{"platform":"Conifer","slug":"conifer","category":"Workflow & Automation","website":"https://www.conifer.build","risk_rating":"low","verification":"partially_verified","verification_detail":{"tier":"partially_verified","partial_reason_code":"missing_terms","partial_reason_label":"Terms not yet captured","blocked_core_documents":[]},"rating":{"value":"low","unknown_reason_code":"none","unknown_reason_label":"Rated"},"corpus_status":"corpus_partial","canonical":"https://airinetwork.com/platform/conifer","machine_url":"https://airinetwork.com/api/machine/platform/conifer","last_reviewed":"2026-07-20","findings_count":17,"findings":[{"id":"prompt-ownership-25875de3114d60ced8d5","permalink":"https://airinetwork.com/platform/conifer/finding/prompt-ownership-25875de3114d60ced8d5","surface":"prompt_ownership","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":"Yours. Your key is stored encrypted and used only to call your provider for your request. Traffic passes through Conifer&#x27;s gateway (2.5% fee) and your prompt goes to your provider under your agreement with them — HIPAA or no-training terms you hold with that provider govern that leg. Conifer keeps no conversation content from these calls unless the cloud chat content setting is on. ","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=Yours.%20Your%20key%20is,setting%20is%20on.%20","structural_citation":"Privacy Policy › “Three questions answered first”","citation_basis":"heading_path","char_start":2304,"char_end":2694,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-41e2c05d350be0581806","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-41e2c05d350be0581806","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":"Each routed question sends numbers and categories describing the decision (request shape, timings, which side answered, what you did next), plus an irreversible fingerprint (one-way hash) of your message and system prompt, which cannot reconstruct the text. The text of what you typed and what a model wrote is never sent. Tied to your account; shown in the app&#x27;s egress count. \n Cloud chat content (on by default, consent-versioned) On by default; turn it off anytime. The cloud lane necessarily transmits your prompt to serve the request (see Cloud-lane inference above); this consent governs whether we may retain it: encrypted per-account, erasable on withdrawal in one step. Retention limits and audit guarantees: section 03 below. \n Local chat content (on by default, separate) On by default and asked separately; turn it off anytime. Local conversations never leave your machine unless you allow sharing them for model improvement; sensitive-looking conversations are excluded on-device, and a conversation that ever looked sensitive never uploads its history. \n Your own API keys (BYOK) Your provider, under YOUR agreement with them. Your key is stored encrypted and used only to call your provider for your request; traffic passes through Conifer&#x27;s gateway (2.5% fee). HIPAA or no-training terms you hold with that provider govern the provider leg. Conifer keeps no conversation content from these calls unless the cloud chat content consent is on. ","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=Each%20routed%20question%20sends,consent%20is%20on.%20","structural_citation":"Privacy Policy › “The whole story one table”","citation_basis":"heading_path","char_start":4175,"char_end":5643,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-1b65fa8460a1d3783be1","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-1b65fa8460a1d3783be1","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Conifer routes each query to the cheapest model that can do the job, and the cheapest lane is the free one on your own hardware. So by default, everyday queries run locally: the model, the prompt, and the generated tokens stay on your machine. The engine does not phone home. It has no analytics, no error reporting, no model-usage telemetry, and no background ping.\n A local query touches the network zero times, unless one of the sharing settings is on (the usage-data setting above, or section 03). Those settings are on by default and each can be turned off in the app — the app&#x27;s Local-only switch turns every one of them off at the wire in a single step. The only other outbound calls the engine makes are ones you start: downloading the weights for a model you asked to install, and checking for updates when you ask it to. Neither call carries your prompts or your data.","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20routes%20each,prompts%20or%20your%20data.","structural_citation":"Privacy Policy › “Local inference stays local”","citation_basis":"heading_path","char_start":6432,"char_end":7316,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-43d556ae481d57572855","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-43d556ae481d57572855","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Everything that does or does not cross the wire, in one glance: the local lane where it does not, and the cloud lane and account system where it can. The sections below say the same thing in full.