exact provider entity, product, region, transfer mechanism, data scope, and retention can vary by account, route, and configuration and are not fully verified for every production path.

We do not describe Customer Content as sold for money. Certain privacy laws may define sale, sharing, targeted advertising, or cross-context behavioral advertising differently. Contact us if you have a question about how those definitions apply to your information.

  1. Regions and international processing

Freesolo operates from the United States, and information may be processed in the United States and other countries where Freesolo or its service providers operate.

Current processing regions are not fully controlled:

• the Freesolo backend is evidenced in Azure Virginia;
• Modal ingress defaults to Virginia;
• Modal GPU placement is unconstrained;
• the Supabase region has not been verified;
• OpenRouter and downstream provider regions vary or may be unknown; and
• PostHog is configured to US ingestion.

We do not currently promise fixed data residency. International-transfer requirements, provider regions, and applicable transfer mechanisms remain unverified for some routes and providers. We will identify a contract or other lawful transfer mechanism for a route only after it has been verified for that processing.

  1. Retention

The only verified current fixed retention period is:

Training-agent logs: 90 days

Completed synchronous Modal hosted-inference invocation inputs and outputs are not retained after result delivery. Retention for asynchronous Modal calls, operational logs, volumes, images, and other artifacts is not verified. Other current retention periods are unspecified unless a separate customer agreement or verified service setting states otherwise. In particular:

• no trace cleanup schedule is currently implemented;
• no current cleanup schedule exists for serving usage rows;
• account, organization, project, dataset, evaluation, adapter, checkpoint, deployment, billing, analytics, support, and repository retention varies by system and is currently unspecified; and
• provider-side retention depends on the actual provider, account, route, and configuration.

We do not promise a fixed deadline for deletion from active systems or backups. We may retain information when required for security, fraud prevention, billing disputes, legal compliance, or preservation of legal claims.

  1. Deletion and termination

Deletion is multi-system, asynchronous, and not immediate. Organization teardown attempts to remove database records and out-of-band resources such as Stripe customer state, storage objects, and hosted serving adapters. Current teardown is best-effort. Individual steps can fail, signed upload windows and race conditions can leave objects, and some provider artifacts may persist after the primary organization row is removed.

Customers should contact founders@freesolo.co for deletion requests and identify the organization, project, routes, artifacts, and providers involved. We may need to verify identity and authority before acting.

  1. Security

We use technical and organizational measures intended to protect the service. Security depends on application code, deployed configuration, database policy, provider configuration, credentials, and operational practice. We do not guarantee that the service is secure or that every active vendor, storage system, backup, internal path, or provider configuration has the same controls.

Staff currently may access Customer Content for support and administration. Current staff membership is broad. Access is intended for legitimate support, security, reliability, billing, legal, and administrative needs, but we do not claim stronger access controls than those actually implemented.

We do not claim SOC 2, ISO, HIPAA, PCI, penetration-testing, fixed data residency, 24/7 staffing, or an uptime commitment unless separately stated in an executed agreement.

  1. Your choices and rights

Depending on law and context, individuals may have rights to request access, correction, deletion, restriction, objection, portability, or withdrawal of consent. When Freesolo processes Customer Content for a customer, requests should generally be directed to that customer first. We provide reasonable assistance as required by applicable law and any separately executed agreement.

You may:

• disable recording for an eligible proxy request using X-Freesolo-Record: false;
• choose provider settings where supported;
• manage organization membership and project data through available product controls; and
• contact us about a privacy request.

We may request information needed to verify identity, authority, organization, and request scope. We will not discriminate against an individual for exercising an applicable legal right.

  1. Children and regulated data

The service is not intended for children. Customers must not submit children's data, protected health information, cardholder data outside Stripe, biometric data, classified information, or export-controlled technical data unless a signed addendum expressly permits the category and required controls are in place.

Customers are responsible for providing required notices, obtaining required consents and rights, minimizing personal and confidential data, and using the service in compliance with applicable law and the Terms of Service (https://freesolo.co/terms).

  1. Changes

We may update this Privacy Policy to reflect product, provider, legal, or operational changes. The updated policy will show a new last-updated date and effective date. We will provide additional notice when required by applicable law.

  1. Contact

General privacy and service inquiries may be sent to:

Linkd Inc.
1031 Jackson Street
San Francisco, California 94133
founders@freesolo.co