Skip to content
Formal Engines
SystemProcessDocsDemoContact
Bring us a task
SystemProcessDocsDemoContactBring us a task ↗

Legal

Privacy policy.

We collect little, we keep it for stated periods, and we do not train on your work. This page says exactly what that means for the Formal Engines API, SDK, documentation, and website.

Last updated: 18 August 2026Applies to the private beta

  1. 01What we collect
  2. 02Why we collect it
  3. 03What we do not do
  4. 04Subprocessors
  5. 05How long we keep it
  6. 06Your rights
  7. 07Security
  8. 08International transfers
  9. 09Changes and contact

01

What we collect

An email, what your key does, what your runs contain, and ordinary server logs.

  • Account data. The email address you give at signup, the workspace it created, a hash of the API key, and the dates involved. During the beta we do not ask for a name, a company, an address, or payment details.
  • API usage metadata. Which endpoints your key called and when, response status, run and artifact identifiers, queue and compute time, run duration, and resource size. This is what tells us a run happened and what it cost to serve.
  • Run content you submit. The specification environments and their code, datasets and splits, prompts, rollout traces, metrics, checkpoints, and evidence bundles. We receive whatever your environments contain — so treat an environment as something you have decided to send us, and do not put personal data in one unless you need it there and have a lawful basis for it.
  • Server logs. Ordinary web-server records for requests to the API and this site: IP address, user agent, timestamp, request path, and response status.
  • What you write to us. Email you send to hello@formalengines.com, and our replies.

This website and the documentation set no cookies of their own and carry no third-party analytics, session recording, or advertising trackers. There is nothing here to consent to.

02

Why we collect it

Running the service, keeping it from being abused, and sizing the compute pool.

  • To provide the service. Authenticate your key, schedule and execute runs, store artifacts, return results, and reach you about your workspace. Legal basis: performance of our agreement with you.
  • To prevent abuse. Detect and investigate attacks, quota evasion, leaked keys, and attempts to reach other workspaces; keep the platform available for everyone else. Legal basis: our legitimate interest in a service that stays up and is not used to harm others.
  • To plan capacity and fix things. Understand queue depth, run durations, and failure rates so we can size the compute pool and debug what broke. Legal basis: our legitimate interest in operating and improving the platform. We use aggregate metadata for this, not the content of your runs.
  • To meet legal obligations. Where the law requires us to keep or produce records.

We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not build profiles of you.

03

What we do not do

No selling, no training on your data, no ad-tech.

  • We do not sell or rent your data. Not personal data, not run content, not to data brokers, not to anyone — and we do not share it for cross-context behavioural advertising.
  • We do not train on your content. Your environments, datasets, traces, checkpoints, and evidence bundles are not training data for our models or anyone else's, and we do not pass them to a model provider for that purpose.
  • We run no advertising or ad-tech. No ad networks, no marketing pixels, no third-party trackers on the site.
  • We do not browse your runs. Our people access run content only to operate the service — to investigate a problem you have reported, or abuse we have detected — and access to production is limited to the people who run it.

04

Subprocessors

The third parties that touch data because they run infrastructure for us.

Running a training platform means other companies touch the infrastructure. We keep that list as short as we can, and we name providers concretely rather than gesturing at "trusted partners".

  • Cloud hosting — Amazon Web Services. The API, the database, and object storage for artifacts and evidence bundles run on AWS.
  • GPU compute — engaged per run. Training and evaluation execute on accelerator capacity we engage for that run, which may be our own or a third-party GPU provider. Which one handles a given run depends on the accelerator required and what is available at the time, so the set changes as we add and drop providers.
  • Transactional email. A standard email provider delivers signup, beta, and breaking-change notices to workspace addresses.

Because the GPU set moves, the authoritative list of named subprocessors lives in the dashboard and the documentation, and we update it there as providers are added or removed. Each subprocessor is engaged under terms that limit them to processing on our instructions. If you need advance notice of new subprocessors for your workspace, tell us and we will email you before we add one.

05

How long we keep it

Account data, run artifacts, and logs each have a different clock.

  • Account data. Kept while the workspace exists, and deleted when you ask us to delete it or close the workspace.
  • Run artifacts. Specifications, traces, metrics, checkpoints, and evidence bundles are kept according to your workspace's retention setting. Where a workspace has no explicit setting, they are kept until you delete them or the workspace closes — after which the 30-day export window in theTerms applies.
  • Server logs. Kept for 90 days, then deleted or reduced to counts that no longer identify a request.
  • Email correspondence. Kept while it is useful for supporting you, then deleted.

Deletion propagates to backups within 30 days, because backups roll rather than being edited in place.

06

Your rights

Access, export, correction, deletion — and who is controller for what.

For your account and usage data, Formal Engines is the controller. For personal data that you place inside your environments, datasets, or traces, you are the controller and we process it on your instructions.

  • Access and portability. Ask us what we hold about you and we will tell you. Your run artifacts and evidence bundles are exportable through the API and SDK at any time without asking us — that is the point of a signed bundle.
  • Correction and deletion. Ask us to correct your account details, or to delete the workspace and everything in it. Deletion removes the account record, the key hash, and the artifacts; logs age out on the 90-day cycle.
  • Restriction and objection. You can object to processing we base on legitimate interests, and ask us to restrict processing while we consider it.
  • How to ask. Write to hello@formalengines.com from your workspace email address. We aim to reply within 30 days, and we will not charge you for a reasonable request.

If you are in the EEA or the UK you also have the right to complain to your data protection authority. We would rather you told us first and gave us a chance to fix it.

07

Security

What actually protects the data, stated without certification claims.

  • TLS everywhere. Traffic to the API, the package index, and this site travels over TLS.
  • Keys hashed at rest. We store a hash of every API key, never the key itself. We can revoke a key; we cannot read one back.
  • Workspace isolation. Every request is scoped to the workspace behind the key, and customer environment code executes in isolated ephemeral compute that is created for a run and destroyed after it.
  • Signed evidence. Evidence bundles carry an HMAC-SHA256 signature over the canonical payload, so a bundle can be checked for tampering long after it leaves us.

We hold no security certification — not SOC 2, not ISO 27001 — and we do not claim otherwise while we are in beta. No system is perfectly secure. If you find a weakness, write to hello@formalengines.com and we will respond; if a breach affects your data we will tell you and any regulator we are required to notify.

08

International transfers

Where the data sits, and where a run may execute.

We are a small team using cloud infrastructure, and data may be stored or processed outside the country you are in. GPU capacity in particular is engaged where it is available, so a run can execute in a different region from the one holding your account data.

Where personal data leaves the UK or the EEA, we rely on the transfer safeguards in our providers' terms — in practice the standard contractual clauses — together with the technical measures described above. During the beta we cannot guarantee that a run stays in a particular region; if that matters for your data, talk to us before you start and we will tell you honestly whether we can meet it.

09

Changes and contact

How this page changes, and the address that reaches us.

We update this page when what we do changes — a new subprocessor, a new retention period, a new kind of data. The date at the top changes with it, and for changes that materially affect you we email workspace addresses rather than relying on you to re-read the page.

Questions, requests, or a report about data you think we should not have: hello@formalengines.com.

hello@formalengines.com↗Terms of service→
Formal Engines

Executable environments for models you can stand behind.

hello@formalengines.com
TermsPrivacy

© 2026 Formal Engines