\n Local inference Stays on your machine. The default lane for everyday queries: the model, the prompt, and the generated tokens run on your hardware and are not sent anywhere. The engine has no analytics, no error reports, no usage telemetry, and no phone-home. \n Cloud-lane inference The model provider you chose, and only if you allowed the cloud at all. The prompt and context for that one query cross the wire only when the router escalates a query local could not handle well. Disclosed in the run, never silent. Never happens in privacy-first mode. \n Usage data (on by default) On by default; turn it off anytime in the app&#x27;s settings. While on, the app sends anonymized usage notes and, during the demo phase, the text of your prompts. Your device strips text that looks like keys, tokens, passwords, emails, or card numbers first; that redaction is best-effort, so assume anything you type may be included. This pipeline carries no model outputs and none of your files, and it is keyed to a random anonymous id, not your account. It is separate from the account-tied routing signals below, and the two are not joined. Every upload shows in the app&#x27;s egress count. \n Routing signals (on by default) On by default; turn it off anytime. ","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20Everything%20that%20does,it%20off%20anytime.%20","structural_citation":"Privacy Policy › “The whole story one table”","citation_basis":"heading_path","char_start":2726,"char_end":4175,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-11a1973884da78a62c5f","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-11a1973884da78a62c5f","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Conifer is the front door to all inference: a router sends each query to the cheapest model that can do the job, starting with the free ones on your own hardware. By default everyday queries run locally, so the model, the prompt, and the tokens stay on your machine. The router may send a query to a cloud model when local is not good enough, and only if you allowed the cloud at all. This page covers exactly what can cross the wire, when, and to whom.","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20is%20the,when%2C%20and%20to%20whom.","structural_citation":"Privacy Policy › “Local by default. The cloud only when you allow it.”","citation_basis":"heading_path","char_start":135,"char_end":589,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-2f98e3fa273fb8a5c331","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-2f98e3fa273fb8a5c331","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" ┌─ your machine \n │ the local model · your prompts · the tokens \n │ your files · your keys · your chats \n └─ stays here by default. \n cloud lane ──▸── only a query you allowed, only when local is not enough. ","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20%E2%94%8C%E2%94%80%20your%20machine,is%20not%20enough.%20","structural_citation":"Privacy Policy › “Local by default. The cloud only when you allow it.”","citation_basis":"heading_path","char_start":591,"char_end":800,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-84bfd6b152d587fbc73f","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-84bfd6b152d587fbc73f","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" The three questions that decide whether you can use Conifer professionally, answered up front. The desktop app answers the same three from live state in Settings → Privacy & data.\n Does anything from my local chats leave my machine? By default, yes: Conifer shares conversation data and anonymized routing signals to improve routing, and usage data (including prompt text during the demo, captured only after best-effort on-device redaction — pattern redaction cannot catch everything). Turns that look sensitive are excluded on-device from every content channel: chat-content sharing and the usage prompt channel both apply the same sensitivity check before anything is stored or sent. Turn the sharing settings off in the app — or flip its Local-only switch — and the answer becomes no: local chats stay on your machine, enforced at every send path, and the app&#x27;s egress ledger shows what actually left. \n Can I control what stays local? Yes. Prompts that look sensitive stay local by default (keep-sensitive-local); any chat can be pinned On-device; and the Local-only switch sets the whole app offline — chats, voice, sharing uploads, and scheduled workflow cloud steps make no cloud calls, checked at each send path (your signed-in session itself stays alive). When the router escalates a query, that one prompt and its context go to the provider for that single query — disclosed in the run, never silent. \n I brought my own API keys — whose terms apply? ","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20The%20three%20questions,whose%20terms%20apply%3F%20","structural_citation":"Privacy Policy › “Three questions answered first”","citation_basis":"heading_path","char_start":837,"char_end":2304,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-9235947144c12a4c64cf","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-9235947144c12a4c64cf","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" The router may escalate a query to a cloud model when a local model is not good enough for it, and only if you allowed the cloud at all. When that happens, the prompt and the context for that one query go to the model provider you chose. We say so in the run; it is never silent.