Privacy policy

What we collect, what we don’t, and why.

Effective April 22, 2026

This Privacy Policy describes how GeniusPro, LLC (“GeniusPro,” “we,” “our”), a Montana limited liability company, collects, uses, retains, and shares personal data when you access geniuspro.io, the api.geniuspro.io API, the platform dashboard, our documentation, or any other GeniusPro service that links to this policy (collectively, the “Services”).

The controls described here are paired with the technical posture at /security. Rules for AI agents reading our public content live at /ai-usage. Terms of use for the Services live at /terms.

Commitments

What we will always do

  • Never train AI models on your prompts or completions.
  • Scrub PII from operational logs by default.
  • Offer opt-in edge PII scrubbing before upstream routing.
  • Honor deletion, access, and correction requests.
  • Use electronic notice for any material policy change.
Boundaries

What we will never do

  • Sell personal data to advertisers or data brokers.
  • Use your content to train foundation models.
  • Publish the street addresses of our customers or vendors.
  • Retain request content longer than 30 days in logs.
  • Share data with third parties beyond what this policy describes.
Who we are

Who is the data controller?

GeniusPro, LLC, a Montana limited liability company, is the controller for personal data collected through the Services. Formal notices and privacy requests are delivered electronically to privacy@geniuspro.io.
Collection

What personal data do we collect?

Five categories, each collected for the purpose described in the next section.
  • Account data. Name, email, company name, and any notes you submit when requesting an invite or signing in to the platform.
  • Billing data. Processed by our payment provider. We receive a customer ID, billing email, and invoice-level totals; we do not store full card numbers on our systems.
  • API usage metadata. Request IDs, timestamps, token counts, model routing decisions, latency, and status codes — used for billing, rate limiting, and debugging.
  • Request content. Prompts you send and completions we return, retained only for operational debugging and abuse investigation. PII is scrubbed from these logs by default.
  • Technical data. IP address and user agent, recorded for security, rate limiting, and abuse prevention.
Purpose

How do we use personal data?

To operate the Services you requested. Specifically: to provision and authenticate your account; to route each API request to the appropriate upstream model provider; to invoice and collect fees; to prevent fraud, abuse, and violations of our acceptable use rules; to respond to your support requests; and to comply with legal obligations. We do not use your prompts or completions to train, fine-tune, or distill any AI model.
Sharing

Who do we share data with?

Four categories. We do not sell personal data, and we do not share personal data with advertisers or data brokers.
  • Model providers. Hyperscaler-hosted AI model endpoints that fulfill each request. Only the prompt content and parameters required to serve your request are transmitted. Upstream providers are configured for no-training where the route supports it.
  • Infrastructure vendors. Hosting, database, logging, and transactional-email providers under contractual confidentiality obligations.
  • Payment processor. For billing, invoicing, and fraud prevention.
  • Legal and safety. When required by law, court order, or to protect the rights, property, or safety of GeniusPro, our customers, or the public.
Vendor names are disclosed in onboarding materials, security questionnaires, and under NDA rather than on this public page.
Retention

How long do we keep data?

  • Request content in logs: up to 30 days, then deleted. PII is scrubbed from these logs by default.
  • Account data: for the duration of the customer relationship. After account closure, retained only as required for tax, billing, regulatory, and anti-abuse purposes (typically up to seven years).
  • API keys: stored as cryptographic hashes only, until you rotate or revoke them.
  • Billing records: retained as required by applicable tax and accounting laws.
Security

How is the data protected?

Encryption in transit (TLS 1.2+) and at rest, hashed API keys with server-side verification, short-lived request tokens, default log redaction of PII, and optional per-request edge PII scrubbing. Full technical detail at /security.
Your rights

What rights do you have, and how do you exercise them?

Where applicable under GDPR, CCPA, or similar data-protection laws, you have the right to know what we hold, access a copy, correct inaccuracies, delete your data, restrict or object to processing, port your data, and withdraw consent. GeniusPro does not sell personal data and does not engage in automated decision-making that produces legal or similarly significant effects. To exercise any right, email privacy@geniuspro.io from the address associated with your account. We will verify your identity before acting on the request and respond within the timeframe required by law.
International

Where is the data processed?

GeniusPro operates from the United States. API requests are routed to hyperscaler-hosted model providers in regions we select for availability and compliance. If you are located in the European Economic Area, the United Kingdom, or Switzerland, data transferred to the United States is protected by Standard Contractual Clauses or an equivalent transfer mechanism with our subprocessors. Email privacy@geniuspro.io for the current list of applicable mechanisms.
Children

Do you serve children?

No. The Services are not directed to children under 18 and we do not knowingly collect personal data from them. If you believe a child under 18 has provided personal data to us, email privacy@geniuspro.io and we will delete it.
Changes

How will we tell you if this policy changes?

We will update the effective date at the top of this page for any change and give at least 30 days’ prior electronic notice for material changes that reduce your rights or expand the categories of data we collect. Continued use of the Services after the effective date of a material change constitutes acceptance of the updated policy.
Contact

How do you reach us about privacy?

Email privacy@geniuspro.io for privacy questions, data-subject requests, or suspected incidents. For legal notices under the Terms of Use, email legal@geniuspro.io. All formal notices are electronic; physical mailing and registered-agent details are available on request to customers and regulators with a legitimate need.