1. Introduction & Scope
This Privacy Policy ("Policy") describes how Core Labs ("Core Labs", "we", "us", or "our"), a company organized under the laws of the Republic of Panama, collects, uses, discloses, and protects personal data in connection with Molly AI — our sovereign multi-agent AI orchestration platform, including the chat interface, Training Studio, Creative Studio, image, video, and voice generation features, the OpenAI-compatible API, SDK, and CLI (collectively, the "Services").
This Policy applies to all users of the Services, whether accessing them through our web application, API, SDK, or command-line tools. By using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, please do not use the Services.
This Policy is effective as of 16 July 2026.
2. Data We Collect
2.1 Account Data
When you register for an account, we collect:
- Email address and chosen display name or username;
- Authentication credentials (stored as salted cryptographic hashes) or federated identity tokens if you sign in via a third-party provider;
- Organization or team information, if applicable;
- Account preferences and settings.
2.2 Usage and Metering Data
To operate our prepaid token pack and subscription billing model, we collect and process:
- Token consumption per request, model, and feature (chat, Training Studio, Creative Studio, image/video/voice generation);
- API request metadata such as timestamps, endpoints called, response codes, latency, and request volumes;
- Feature usage statistics, session duration, and platform interactions;
- Technical information including IP address, browser type, operating system, and SDK/CLI version.
2.3 Payment Metadata and Wallet Addresses
Payments for token packs and annual subscription plans are processed on a prepaid basis in fiat currency or cryptocurrency (Bitcoin and EVM-compatible stablecoins). We collect:
- Transaction identifiers, amounts, currency, timestamps, and payment status;
- For fiat payments: limited payment metadata provided by our payment processors (e.g., card type, last four digits, billing country). We do not store full card numbers or CVV codes;
- For crypto payments: the sending wallet address, blockchain network, transaction hash, and confirmation status;
- Invoicing and receipt records required for accounting and tax compliance.
2.4 Privacy-Preserving Device Fingerprint (Anti-Fraud Only)
We generate a privacy-preserving device fingerprint derived from non-invasive technical signals. This fingerprint:
- Is used exclusively for anti-fraud and abuse prevention, including detecting account sharing abuse, payment fraud, duplicate free-tier accounts, and automated abuse of the platform;
- Is never used for advertising, cross-site tracking, profiling for marketing purposes, or sold or shared with third parties;
- Is stored in hashed/derived form and cannot be reversed to reconstruct your device configuration.
2.5 Content You Submit
The Services process content that you submit, including:
- Prompts, messages, and instructions sent to AI models;
- Files, datasets, and materials uploaded to Training Studio or Creative Studio;
- Generated outputs (text, images, video, audio) associated with your account;
- Custom agent configurations, system prompts, and workflow definitions.
Processing of this content is subject to our Zero Data Retention commitments described in Section 4.
3. How We Use Data
We use the data described above for the following purposes:
- Service delivery: to operate, provide, and maintain the platform, route requests to AI models, and return outputs to you;
- Billing and metering: to deduct token consumption from prepaid balances, manage subscriptions, process payments, issue receipts, and prevent billing disputes;
- Anti-fraud and abuse prevention: to detect, investigate, and prevent fraudulent payments, unauthorized access, policy violations, and platform abuse;
- Security: to secure our systems, monitor for intrusions, and protect user accounts;
- Support: to respond to inquiries submitted to [email protected] and resolve technical issues;
- Service improvement: to analyze aggregated, de-identified usage patterns and improve platform performance and reliability;
- Legal compliance: to comply with applicable laws, including tax, accounting, and anti-money-laundering obligations;
- Communications: to send transactional notices (e.g., low balance alerts, security notifications) and, with your consent where required, product updates.
We do not use your prompts, outputs, or submitted content to train our own or third-party AI models without your explicit, opt-in consent.
4. Zero Data Retention (ZDR)
Core Labs enforces a platform-wide Zero Data Retention posture with respect to third-party frontier model providers:
- No training on your data: Prompts and outputs transmitted to third-party frontier AI providers through Molly AI are not retained by those providers for model training;
- Contract-level enforcement: ZDR is enforced through binding contractual agreements with every frontier model provider integrated into the platform. Providers that do not offer contractual ZDR terms are not integrated;
- Transient processing only: Third-party providers process your prompts and outputs transiently, solely to generate responses, subject to limited legally mandated safety retention exceptions where applicable under provider terms;
- Your storage, your control: Conversation history and generated content are stored on Core Labs infrastructure only to provide the Services to you (e.g., displaying your chat history), and you may delete this content at any time.
5. Legal Bases for Processing
Where required by applicable data protection law (including the GDPR for users in the European Economic Area and the United Kingdom), we rely on the following legal bases:
- Performance of a contract: processing account data, usage/metering data, content, and payment data necessary to provide the Services you have purchased;
- Legitimate interests: anti-fraud and abuse prevention (including the device fingerprint), platform security, and service improvement using aggregated data, balanced against your rights and freedoms;
- Legal obligation: retention of transaction and invoicing records for tax, accounting, and anti-money-laundering compliance;
- Consent: optional marketing communications, non-essential cookies, and any opt-in use of your content, which you may withdraw at any time.