\n Once a query is on the cloud lane, the provider you chose handles it under their own terms, including whatever logging and retention their policy describes. Read the policy of the provider you route to. Conifer passes the query through; it does not keep its own copy unless you separately said yes to cloud chat content retention (section 03), and outside that consent the content is dropped after a short operational window.\n Privacy-first mode pins every query to a local model. Nothing crosses the wire in that mode: the cloud lane is not reached, no matter what the router would otherwise have chosen.","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20The%20router%20may,would%20otherwise%20have%20chosen.","structural_citation":"Privacy Policy › “Cloud-lane routing”","citation_basis":"heading_path","char_start":7373,"char_end":8260,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-d4483b344ea007c09e63","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-d4483b344ea007c09e63","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Everything in this section is on by default and can be turned off individually in the app&#x27;s settings, one consent at a time; no setting here implies another, and turning one off never turns off the rest. Each grant is versioned: you agree under a stated version of the consent terms, and if the terms change, sharing pauses until you re-confirm under the new ones. Every upload any of these settings causes is counted in the app&#x27;s egress log.\n routing signals Numbers and categories describing each routing decision (request shape, timings, which side answered, what you did next), plus an irreversible fingerprint (a one-way hash) of your message and of the system prompt. A fingerprint cannot reconstruct the text; we use it only to spot duplicates and join records. The text of what you typed and what a model wrote is never sent. Tied to your account. \n cloud chat content A retention consent, not a new transmission: the cloud lane already carries your prompt to serve the request (section 02). With this consent we may keep that request and the model&#x27;s answer, encrypted with a per-account key, to improve routing and models. Without it, cloud content is dropped after a short operational window. Withdrawal is one step and erases what was kept by destroying your account&#x27;s encryption key. \n local chat content Asked separately, and never implied by anything else. Local conversations stay on your machine unless you allow sharing them, encrypted per-account, to improve the models everyone runs locally. ","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20Everything%20in%20this,everyone%20runs%20locally.%20","structural_citation":"Privacy Policy › “Routing signals and chat content”","citation_basis":"heading_path","char_start":8323,"char_end":9855,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-d909dda008784accc396","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-d909dda008784accc396","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" One account, one interface across the models you use. Signing in involves the account system, which holds:\n email The address you signed in with. Used to identify your account and contact you about it. No browsing profile is built from it. \n created_at Timestamp of first sign-in. \n last_sign_in Timestamp of the most recent sign-in. \n An account is optional for local-only use where it can be: running a local model does not require signing in. The account exists so that consolidated billing and cloud routing can be tied to you when you use them.","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20One%20account%2C%20one,when%20you%20use%20them.","structural_citation":"Privacy Policy › “Account and sign-in”","citation_basis":"heading_path","char_start":10444,"char_end":10994,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-fbf87c8aef53711f1098","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-fbf87c8aef53711f1098","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" The marketplace, where you pick and enable models, and the cloud routing lane are the two places a query can leave your machine. Choosing a model in the marketplace involves your account. Sending a query to a chosen cloud model involves that provider, as described in section 02.\n The local tier and privacy-first mode are the places a query does not leave your machine. If you never allow the cloud, or you pin to privacy-first mode, the router keeps every query on your hardware.","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20The%20marketplace%2C%20where,query%20on%20your%20hardware.","structural_citation":"Privacy Policy › “The marketplace and routing”","citation_basis":"heading_path","char_start":11601,"char_end":12083,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-d8174d2356367fcaa821","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-d8174d2356367fcaa821","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" The website is hosted by a static-site host that keeps standard request logs (IP, user agent, requested URL, response status) for abuse handling. If first-party site analytics are enabled they are aggregate only, used to understand traffic, not to profile individuals. The website is separate from the engine: nothing you do on