Privacy Policy
Last updated: August 13, 2026
Corion Intelligence LLC (“Corion AI,” “we,” “us,” or “our”) operates the Corion AI API gateway and related services (collectively, the “Services”). This Privacy Policy explains how we collect, use, disclose, and retain personal data when you visit our website, create an account, or use the Services.
This policy does not apply to third-party websites or model providers that we do not control. Those third parties are subject to their own privacy notices, terms, and data handling practices.
1. Scope and roles
Depending on how you use the Services, Corion AI may act as a data controller, business, processor, or service provider. When we administer accounts, billing, security, and our website for our own purposes, we act as a controller. When an enterprise customer routes its own data through the Services, we may act as a processor or service provider on that customer's behalf, and the customer is responsible for any required notices or consents to end users.
2. Personal data we collect
Depending on how you interact with the Services, we may collect:
- Account and contact information, such as your name, email address, and account identifiers.
- Commercial and billing information, such as prepaid balance history, transaction records, invoices, and payment verification data. Payment card details are processed by our payment processors rather than by us.
- Technical, device, and usage information, such as IP address, browser type, API key identifiers and prefixes, token counts, selected model identifiers, request volume, latency, error logs, and authentication events.
- Support and communications information, such as the contents of emails, tickets, and feedback you send us.
- Customer Content, such as prompts, instructions, files, and generated content that you submit to or receive from the Services, as described in Section 5.
- Cookies and similar technologies, as described in Section 11.
3. How we collect personal data
- Directly from you when you create an account, contact us, or purchase credits.
- Automatically through server logs, cookies, and similar technologies.
- From your organization or account administrator where access is provisioned for you.
- From third parties such as payment processors, where permitted by law.
4. How we use personal data
We use personal data to:
- Provide, operate, maintain, and improve the Services.
- Create and manage accounts, credentials, API access, and prepaid balances.
- Route requests, process payments, and provide billing and invoicing.
- Communicate with you about your account, support, and service updates.
- Analyze usage, performance, reliability, and abuse signals.
- Protect against fraud, abuse, unauthorized access, and security incidents.
- Comply with legal obligations and enforce our Terms of Service.
5. Customer Content handling
The Corion AI service is an API gateway. Customer Content passes through our gateway and one or more upstream inference providers to fulfill your requests. Corion applies a consistent privacy and security posture across our own systems:
- No training on user data. Corion does not use your prompts or outputs to train, fine-tune, or improve any general-purpose model.
- No storage by default. Prompts and responses are processed transiently and purged after the response is delivered. We do not write the content of prompts or responses to persistent application logs, disks, or databases unless you opt in to logging or support, retention is necessary to investigate abuse or a security incident, or retention is required by law.
- Identity shielding. Where technically feasible and operationally appropriate, we minimize the disclosure of end-user identity data to upstream providers by routing requests under Corion credentials and withholding user-identifiable metadata.
We may process limited metadata such as token counts, timestamps, latency, model identifiers, and billing records for billing, analytics, security, and support purposes, even where prompt text is not retained. Upstream providers process Customer Content under their own terms and privacy practices; you are responsible for reviewing whether a given model or provider is appropriate for your use case.
6. How we disclose personal data
We may disclose personal data to:
- Upstream inference providers, as necessary to serve your requests.
- Service providers, including hosting and infrastructure providers such as Vercel, Supabase, Railway, and Cloudflare.
- Payment processors, such as Stripe, to process transactions.
- Enterprise customers or account administrators, where you use the Services through an organizational account.
- Legal and safety parties, where we believe in good faith that disclosure is necessary to comply with law, enforce our rights, or protect safety and security.
- Transaction counterparties, in connection with a merger, acquisition, or similar corporate transaction.
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.
7. Legal bases (EEA, UK, Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on one or more of the following legal bases: performance of a contract, compliance with legal obligations, our legitimate interests (such as operating and securing the Services and preventing fraud), and your consent where required by law.
8. International transfers
The Services are hosted in the United States, and personal data may be processed in other jurisdictions where our service providers operate. Where required by law, we use appropriate safeguards for cross-border transfers.
9. Data retention
We retain account, billing, and usage data for as long as your account is active and as needed to operate the Services, comply with legal obligations, and resolve disputes. Prompts and responses are not stored by default, except as described in Section 5.
10. Security
We use commercially reasonable administrative, technical, and organizational safeguards, including encryption in transit using TLS, access controls, and audit logging. No method of transmission or storage is completely secure, and you are responsible for protecting your credentials.
11. Cookies and similar technologies
We use session cookies to keep you signed in and remember your language preference, and we use Vercel Analytics and Vercel Speed Insights for anonymized, aggregated traffic and performance data. You can control cookies through your browser settings.
12. Your rights and choices
Depending on your jurisdiction, you may have the right to request access to, correction of, deletion of, or a copy of your personal data, and to object to or restrict certain processing. To exercise these rights, contact support@corion.ai. We may need to verify your identity and may deny or limit a request where permitted by law.
13. U.S. state privacy disclosures
For residents of California and other states with applicable privacy laws, we may collect identifiers and contact information, commercial and transaction data, internet or network activity, approximate location from IP address, professional information, support records, and Customer Content where you submit it. We disclose these categories to the recipients described in Section 6 for the purposes described in this policy. We do not sell personal data for money or share it for cross-context behavioral advertising.
14. Children
The Services are not intended for individuals under 18, and we do not knowingly collect personal data from children under 18.
15. Regulated data
Do not submit regulated, export-controlled, secret, or personal data to the Services unless you have an applicable data-processing agreement in place for your workload.
16. Changes
We may update this policy from time to time and will post the revised version with a new “Last updated” date. Where required by law, we will provide additional notice.
17. Contact
For questions or to exercise your rights, contact support@corion.ai or write to:
Corion Intelligence LLC
4201 Main Street, Ste 200
Houston, TX 77002
