InferenceBrake
Detection Demo Pricing
Sign In Get Started

Privacy Policy

Last updated: March 2026

1. Introduction

InferenceBrake is operated by Vincent Mathis, Loni-Franz-Straße 14, 65510 Idstein, Germany ("we", "us", or "our"). This Privacy Policy explains how we collect, use, and safeguard your data when you use InferenceBrake.

We are subject to the EU General Data Protection Regulation (GDPR). The responsible controller within the meaning of the GDPR is the operator listed above.

2. Data We Collect

Account Data

When you register, we collect:

  • Email address
  • Password (stored as a bcrypt hash — never readable by us)
  • Account creation date and selected plan

Legal basis: Art. 6(1)(b) GDPR — necessary to perform the contract with you.

API Usage Data

When you use the API, we process:

  • API key (for authentication)
  • Reasoning traces submitted for loop detection
  • Session IDs and request timestamps
  • Daily request counts (for rate limiting)
  • Detection results (whether a loop was detected)

Reasoning traces are stored and automatically deleted after 7 days (Hobby plan) or 90 days (Pro plan).

Legal basis: Art. 6(1)(b) GDPR — necessary to perform the contract with you.

Note: Do not submit personal data of end users as reasoning traces. InferenceBrake is designed to monitor AI agent outputs, not to process end-user personal information.

Payment Data

Note: Payments are not currently active. Paid plans will be introduced in the future.

Payments are processed exclusively by Stripe. We only store:

  • Stripe Customer ID
  • Stripe Subscription ID
  • Subscription status and current period end date

Credit card numbers and full payment details are never stored on our servers. They are handled entirely by Stripe.

Legal basis: Art. 6(1)(b) GDPR — necessary to perform the contract with you.

Server Logs

Our infrastructure providers (Supabase, Vercel) automatically log IP addresses, user agents, and request metadata for security and debugging purposes. These logs are retained for up to 30 days.

Legal basis: Art. 6(1)(f) GDPR — legitimate interest in operating secure systems.

3. Data Sharing and Processors

We use the following sub-processors who handle data on our behalf:

  • Supabase Inc. — Database, authentication, and edge functions. Data is processed in EU data centers (AWS Frankfurt). Privacy Policy
  • Stripe Inc. — Payment processing and subscription management. Data transfer to the US is based on the EU-US Data Privacy Framework (Art. 45 GDPR). Privacy Policy
  • Vercel Inc. — Frontend hosting. Data transfer to the US is based on Standard Contractual Clauses (Art. 46 GDPR). Privacy Policy

We do not sell your data to third parties. We do not use your data to train AI models.

4. Data Retention

Reasoning traces and session data are deleted automatically according to your plan (7 or 90 days). When you delete your account, all personal data is deleted within 30 days, except where we are required to retain it by law.

Billing records and invoices are retained for 10 years to comply with German tax law (§ 147 AO). Stripe-side payment data is subject to Stripe's own retention policy.

5. Your Rights (GDPR)

If you are in the EEA, you have the following rights:

  • Right to access (Art. 15): Request a copy of your data.
  • Right to rectification (Art. 16): Correct inaccurate data.
  • Right to erasure (Art. 17): Request deletion of your data.
  • Right to restriction (Art. 18): Restrict how we process your data.
  • Right to data portability (Art. 20): Receive your data in a machine-readable format.
  • Right to object (Art. 21): Object to processing based on legitimate interests.

To exercise any of these rights, contact us at inferencebrake.dev@proton.me. We will respond within 30 days.

You also have the right to lodge a complaint with the supervisory authority in Hesse, Germany: Der Hessische Beauftragte für Datenschutz und Informationsfreiheit (HBDI)

6. Cookies

InferenceBrake uses only technically necessary cookies for authentication (Supabase Auth session token). These are required for the service to function and do not require consent under § 25(2) TDDDG / Art. 5(3) ePrivacy Directive.

We do not use tracking, advertising, or analytics cookies.

7. Data Security

All connections are TLS-encrypted. Passwords are hashed with bcrypt. API keys are generated with 64 bytes of cryptographic randomness. We recommend storing your API key securely and rotating it if you believe it has been compromised (available in your dashboard settings).

8. Changes to This Policy

We may update this Privacy Policy from time to time. For significant changes, we will notify registered users by email. The date at the top of this page reflects the most recent update.

9. Contact

For any privacy-related questions or to exercise your rights: inferencebrake.dev@proton.me

InferenceBrake

Multi-detector loop detection for AI agents.

Product

Pricing Docs Dashboard Settings

Legal

Impressum Privacy Terms

© 2026 InferenceBrake.