the site reaches your local models.","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20The%20website%20is,reaches%20your%20local%20models.","structural_citation":"Privacy Policy › “What the website logs”","citation_basis":"heading_path","char_start":12645,"char_end":13009,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"privacy-data-use-644a96ff36612a6d5203","permalink":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-644a96ff36612a6d5203","surface":"privacy_data_use","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Conifer is not intended for children under 13 and does not knowingly collect data from them. If you learn that a child has signed up, write to the address above and the account will be deleted.","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20is%20not,account%20will%20be%20deleted.","structural_citation":"Privacy Policy › “Children”","citation_basis":"heading_path","char_start":13595,"char_end":13789,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"moderation-enforcement-550e2a7fccb8427d1d48","permalink":"https://airinetwork.com/platform/conifer/finding/moderation-enforcement-550e2a7fccb8427d1d48","surface":"moderation_enforcement","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" For regulated teams, Conifer supports fleet governance: spend caps, and a routing policy that can be set to local-only so no query on those machines is allowed to reach a cloud provider. The policy is attestable and enforced client-side, on the device, so a machine can report exactly which routing posture it is under.\n Under a local-only fleet policy, the cloud lane is closed for every user on those machines, and inference stays on the endpoint.","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20For%20regulated%20teams%2C,stays%20on%20the%20endpoint.","structural_citation":"Privacy Policy › “Enterprise governance”","citation_basis":"heading_path","char_start":12146,"char_end":12596,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"subprocessors-data-sharing-a793299effb3b7246827","permalink":"https://airinetwork.com/platform/conifer/finding/subprocessors-data-sharing-a793299effb3b7246827","surface":"subprocessors_data_sharing","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":"\n Account and sign-in The account system. Your email and the timestamps of sign-in, so you have one account across devices. Optional for local-only use where it can be. No passwords stored, no browsing profile. \n Billing The payment processor, for consolidated billing across the models you used. It holds your card details; Conifer never sees them. We receive a customer reference and the amounts, not the card. \n Model downloads The weights host, started by you, only for the models you ask to install. \n Update check The release host, only when you check for updates. \n The website Standard web-server request logs from the host for abuse handling. First-party site analytics if enabled, aggregate only. No selling of data. ","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20Account%20and%20sign-in,selling%20of%20data.%20","structural_citation":"Privacy Policy › “The whole story one table”","citation_basis":"heading_path","char_start":5643,"char_end":6370,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"subprocessors-data-sharing-50ac0900eed8f70b26d1","permalink":"https://airinetwork.com/platform/conifer/finding/subprocessors-data-sharing-50ac0900eed8f70b26d1","surface":"subprocessors_data_sharing","risk":"low","confidence":"high","tier":"All","verified":true,"quote":" Conifer gives you one bill across every model you used, local and cloud. Local inference on your own hardware is the free tier: it costs nothing to run and adds nothing to the bill. When you use paid cloud models, billing runs through the payment processor.\n The payment processor holds your card details; Conifer never sees them. We receive a customer reference and the amounts charged, which we keep next to your account so we can show you what you spent and on which models. We do not sell this data.","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20gives%20you,not%20sell%20this%20data.","structural_citation":"Privacy Policy › “Billing”","citation_basis":"heading_path","char_start":11039,"char_end":11543,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}},{"id":"audit-rights-dpa-residency-f0ac81bcffbbcdd4015d","permalink":"https://airinetwork.com/platform/conifer/finding/audit-rights-dpa-residency-f0ac81bcffbbcdd4015d","surface":"audit_rights_dpa_residency","risk":"unknown","confidence":"high","tier":"All","verified":true,"quote":" Write to [email&#160;protected] from the address tied to your account and ask for a copy, a correction, or a deletion of the account and billing records held for you. We will do it within 30 days and confirm when it is done. EU and UK residents have the rights enumerated under GDPR; California residents have the rights enumerated under CCPA. Both reduce, in practice, to the email above. Local data on your own machine is yours to delete directly; the engine keeps no copy of it anywhere else.","caution":null,"provenance":{"source_url":"https://www.conifer.build/privacy/","snapshot_sha256":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1","wayback_url":null,"deep_link":"https://www.conifer.build/privacy/#:~:text=%20Write%20to%20%5Bemail%26%23160%3Bprotected%5D,of%20it%20anywhere%20else.","structural_citation":"Privacy