Privacy Policy
Version: 2.0
Last Updated: @August 22, 2025
Privacy Policy Sections
Introduction and Scope
This Privacy Policy explains how Sentient Labs Pte. Ltd. (“Sentientˮ, “weˮ, “ourˮ or “usˮ) collects, uses, and discloses personal information when you use our applications, websites, and services (collectively, the “Servicesˮ). We are committed to protecting your privacy and complying with applicable data protection laws. For the purposes of data protection law, Sentient is the data controller for personal data you provide to our Services. If you have any questions about this Policy or your rights, you can contact our Data Protection Officer at contact@sentient.xyz.
Personal Data We Collect
Information You Provide: We do not require you to provide direct identifiers such as your name, address, or phone number to use most of our Services. However, we may collect certain identifiers when necessary (for example, payment details if you subscribe to a paid service, or profile information if you choose to log in with a third-party account). Additionally, we may collect personal data that may be created automatically so that the Services work correctly and securely, this may include: IP addresses, device IDs or payment data (if you subscribe to a paid service), and any content you input into the Services (such as prompts, queries, files, or messages). If you communicate with us (e.g. for support), we will collect the information in those communications. We do not intentionally collect sensitive personal data (such as race, health, or biometric data) unless you choose to provide it, and we ask that you not upload sensitive data into our AI or blockchain features without necessity.
Information Collected Automatically: When you use our website or app, we and our third-party analytics providers may automatically collect certain technical data about your visit. This includes your IP address, browser type, device identifiers, pages or screens viewed, date/time of access, and referral links. We use cookies or similar tracking technologies to gather usage statistics and to improve user experience (see our Cookie Policy for details). This data may qualify as personal data under some laws, and if so, we treat it in accordance with those laws. We do not use this data to identify you by name, and we do not allow third parties to use it for their own marketing.
Information from Third Parties: If you choose to link a third-party account to Sentient (for example, signing in via Google or using a crypto wallet), we may receive basic profile or account information from that third party with your consent. We ensure any such data sharing is subject to your control and in line with this Policy.
How We Use Personal Data
Service Delivery: We use your personal data to operate and provide the Services’ functionality. For example, we process your Inputs to generate AI Outputs (this inherently involves handling the content of your prompts) and use your account data to authenticate you and manage your account. Payment information is used to process subscription fees or purchases.
Service Improvement and AI Training: We may use the content you provide (your prompts and outputs) to train, test, and improve our AI models and algorithms unless you have opted out of such use. Training on user data allows us to enhance model accuracy and develop new features. Where possible, we de- identify or aggregate data used for improvement to protect your privacy. (If you opt out or are a paid enterprise user, your content will not be included in training datasets, per our Terms.)
Compliance and Safety: We process personal data as required to comply with legal obligations, such as financial record-keeping or responding to lawful requests by authorities. We also may process data to enforce our Terms of Service and usage policies – for instance, monitoring for abuse of the platform. This includes using automated tools to detect prohibited content (which may involve scanning inputs/outputs for policy violations). If necessary, we will use or disclose data to investigate fraud, security incidents, or other illegal activities, or to protect the rights, property, or safety of Sentient, our users, or the public
Communications: If you provide contact information, we may use it to send you service-related notices such as important announcements or support responses. With your permission, we may also send marketing communications about new features or products; you can opt out of marketing at any time.
Blockchain Specific Usage: If our Service involves writing certain data to a blockchain (e.g. recording a transaction or verification), we will use the minimum data necessary (often just a hash or an identifier) and the data will become a permanent part of the public ledger. This usage is inherent to the Service’s decentralized functionality, and by using those features you are asking us to record that data on the blockchain on your behalf.
Legal Bases for Processing (for EU Users)
If you are in a jurisdiction that requires a legal basis for processing personal data, we process your information under the following bases: Contractual Necessity – to provide you the Services as per our Terms (Article 6(1)(b) GDPR); Legitimate Interests – for improving our AI, ensuring security, and customer service (Article 6(1)(f)), but we perform a balance test and offer opt-outs where needed (for example, we rely on legitimate interest for model training on user data, balanced against your privacy rights – and we provide an opt-out to respect individual choice); Legal Obligation – to comply with laws (Article 6(1)(c)); and Consent – where we explicitly ask for your consent, such as for improving our AI, sending promotional emails or for collecting certain analytics cookies (Article 6(1)(a)).
Where we process sensitive data (which we generally do not intend to), we would do so only with your explicit consent or if otherwise lawfully permitted.
