← Back to Endoplas

Privacy Policy

Effective July 29, 2026

This Privacy Policy explains how Endoplas Inc. (“Endoplas,” “we,” “us,” or “our”) collects, uses, and protects information when you use the Endoplas website, applications, and services (the “Service”). It should be read together with our Terms of Service.

1. Information We Collect

We collect the following categories of information:

  • Account information: the email address you register with, and an optional display name. If you sign in with a password, we store a one-way cryptographic hash of it (bcrypt) — we never store or have access to your plaintext password.
  • Conversation content: the messages, prompts, and files you submit to the Service, and the responses generated for you.
  • Usage metadata: which model and provider handled a given request, token counts, latency, and cost. This metadata is stored separately from conversation content and never includes the text of your messages.
  • Personalization data (optional): if you use the “My Adaptation” feature, preferences and notes you explicitly author to personalize how the Service responds to you.
  • Workspace and organizational data: for team or enterprise workspaces, information shared within that workspace by its members, isolated from other workspaces.

2. How We Use Information

We use the information above to:

  • Operate, maintain, and secure the Service, including authenticating your account;
  • Route your requests to the appropriate underlying AI provider and return a response;
  • Personalize responses, where you have opted into personalization features;
  • Monitor and improve the reliability, performance, and cost-efficiency of the Service (using usage metadata, not conversation content);
  • Process payment where you subscribe to a paid plan;
  • Communicate with you about your account or material changes to the Service.

3. Third-Party AI Providers

Endoplas is an orchestration layer over multiple third-party AI providers. To generate a response, the content necessary to answer your specific request — generally, the relevant message history for that conversation — is transmitted to whichever provider is selected for that request. As of this policy’s effective date, those providers are:

  • Anthropic (Claude models)
  • OpenAI (GPT models)
  • xAI (Grok models)
  • Google (Gemini models)
  • Moonshot AI (Kimi models)

We do not send more of your data to a provider than is necessary to serve the request. Whether a given provider uses API traffic to train its own models is governed by that provider’s own policy, not by Endoplas — we encourage you to review the relevant provider’s data-use terms if this matters to you. We do not sell your information to any provider or other third party.

4. We Do Not Train on Your Content

Endoplas does not use your conversation content for any purpose beyond serving the request it was submitted for — including routing, generating a response, or multi-model “Council” deliberation. We do not use your conversation content to train our own models, and no internal analytics process ingests message content: analytics and usage records are limited to metadata such as token counts and provider/model identifiers, described in Section 1.

5. Data Retention and Deletion

When you delete a conversation, it is immediately removed from your account and excluded from all further access through the Service. Deleted content may be retained for a limited period afterward for security, audit, or legal-compliance purposes before it is permanently purged.

Personalization entries you explicitly remove (via “My Adaptation”) are deleted immediately and are not retained. You can request deletion of your account and associated data at any time by contacting us at the address in Section 11.

6. Private Sessions

Conversations marked as a private session are excluded from personalization — they are neither read from nor written to your personalization data.

7. Data Security

Passwords are hashed using bcrypt and never stored in plaintext. Data in transit is encrypted via HTTPS/TLS. Our infrastructure runs on Google Cloud (Cloud Run, Cloud SQL, Cloud Storage, and Secret Manager for credentials), located in the United States. Access to production data is restricted and every request is scoped to your authenticated account and workspace — a request can never read another workspace’s data. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

8. Error Monitoring

We use Sentry, a third-party error-monitoring service, to detect and diagnose bugs in the Service. When an unexpected error occurs, technical details — an error message, a stack trace, and a request identifier — are sent to Sentry. We do not send the content of your conversations or messages to Sentry as part of this.

9. Children’s Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us information, contact us at the address in Section 11 and we will delete it.

10. International Users

The Service is operated from, and its infrastructure is located in, the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.

11. Your Rights and Contact

Depending on your location, you may have rights to access, correct, export, or delete your personal information. You can exercise these rights, or ask any question about this policy, by emailing info@endoplas.ai.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, provide additional notice.

This document was prepared to reflect Endoplas’s actual data practices as implemented in the product. Endoplas Inc. recommends consulting a qualified attorney before relying on it as a final legal instrument, particularly regarding jurisdiction-specific data protection requirements (e.g. GDPR, CCPA).