Privacy Policy
Effective date: July 8, 2026
NoThirdParty AI ("we," "us," or "our") operates the website at nothirdparty.ai and provides private AI services to businesses. This Privacy Policy explains what information we collect, how we use it, and your rights with respect to that information.
1. Information We Collect
Contact Form. When you submit our contact form, we collect your name, email address, company name (optional), and message. We use this information solely to respond to your inquiry.
Infrastructure Data. Our marketing website is served through Cloudflare's network. As part of routing traffic to our servers, Cloudflare may process your IP address, browser type, pages visited, and request timestamps. Cloudflare does not use this data for advertising and does not share it with third-party AI vendors.
AI Platform Traffic Routing. Your client subdomain (e.g., yourfirm.nothirdparty.ai) is also routed through Cloudflare's network via Cloudflare Tunnel. Because of how this connection is established, Cloudflare's edge servers briefly decrypt traffic - including conversation content - before it is re-encrypted and forwarded to our servers. Cloudflare does not log, store, retain, or use this content for any purpose, including AI training or advertising, and our configuration does not enable Cloudflare's caching or AI features on this traffic. We are evaluating a direct, Cloudflare-free connectivity option (client-side VPN) for clients who require zero intermediary infrastructure; contact us if this is a requirement for your organization.
Website Analytics. We use Cloudflare Web Analytics, a cookie-free analytics tool. It collects anonymized page view data including approximate country, device type, and browser. No personally identifiable information is stored, no cookies are set on your device, and EU visitor data is excluded from collection.
Client Service Data. If you are a client using our AI platform, your conversation data is stored on our servers to provide conversation history to your team. We do not use this data to train any AI model. We do not share this data with any third-party AI vendor.
Platform Cookies. The AI platform (accessed at your client subdomain, e.g., yourfirm.nothirdparty.ai) uses session cookies strictly necessary for authentication and maintaining your logged-in state. These cookies are not used for tracking or advertising and are deleted when you log out or your session expires.
2. Information We Do Not Collect
- We do not set advertising or tracking cookies on the marketing website (nothirdparty.ai)
- We do not use Google Analytics, Meta Pixel, or similar third-party tracking tools
- We do not sell your personal information to any third party
- We do not share your data with AI training pipelines
3. How We Use Your Information
- To respond to contact form submissions
- To provide and maintain our service to clients
- To fulfill billing obligations (via Stripe, for clients)
4. Data Retention
Contact form submissions are retained for a reasonable period to address your inquiry. Client service data is retained for the duration of the service agreement and deleted upon request or within 30 days of agreement termination.
5. Third-Party Service Providers
We use the following service providers to operate our business. These providers process data only as necessary to perform their functions and are not permitted to use your data for their own purposes.
| Provider | Role |
|---|---|
| Cloudflare, Inc. | Network infrastructure and anonymized website analytics |
| Stripe, Inc. | Payment processing for client subscriptions (collected directly by Stripe; we do not store payment card data) |
| Google LLC (Google Drive) | Encrypted remote backup storage. Data is encrypted client-side (via rclone) before transmission; Google does not have access to unencrypted content. |
6. Health Information
We do not currently offer a Business Associate Agreement (BAA) under HIPAA. If your organization is a covered entity or business associate under HIPAA, do not submit Protected Health Information (PHI) to the Service until a BAA is executed. Contact us if you require a BAA - we can discuss availability and timeline.
7. International Data Transfers
Our servers and Cloudflare's traffic-routing infrastructure are located in the United States. If you are located outside the United States, your data will be transferred to and processed in the United States. For clients in the European Economic Area, United Kingdom, or Switzerland, we will execute Standard Contractual Clauses (SCCs) upon request as part of your DPA.
8. Your Rights
You may request access to, correction of, or deletion of your personal information at any time by contacting us at [email protected]. We will respond within 30 days.
9. Children's Privacy
Our service is not directed to children under 13. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us and we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. The effective date at the top of this page indicates when this version was last revised. We will notify active clients of material changes via email before they take effect.
11. Governing Law
This Privacy Policy is governed by the laws of the State of Nebraska, United States.
Questions about this policy? Contact us at [email protected].