Disclosure of Personal Data
We do not sell your personal information to third parties. We also do not share it with third parties for their own advertising purposes. We may disclose personal data in the following cases:
Service Providers: We use trusted third-party service providers to help us operate the Service – for example, cloud hosting providers, payment processors, analytics services, or email service platforms. These parties process data on our behalf and are contractually obligated to safeguard it and use it only for the services they perform for us.
Affiliates: We may share data with subsidiaries or affiliates of Sentient, for purposes consistent with this Policy (e.g., a related R&D team improving the AI). All such entities follow equivalent privacy protections.
Business Transfers: If Sentient is involved in a merger, acquisition, bankruptcy, or sale of all or a portion of its assets, personal data may be transferred to the successor entity. We will ensure the new owner honors the commitments we have made in this Policy or provide notice if terms change.
Legal and Safety: We may disclose your information if required to do so by law or in response to a valid legal request (e.g., a subpoena or court order). We may also disclose data if we believe in good faith that it is necessary to (a) comply with a legal obligation, (b) protect and defend the rights or property of Sentient, (c) prevent fraud or abuse of our Services or users, or (d) protect the personal safety of users or the public. For example, if compelled by law enforcement regarding illegal content generated or stored, we will comply after verifying the requestʼs legality.
With Consent: We will share your personal data with third parties outside of the above scenarios only with your consent. For instance, if you opt in to a beta integration that sends your data to an external application, we will do so only with your approval and clearly inform you beforehand.
Data Security
Security Measures: We employ appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. This includes encryption of data in transit (e.g., TLS for our website) and at rest where applicable, regular security audits, restricted access controls, and employee training on data protection. We also implement measures such as firewall protections, intrusion detection, and anonymization/pseudonymization techniques as appropriate. Our security program is aligned with industry standards and is periodically reviewed for enhancements.
No Guarantee: However, please note that no method of transmission or storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security. You use the Service and provide personal data at your own discretion and risk. In the event of a data breach that affects your personal data, we will notify you and the relevant authorities as required by law.
Account Security: You are responsible for maintaining the confidentiality of your account login credentials and for any actions taken under your account. Please use a strong, unique password and limit access to your devices. If you believe your account has been compromised, contact us immediately.
Data Retention
We retain personal data for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law. For example, we may retain your account information while your account is active and for a reasonable period thereafter in case you decide to reactivate, or to comply with legal obligations (such as retaining transaction records for financial regulations). AI training data derived from your content may be retained to improve our models, but if you delete your account or opt out, we will cease using new data from you for training and will delete or anonymize personal identifiers associated with past content where feasible. We will not continue to use personal data for model training once you delete your account or opt out.
On blockchain: Any data recorded on a public blockchain through your use of our Service (such as transaction data) may be permanently retained on the blockchain. We cannot delete or modify such data – it will remain as part of the distributed ledger in accordance with the design of the blockchain. Where possible, Sentient will minimize personal data in blockchain transactions (e.g., by using hashed values or pointers). Off-chain copies of blockchain data (in databases we control) will be subject to standard retention and deletion protocols. When we no longer have a lawful basis or business need to retain your personal information, we will securely delete it or anonymize it in accordance with applicable laws.
International Data Transfers
Sentient is based in Singapore but we operate globally. Your personal data may be transferred to and processed in countries other than your own, including the United States and countries in the European Economic Area EEA. We rely on appropriate legal mechanisms for international transfers. If you are in the EEA, we ensure transfers outside the EEA are governed by EU Standard Contractual Clauses or that we otherwise implement adequate safeguards. If in the UK, we ensure it complies with the IDTA and/or UK addendum to the SCC. We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Policy wherever it is processed.
Your Rights and Choices
Access, Correction, Deletion: You have the right to request access to the personal data we hold about you, to correct any inaccuracies, and to request deletion of your data, subject to certain exceptions allowed by law. You can review and update much of your basic account information by logging into your account settings. If you need assistance or wish to exercise your data rights, please contact us at contact@sentient.xyz. We will respond to your request within the timeframe required by law (typically within 30 days).
Please note: we cannot modify or delete data written to a public blockchain as part of the Services. Where possible, we minimize personal data recorded on- chain, but such data may be permanently stored outside our control.
Data Portability: You have the right to obtain a copy of the personal data you provided to us in a common portable format, to the extent applicable (this applies to data we process on the basis of your consent or contract).