Policy › “Your rights”","citation_basis":"heading_path","char_start":13065,"char_end":13561,"retrieved_at":"2026-07-20T00:07:37.39132+00:00"}}],"documents":[{"doc_type":"privacy","pdf_page_count":null,"extraction_method":null,"page_level_citations":false,"last_captured":"2026-07-20","last_verified_scan":"2026-07-20","verified_scan_count":1}],"clause_intelligence":{"clauses_count":18,"risk_patterns_count":1,"stance_events_count":1,"patterns_by_family":{"privacy_sharing":1},"risk_summary":{"high":1},"evidence":[{"pattern_key":"personal_data_sale","pattern_family":"privacy_sharing","risk_rating":"high","confidence":"high","stance_key":"data_sharing","stance_value":"sale_or_sell","evidence":"Conifer gives you one bill across every model you used, local and cloud. Local inference on your own hardware is the free tier: it costs nothing to run and adds nothing to the bill. When you use paid cloud models, billing runs through the payment processor. The payment processor holds your card details; Conifer never sees them. We receive a customer reference and the amounts charged, which we keep next to your acc...","reason":"The clause permits sale of personal data or information.","matcher_version":"clause-intelligence-2026-06-17.1","citation":{"surface":"subprocessors_data_sharing","quote":"Conifer gives you one bill across every model you used, local and cloud. Local inference on your own hardware is the free tier: it costs nothing to run and adds nothing to the bill. When you use paid cloud models, billing runs through the payment processor. The payment processor holds your card details; Conifer never sees them. We receive a customer reference and the amounts charged, which we keep next to your account so we can show you what you spent and on which models. We do not sell this data.","source_url":"https://www.conifer.build/privacy/","deep_link":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20gives%20you,not%20sell%20this%20data.","structural_citation":"Privacy Policy › “Billing”","citation_basis":"heading_path","char_start":11039,"char_end":11543}}]},"tier_conditions":[{"tier":"Api","surface":"privacy_data_use","verdict":"improves","confidence":"high","citation_count":1,"citations":[{"finding_id":"b107e198-a2a2-4a71-8b2f-e651877614fc","quote":" The three questions that decide whether you can use Conifer professionally, answered up front. The desktop app answers the same three from live state in Settings → Privacy & data.\n Does anything from my local chats leave my machine? By default, yes: Conifer shares conversation data and anonymized routing signals to improve routing, and usage data (including prompt text during the demo, captured only after best-effort on-device redaction — pattern redaction cannot catch everything). Turns that look sensitive are excluded on-device from every content channel: chat-content sharing and the usage prompt channel both apply the same sensitivity check before anything is stored or sent. Turn the sharing settings off in the app — or flip its Local-only switch — and the answer becomes no: local chats stay on your machine, enforced at every send path, and the app&#x27;s egress ledger shows what actually left. \n Can I control what stays local? Yes. Prompts that look sensitive stay local by default (keep-sensitive-local); any chat can be pinned On-device; and the Local-only switch sets the whole app offline — chats, voice, sharing uploads, and scheduled workflow cloud steps make no cloud calls, checked at each send path (your signed-in session itself stays alive). When the router escalates a query, that one prompt and its context go to the provider for that single query — disclosed in the run, never silent. \n I brought my own API keys — whose terms apply? ","source_url":"https://www.conifer.build/privacy/","deep_link":"https://www.conifer.build/privacy/#:~:text=%20The%20three%20questions,whose%20terms%20apply%3F%20","structural_citation":"Privacy Policy › “Three questions answered first”"}]},{"tier":"Free","surface":"privacy_data_use","verdict":"improves","confidence":"high","citation_count":2,"citations":[{"finding_id":"64ec8be3-c586-4e76-9af5-2fbc1fdd36ce","quote":" Conifer routes each query to the cheapest model that can do the job, and the cheapest lane is the free one on your own hardware. So by default, everyday queries run locally: the model, the prompt, and the generated tokens stay on your machine. The engine does not phone home. It has no analytics, no error reporting, no model-usage telemetry, and no background ping.