Skip to content
Public preview · the console is open

Privacy Policy

Effective August 4, 2026 · Last updated September 18, 2026

This document is effective as of August 4, 2026 and is undergoing legal review; it may be updated.

1. Who we are

ggui.ai is operated by Loqu, Inc., a Delaware corporation (“Loqu”, “we”). This policy covers ggui.ai and its subdomains operated by Loqu, including the ggui.ai website, docs.ggui.ai, benchmarks.ggui.ai, console.ggui.ai, status.ggui.ai, registry.ggui.ai, and hosted GGUI — the managed cloud service — and its service endpoints (mcp.ggui.ai, api.ggui.ai, auth.ggui.ai). It does not cover guuey.com, which has its own documents, Loqu’s internal staff-only surfaces such as admin.ggui.ai, or third-party services we link to.

2. Whose data we process

For visitors to and account holders of the surfaces above, Loqu acts as the data controller, and the legal bases in section 8 apply as written.

The service also processes content on behalf of account holders and registered platforms — including identifiers of end-users (issuer and subject), per-render end-user identity, interaction events, and usage records of end-users who may hold no GGUI account. We process that data only to operate the service. If you are such an end-user, please direct data-rights requests to the platform or agent builder responsible for your relationship; if a request reaches privacy@ggui.ai by mistake, we forward it to the responsible party.

3. Data we collect

4. How we use data

We use data to provide, operate, and improve the service: authenticating you, generating and serving interfaces, routing LLM requests (including with provider keys you supply), metering usage, billing and fraud prevention, delivering organization invitations and status or incident notifications, product analytics, and support.

5. AI processing disclosures

Platform-routed requests

When generation runs on our provider pool, your content is processed by the LLM providers we contract with: Anthropic (through AWS Bedrock and the Anthropic API), OpenAI, Google Gemini, and OpenRouter (which routes to further downstream model providers). We only enable platform providers whose terms prohibit training on API content: content routed through AWS Bedrock is excluded from model training under the AWS Bedrock service terms, and content sent to the Anthropic API is not used to train models under Anthropic’s commercial terms; equivalent commitments apply to each other enabled provider under its commercial terms.

Bring-your-own-key requests

When you supply your own provider API key, content on that leg is processed under your own agreement with that provider. Loqu makes no training representation for BYOK traffic.

Our own use

Loqu does not use your content to train models.

Social sign-in data

Google user data obtained through Google Sign-In is used solely for authentication and account provisioning. It is never used for advertising, never sold, and shared only with the subprocessors listed below. Our use of Google user data adheres to the Google API Services User Data Policy, including its Limited Use requirements. GitHub profile data is handled the same way: sign-in and account provisioning only.

6. Subprocessors

7. Data retention

8. Your rights — EEA and UK

Where GDPR or UK GDPR applies, we process personal data on these legal bases: performance of a contract (providing the service), legitimate interests (security, fraud prevention, product analytics), and consent where required. You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. International transfers to the United States rely on Standard Contractual Clauses. Where we obtain personal data other than from you directly — for example, an organization member inviting you by email — this policy serves as notice under Article 14. Deletion requests are served by the in-product account-erasure flow in the console or via privacy@ggui.ai; analytics profiles held in PostHog are deleted as a separate step of the same request.

9. Your rights — California

We do not sell or share personal information as those terms are defined by the CCPA/CPRA. California residents have the rights to know, delete, correct, and limit use of sensitive personal information, without discrimination for exercising them. We honor Global Privacy Control signals for opt-out preferences. Requests: privacy@ggui.ai.

10. Children

The service is not directed at children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact privacy@ggui.ai and we will delete it.

11. Security

Data is encrypted in transit and at rest. Provider API keys you supply are protected with AWS KMS envelope encryption; plaintext keys are never persisted. Access to production systems is limited and audited.

12. Changes to this policy

Material changes are announced by email to your account address together with a dated update to this page; non-material edits update the “Last updated” date only. Prior versions are available on request via privacy@ggui.ai.

13. Contact

Data-rights requests: privacy@ggui.ai. General inquiries: hello@ggui.ai. We fulfill data-rights requests within the windows the applicable law sets, across our authentication, database, cache, and analytics systems.