Legal

Privacy Policy

What we collect, how we handle your code, and the rights you have over your data.

Last updated: 2 August 2026

This Privacy Policy explains how MILLENNIUMS.AI collects, uses, and protects information when you use our website, application, and API (the "Service"). Our guiding principle is to hold as little of your data as possible, and never to learn from it.

We never use your source code or scan results to train any model. Each scan runs in a throwaway sandbox that is destroyed when the scan finishes.

1Information we collect

2How we use it

We use your information only to operate the Service: to run and meter scans, deliver findings, authenticate you, bill your plan, monitor for abuse, and improve reliability. We do not sell your data, and we do not use it for advertising.

3Ephemeral processing & retention

Your source code is processed inside an isolated, per-scan sandbox that is torn down on completion — we do not keep your source beyond the scan. Account data and scan results are retained per-tenant for as long as your account is active, or as needed to comply with legal obligations. You can delete your findings, or request deletion of your account, at any time.

4No training on your data

Model calls use a commercial LLM API (Anthropic, or your own provider on self-hosted deployments) whose terms prohibit training on submitted content. Standard requests may be retained briefly by the provider for abuse monitoring, then deleted; zero-data-retention is available on enterprise agreement.

5Sub-processors

We use a small set of sub-processors — the LLM provider, a container runtime for the sandbox, our cloud host, and Stripe for payments. The current list and what each one touches is published in the Trust Center. Self-hosted deployments have no MILLENNIUMS-operated sub-processors: you supply your own model key and your code never leaves your environment.

6Data residency & transfers

Hosted deployments can be pinned to a region, including the EU. Where data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses. For strict residency or air-gap needs, use the self-hosted / VPC option.

7Your rights

Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, contact us at the address below. A Data Processing Addendum with SCCs is available on request.

8Security

We protect your data with per-tenant isolation, bearer-token authentication with constant-time comparison, encryption in transit and at rest, and strict secrets discipline (your model API key is never returned by any endpoint). Our security posture and how to report an issue are in the Trust Center.

9Cookies & local storage

We use only what the Service needs to function — a stored authentication token and your light/dark theme preference. We do not use third-party advertising or cross-site tracking cookies.

10Children

The Service is intended for professional use and is not directed to anyone under 18. We do not knowingly collect data from children.

11Changes

We may update this Policy from time to time. Material changes will be reflected by the "last updated" date above and, where appropriate, notified in-app or by email.

12Contact

Privacy questions or data requests: privacy@millenniums.ai.