Withdrawal of Consent: Where we rely on your consent for processing, you have the right to withdraw consent at any time. Your profile with Sentient will allow you the option to stop collection of your data at any time. Note that withdrawing consent does not affect the lawfulness of processing performed before withdrawal.
Opting Out of Data Use for AI Training: As noted, you can opt out of the use of your content for AI model training/improvement. This can be done in your account privacy settings or by contacting support. Once opted out, we will stop using your future inputs for model improvement.
California Privacy Rights: If you are a California resident, you have specific privacy rights under the CCPA/CPRA, including the right to know what personal information we collect, the right to delete personal information (with similar exceptions), and the right to opt out of “sale” or “sharing” of personal information. Sentient does not sell personal data or share it for cross-context behavioral advertising. You also have the right not to receive discriminatory treatment for exercising your rights. To make a request under CCPA, you can use the contact methods above. We may need to verify your identity before fulfilling your request (for instance, by having you log in or provide information we have on file). You may also designate an authorized agent to make a request on your behalf by providing us with a valid power of attorney or written authorization, and we will also verify the agent’s identity.
EU/UK Privacy Rights: In addition to access, correction, deletion, and portability, if you are in the EU or UK you have the right to object to certain processing or request we restrict processing of your data in certain circumstances. For example, you may object to processing that we undertake based on legitimate interests. If you do so, we will evaluate your request and will stop or limit processing unless we have compelling legitimate grounds to continue or as otherwise permitted by law. Where applicable, you also have the right to file a complaint with your supervisory authority (e.g., your country’s Data Protection Authority or the UK Information Commissioner’s Office) if you believe our processing violates the law. We ask that you kindly contact us first so we can address your concerns directly.
Children’s Privacy
Our Services are not intended for individuals under 16 in the EU/UK and under 13 in the United States (or the minimum digital consent age in your jurisdiction). We do not knowingly collect personal data from children. If you are under the legally permissible age in your jurisdiction please do not use the Service or provide any personal information. If we learn that we have inadvertently collected personal data where not permitted, we will promptly delete such data. Parents or guardians who believe that their child may have provided us personal information can contact us to request deletion.
Cookies and Tracking Technologies
What Are Cookies?
Cookies are small text files placed on your device by a website. They help us recognize your device, enable core functionality, enhance security, and improve your experience. Some cookies are essential for the website to function properly, while others are used for analytics and performance.
Types of Cookies We Use
- Strictly Necessary Cookies
These cookies are essential for you to browse the website and use its features. Without them, the website may not function properly.
_ct_bm (Cloudflare) - Used by Cloudflare bot products to distinguish between humans and bots.
_cfwaitingroom (Cloudflare) - Used to manage traffic and maintain website availability during high traffic periods.
_cf_clearance (Cloudflare) -** Ensures that the Cloudflare bot protection system works properly after a user successfully completes a challenge.
__Host-next-auth.csrf-token (Sentient) - A CSRF Cross-Site Request Forgery) token that protects login requests from malicious attacks. This value is unique to each login request and not persisted or associated with the user.
__Secure-next-auth.callback-url (Sentient) - Stores the callback URL for login purposes.
__Secure-next-auth.session-token (Sentient) - A JWT session token used after login. The token contains limited information (email, name, picture, and standard JWT metadata such as by the authentication library.
- Analytics and Performance Cookies
These cookies allow us to collect information about how visitors use our site, which helps us improve performance and user experience. We will specifically ask you to opt-in to allow the use of any anyltics and performance cookies before they are distributed.
**_ga (Google Analytics)**Used to distinguish users for site analytics.
**_ga_K6FD7HCERD (Google Analytics)**Persists session state for analytics tracking.
How We Use Cookies
We use cookies to:
Ensure security and integrity of our authentication process.
Distinguish legitimate traffic from bots and protect against attacks.
Maintain session state and login functionality.
Understand how users interact with our website to improve performance and usability.
We do not use cookies for targeted advertising.
Your Choices
You can control cookies through your browser settings, where you may choose to block or delete cookies. Please note, if you disable certain cookies, some features of our site may not function properly.
For information on how to manage cookies, visit:
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. If we make material changes, we will notify you by prominently posting a notice on our website or within the app, or by sending you a notification (e.g., via email) where required by law. The “Last Updated” date at the top of this Policy will indicate when the latest changes were made. We encourage you to review this Policy periodically to stay informed about how we are protecting your information. Your continued use of the Services after any update indicates your acceptance of the revised Policy, to the extent permitted by law.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us at:
Email: contact@sentient.xyz
We will happily address your inquiries and work with you to resolve any concerns.