6. Sharing & Disclosure
We do not sell personal data. We share personal data only in the following circumstances:
- Infrastructure and model providers: cloud hosting, storage, and third-party frontier AI model providers that process data under binding contractual terms, including the ZDR commitments described in Section 4;
- Payment processors: fiat payment processors and crypto payment infrastructure providers, strictly for transaction processing;
- Professional advisers: auditors, accountants, and legal counsel under confidentiality obligations;
- Legal requirements: where disclosure is required by applicable law, court order, or lawful governmental request, or to protect the rights, safety, or property of Core Labs, our users, or the public;
- Business transfers: in connection with a merger, acquisition, or asset sale, subject to continued protection under this Policy and prior notice to you.
7. Data Retention Periods
We retain personal data only as long as necessary for the purposes described in this Policy:
- Account data: for the life of your account, and up to 30 days after account deletion to complete removal from backups;
- Conversation history and generated content: until you delete it or close your account, whichever is earlier;
- Usage and metering records: up to 24 months for billing accuracy and dispute resolution;
- Payment and transaction records: up to 7 years, as required by tax, accounting, and anti-money-laundering laws;
- Device fingerprint data: up to 12 months from last activity, or longer where linked to an active fraud investigation;
- Support correspondence: up to 24 months after resolution.
Upon expiry of the applicable retention period, data is securely deleted or irreversibly anonymized.
8. Security Measures
We implement technical and organizational measures appropriate to the risk, including:
- Encryption of data in transit (TLS 1.2+) and at rest;
- Role-based access controls, least-privilege principles, and multi-factor authentication for internal systems;
- Network segmentation, intrusion detection, and continuous security monitoring;
- Hashing of authentication credentials and device fingerprints;
- Regular security assessments, vendor due diligence, and incident response procedures;
- Contractual security obligations imposed on all subprocessors.
No system is completely secure. If we become aware of a data breach affecting your personal data, we will notify you and relevant authorities as required by applicable law.
9. Your Rights
Depending on your jurisdiction (including under the GDPR and the CCPA/CPRA), you may have the following rights:
- Access: obtain confirmation of whether we process your personal data and receive a copy of it;
- Correction: request rectification of inaccurate or incomplete data;
- Deletion: request erasure of your personal data, subject to legally mandated retention (e.g., transaction records);
- Portability: receive your data in a structured, commonly used, machine-readable format;
- Objection and restriction: object to or request restriction of processing based on legitimate interests;
- Withdraw consent: withdraw any consent previously given, without affecting the lawfulness of prior processing;
- Non-discrimination: exercise your rights without receiving discriminatory treatment;
- Complaint: lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at [email protected]. We will verify your identity and respond within the timeframes required by applicable law. Because we do not sell personal data, there is no need to submit a "Do Not Sell" request; nonetheless, we honor such requests as a matter of policy.
10. Crypto/Wallet & On-Chain Data Note
If you pay with cryptocurrency (Bitcoin or EVM-compatible stablecoins), please be aware of the following:
- Public blockchains are immutable: transactions recorded on the Bitcoin or EVM networks are publicly visible and permanent. Core Labs cannot modify, delete, or anonymize on-chain data, and deletion rights under data protection law do not extend to data recorded on public blockchains;
- Wallet linkage: we associate the sending wallet address with your account solely for payment reconciliation, refund processing where applicable, and fraud prevention;
- No custody: Core Labs does not custody your crypto assets or private keys;
- Compliance screening: wallet addresses may be screened against sanctions and illicit-activity lists as required for legal compliance.
You should treat your wallet address as pseudonymous rather than anonymous, as blockchain analysis may link addresses to identities.
11. Cookies & Local Storage
We use cookies and browser local storage as follows:
- Strictly necessary: session management, authentication, security tokens, and CSRF protection. These cannot be disabled without breaking the Services;
- Functional: storing your preferences, such as language, theme, and UI settings;
- Analytics: privacy-respecting, first-party analytics to understand aggregate usage. Where required by law, these are used only with your consent;
- Anti-fraud: signals supporting the privacy-preserving device fingerprint described in Section 2.4.
We do not use third-party advertising cookies or cross-site tracking technologies. You can manage cookies through your browser settings and, where applicable, our consent banner.
12. International Data Transfers
Core Labs is established in the Republic of Panama, and the Services rely on infrastructure and model providers located in various jurisdictions. Your personal data may therefore be transferred to and processed in countries other than your own. Where required by applicable law, we implement appropriate safeguards for such transfers, including:
- Standard Contractual Clauses (SCCs) or equivalent contractual mechanisms with subprocessors handling data of EEA/UK users;
- Transfer impact assessments and supplementary technical measures (e.g., encryption) where appropriate;
- Contractual ZDR and confidentiality obligations imposed on all providers regardless of location.
13. Children
The Services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from anyone under 18. If you are under 18, do not create an account or submit any personal data to us. If we learn that we have collected personal data from a person under 18, we will delete the associated account and data promptly. If you believe a minor has provided us with personal data, please contact us at [email protected].
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, the Services, or applicable law. When we make material changes, we will:
- Update the effective date at the top of this Policy;
- Notify you via email or an in-platform notice at least 14 days before material changes take effect, where reasonably practicable;
- Where required by law, seek your renewed consent.
Your continued use of the Services after the effective date of an updated Policy constitutes acceptance of the changes.
15. Contact
For questions, concerns, or requests relating to this Policy or your personal data, please contact us:
Core Labs, Republic of Panama.