What we collect, how we handle your code, and the rights you have over your data.
Last updated: 2 August 2026
This Privacy Policy explains how MILLENNIUMS.AI collects, uses, and protects information when you use our website, application, and API (the "Service"). Our guiding principle is to hold as little of your data as possible, and never to learn from it.
We never use your source code or scan results to train any model. Each scan runs in a throwaway sandbox that is destroyed when the scan finishes.
We use your information only to operate the Service: to run and meter scans, deliver findings, authenticate you, bill your plan, monitor for abuse, and improve reliability. We do not sell your data, and we do not use it for advertising.
Your source code is processed inside an isolated, per-scan sandbox that is torn down on completion — we do not keep your source beyond the scan. Account data and scan results are retained per-tenant for as long as your account is active, or as needed to comply with legal obligations. You can delete your findings, or request deletion of your account, at any time.
Model calls use a commercial LLM API (Anthropic, or your own provider on self-hosted deployments) whose terms prohibit training on submitted content. Standard requests may be retained briefly by the provider for abuse monitoring, then deleted; zero-data-retention is available on enterprise agreement.
We use a small set of sub-processors — the LLM provider, a container runtime for the sandbox, our cloud host, and Stripe for payments. The current list and what each one touches is published in the Trust Center. Self-hosted deployments have no MILLENNIUMS-operated sub-processors: you supply your own model key and your code never leaves your environment.
Hosted deployments can be pinned to a region, including the EU. Where data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses. For strict residency or air-gap needs, use the self-hosted / VPC option.
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any of these, contact us at the address below. A Data Processing Addendum with SCCs is available on request.
We protect your data with per-tenant isolation, bearer-token authentication with constant-time comparison, encryption in transit and at rest, and strict secrets discipline (your model API key is never returned by any endpoint). Our security posture and how to report an issue are in the Trust Center.
We use only what the Service needs to function — a stored authentication token and your light/dark theme preference. We do not use third-party advertising or cross-site tracking cookies.
The Service is intended for professional use and is not directed to anyone under 18. We do not knowingly collect data from children.
We may update this Policy from time to time. Material changes will be reflected by the "last updated" date above and, where appropriate, notified in-app or by email.
Privacy questions or data requests: privacy@millenniums.ai.