Effective July 29, 2026
This Privacy Policy explains how Endoplas Inc. (“Endoplas,” “we,” “us,” or “our”) collects, uses, and protects information when you use the Endoplas website, applications, and services (the “Service”). It should be read together with our Terms of Service.
We collect the following categories of information:
We use the information above to:
Endoplas is an orchestration layer over multiple third-party AI providers. To generate a response, the content necessary to answer your specific request — generally, the relevant message history for that conversation — is transmitted to whichever provider is selected for that request. As of this policy’s effective date, those providers are:
We do not send more of your data to a provider than is necessary to serve the request. Whether a given provider uses API traffic to train its own models is governed by that provider’s own policy, not by Endoplas — we encourage you to review the relevant provider’s data-use terms if this matters to you. We do not sell your information to any provider or other third party.
Endoplas does not use your conversation content for any purpose beyond serving the request it was submitted for — including routing, generating a response, or multi-model “Council” deliberation. We do not use your conversation content to train our own models, and no internal analytics process ingests message content: analytics and usage records are limited to metadata such as token counts and provider/model identifiers, described in Section 1.
When you delete a conversation, it is immediately removed from your account and excluded from all further access through the Service. Deleted content may be retained for a limited period afterward for security, audit, or legal-compliance purposes before it is permanently purged.
Personalization entries you explicitly remove (via “My Adaptation”) are deleted immediately and are not retained. You can request deletion of your account and associated data at any time by contacting us at the address in Section 11.
Conversations marked as a private session are excluded from personalization — they are neither read from nor written to your personalization data.
Passwords are hashed using bcrypt and never stored in plaintext. Data in transit is encrypted via HTTPS/TLS. Our infrastructure runs on Google Cloud (Cloud Run, Cloud SQL, Cloud Storage, and Secret Manager for credentials), located in the United States. Access to production data is restricted and every request is scoped to your authenticated account and workspace — a request can never read another workspace’s data. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
We use Sentry, a third-party error-monitoring service, to detect and diagnose bugs in the Service. When an unexpected error occurs, technical details — an error message, a stack trace, and a request identifier — are sent to Sentry. We do not send the content of your conversations or messages to Sentry as part of this.
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us information, contact us at the address in Section 11 and we will delete it.
The Service is operated from, and its infrastructure is located in, the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States.
Depending on your location, you may have rights to access, correct, export, or delete your personal information. You can exercise these rights, or ask any question about this policy, by emailing info@endoplas.ai.
We may update this Privacy Policy from time to time. If we make material changes, we will update the effective date above and, where appropriate, provide additional notice.
This document was prepared to reflect Endoplas’s actual data practices as implemented in the product. Endoplas Inc. recommends consulting a qualified attorney before relying on it as a final legal instrument, particularly regarding jurisdiction-specific data protection requirements (e.g. GDPR, CCPA).