Effective date: April 22, 2026
Totally Private AI ("TPAI," "we," "us") provides air-gapped AI infrastructure for regulated industries. Our platform is designed to minimize personal data, permit no internet egress from the AI environment, and encrypt all user content on a per-user basis. We pseudonymize user identity before it enters the platform, and we retain only the limited operational metadata necessary to run the service.
With respect to user content (prompts, responses, and uploaded files), TPAI acts as a data processor on your behalf. You (or your organization) remain the data controller. TPAI is the data controller only for its own operational data (usage metadata, billing records). If you use Pro as an individual professional, you are the controller for the content you submit. A Data Processing Addendum (DPA) is available for download at totallyprivate.ai/dpa for Pro subscribers and is included in Enterprise Master Services Agreements.
This policy explains what data we collect, why, and how we protect it. If you have questions, contact us at privacy@totallyprivate.ai.
When you subscribe to Totally Private AI, we collect the information necessary to process your payment. Payment processing is handled by Stripe, Inc., our third-party payment processor. Stripe collects and processes your payment card details, billing address, and email address under their own privacy policy. We do not store credit card numbers on our infrastructure.
We receive from Stripe a confirmation of your subscription status, a customer identifier, and your email address for the purpose of provisioning your account. Your email address is pseudonymized using a hardware-backed cryptographic function before it enters the air-gapped AI environment. The pseudonym, not your email address, is the identifier used within the platform.
When you use Totally Private AI, your prompts and the AI model's responses are encrypted with a key unique to your user account and stored within the air-gapped environment. Prompt and response content is processed within the deployment boundary and is not transmitted to the public internet. Within the boundary, AWS Bedrock processes your prompts to generate responses over private endpoints. AWS Bedrock does not use customer inputs or outputs to train models (per AWS Bedrock service terms) and processes inference within the configured deployment boundary.
On Pro (our managed SaaS tier), this data is stored in the TPAI-managed air-gapped environment. On Enterprise, it is stored in your organization's own cloud account. On the API tier, prompts and responses are processed in real time and not stored in the application database; only usage metadata is retained.
We collect operational metadata necessary to run the service: timestamps of requests, model identifiers used, token counts, and error codes. This metadata does not include the content of your prompts or responses. It is used for platform monitoring, capacity planning, and billing. IP addresses may appear in infrastructure logs (such as load balancer and VPN logs) and are treated as personal data where applicable law requires.
On the Pro tier, you connect to the platform via a certificate-authenticated VPN. We log connection timestamps and connection duration for security monitoring. We do not log the content of your network traffic beyond what is described above. Enterprise customers connect through their own network infrastructure (typically Direct Connect); connection logging for Enterprise is governed by the applicable Master Services Agreement.
We do not use cookies for tracking, advertising, or analytics. We do not embed third-party analytics services (no Google Analytics, no Mixpanel, no tracking pixels). We do not serve ads. We do not sell, rent, or share your data with advertisers or data brokers. We do not build profiles of your behavior. We do not use your prompts or responses to train, fine-tune, or improve any AI model.
The AI environment has no internet gateway, no NAT gateway, and no route to the public internet. All cloud service communication occurs over private endpoints on the provider backbone. Your data cannot leave the boundary because there is no path out.
Every user's data is encrypted with a unique encryption key. On Pro, keys are managed in AWS KMS within the deployment boundary; access is restricted and audited. TPAI does not access chat content under normal operations. On Enterprise, your organization owns and controls the encryption keys, and TPAI cannot decrypt your data.
On Enterprise deployments, no one at Totally Private AI has persistent access to your production environment. Emergency access requires a documented request, multi-factor authentication, your approval, and expires automatically. On Pro, TPAI operators can maintain the platform infrastructure without accessing your encrypted chat data.
AWS Bedrock, the model provider, does not use customer prompts or completions for model training. Your prompts and responses do not become part of any model's training data.
We use a limited number of third-party services, and each is scoped as narrowly as possible:
We do not send platform data to third-party analytics, telemetry, SIEM, or advertising services. Operational monitoring and support tooling are self-hosted within our infrastructure. If we add any third-party service that receives platform data in the future, we will update this policy and notify active subscribers.
The totallyprivate.ai marketing website (the pages you are reading now) is a static site. It does not set tracking cookies, does not use analytics services, and does not collect personal information unless you voluntarily contact us by email or schedule a call through Calendly.
Your chat data is retained for as long as your subscription is active. On cancellation, your encrypted data is retained for 30 days to allow for reactivation, then permanently deleted. Because the data is encrypted with a per-user key, deletion of the key renders the data irrecoverable.
Stripe retains billing data in accordance with their own retention policies and applicable financial regulations.
Beta participants: During the beta period, we retain your email address in cleartext outside the air-gapped environment for the purpose of providing support and collecting feedback. At general availability, retained email addresses will be pseudonymized or deleted in accordance with our standard data handling practices.
Default retention windows for the Pro tier: usage metadata (timestamps, token counts) is retained for up to 90 days; VPN connection logs and infrastructure logs (including VPC flow logs) are retained for up to 30 days; audit trail logs are retained for up to 30 days. These defaults may be adjusted for security or compliance requirements. Enterprise customers control their own log retention policies.
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal data. Because TPAI is designed to hold minimal personal data (your email is pseudonymized, your chat data is encrypted per-user), many of these rights are satisfied by the architecture itself.
To exercise any data rights, contact privacy@totallyprivate.ai. We will respond within 30 days.
If you are in the EU, you have rights under the General Data Protection Regulation including access, rectification, erasure, data portability, and the right to object to processing. Our lawful basis for processing is contractual necessity (providing the service you subscribed to) and legitimate interest (platform security and operational monitoring).
If you are a California resident, you have the right to know what personal information we collect, to request deletion, and to opt out of the sale of personal information. We do not sell personal information.
The Pro environment currently operates in a single AWS region. We publish the current hosting region on our Security page (or contact privacy@totallyprivate.ai). Additional regions are planned; when we add regions, we will update this policy. We do not transfer user content across regional boundaries. If you are located outside the region where your data is hosted, your data is transferred to and processed in that region. For Enterprise deployments, the environment is deployed in the AWS region of your choice, and data residency is determined by your configuration.
Totally Private AI is designed for professional use in regulated industries. The Service is intended for users who are at least 18 years old. We do not knowingly collect data from children under 13, or under 16 where applicable law requires a higher age threshold. If you believe a child has provided us with personal data, contact privacy@totallyprivate.ai and we will delete it.
Professionals (such as therapists, attorneys, or healthcare providers) may process information about minors as part of delivering their own services. The age restriction above applies to account holders, not to the subjects described in professional records. You are responsible for ensuring you have the rights and consents required to process any third-party data through the Service.
We may update this privacy policy from time to time. If we make material changes, we will notify active subscribers by email at least 30 days before the changes take effect. The effective date at the top of this page reflects the most recent revision.
For privacy-related questions or requests:
Totally Private AI
Email: privacy@totallyprivate.ai
Security: totallyprivate.ai/security