\n A local query touches the network zero times, unless one of the sharing settings is on (the usage-data setting above, or section 03). Those settings are on by default and each can be turned off in the app — the app&#x27;s Local-only switch turns every one of them off at the wire in a single step. The only other outbound calls the engine makes are ones you start: downloading the weights for a model you asked to install, and checking for updates when you ask it to. Neither call carries your prompts or your data.","source_url":"https://www.conifer.build/privacy/","deep_link":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20routes%20each,prompts%20or%20your%20data.","structural_citation":"Privacy Policy › “Local inference stays local”"},{"finding_id":"8ae4d6d2-29f7-484e-9f10-8f78d601e275","quote":" Conifer is the front door to all inference: a router sends each query to the cheapest model that can do the job, starting with the free ones on your own hardware. By default everyday queries run locally, so the model, the prompt, and the tokens stay on your machine. The router may send a query to a cloud model when local is not good enough, and only if you allowed the cloud at all. This page covers exactly what can cross the wire, when, and to whom.","source_url":"https://www.conifer.build/privacy/","deep_link":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20is%20the,when%2C%20and%20to%20whom.","structural_citation":"Privacy Policy › “Local by default. The cloud only when you allow it.”"}]},{"tier":"Free","surface":"subprocessors_data_sharing","verdict":"improves","confidence":"high","citation_count":1,"citations":[{"finding_id":"3bd16edc-9179-4bad-b005-ba089a4288a5","quote":" Conifer gives you one bill across every model you used, local and cloud. Local inference on your own hardware is the free tier: it costs nothing to run and adds nothing to the bill. When you use paid cloud models, billing runs through the payment processor.\n The payment processor holds your card details; Conifer never sees them. We receive a customer reference and the amounts charged, which we keep next to your account so we can show you what you spent and on which models. We do not sell this data.","source_url":"https://www.conifer.build/privacy/","deep_link":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20gives%20you,not%20sell%20this%20data.","structural_citation":"Privacy Policy › “Billing”"}]},{"tier":"Plus","surface":"privacy_data_use","verdict":"improves","confidence":"high","citation_count":2,"citations":[{"finding_id":"bfedb51e-cc47-4942-bb43-d0d3eee65c08","quote":"Each routed question sends numbers and categories describing the decision (request shape, timings, which side answered, what you did next), plus an irreversible fingerprint (one-way hash) of your message and system prompt, which cannot reconstruct the text. The text of what you typed and what a model wrote is never sent. Tied to your account; shown in the app&#x27;s egress count. \n Cloud chat content (on by default, consent-versioned) On by default; turn it off anytime. The cloud lane necessarily transmits your prompt to serve the request (see Cloud-lane inference above); this consent governs whether we may retain it: encrypted per-account, erasable on withdrawal in one step. Retention limits and audit guarantees: section 03 below. \n Local chat content (on by default, separate) On by default and asked separately; turn it off anytime. Local conversations never leave your machine unless you allow sharing them for model improvement; sensitive-looking conversations are excluded on-device, and a conversation that ever looked sensitive never uploads its history. \n Your own API keys (BYOK) Your provider, under YOUR agreement with them. Your key is stored encrypted and used only to call your provider for your request; traffic passes through Conifer&#x27;s gateway (2.5% fee). HIPAA or no-training terms you hold with that provider govern the provider leg. Conifer keeps no conversation content from these calls unless the cloud chat content consent is on. ","source_url":"https://www.conifer.build/privacy/","deep_link":"https://www.conifer.build/privacy/#:~:text=Each%20routed%20question%20sends,consent%20is%20on.%20","structural_citation":"Privacy Policy › “The whole story one table”"},{"finding_id":"71c183fd-ed3b-47e4-b83c-bf1a6dc23011","quote":" Everything in this section is on by default and can be turned off individually in the app&#x27;s settings, one consent at a time; no setting here implies another, and turning one off never turns off the rest. Each grant is versioned: you agree under a stated version of the consent terms, and if the terms change, sharing pauses until you re-confirm under the new ones. Every upload any of these settings causes is counted in the app&#x27;s egress log.\n routing signals Numbers and categories describing each routing decision (request shape, timings, which side answered, what you did next), plus an irreversible fingerprint (a one-way hash) of your message and of the system prompt. A fingerprint cannot reconstruct the text; we use it only to spot duplicates and join records. The text of what you typed and what a model wrote is never sent. Tied to your account. \n cloud chat content A retention consent, not a new transmission: the cloud lane already carries your prompt to serve the request (section 02). With this consent we may keep that request and the model&#x27;s answer, encrypted with a per-account key, to improve routing and models. Without it, cloud content is dropped after a short operational window. Withdrawal is one step and erases what was kept by destroying your account&#x27;s encryption key. \n local chat content Asked separately, and never implied by anything else. Local conversations stay on your machine unless you allow sharing them, encrypted per-account, to improve the models everyone runs locally. ","source_url":"https://www.conifer.build/privacy/","deep_link":"https://www.conifer.build/privacy/#:~:text=%20Everything%20in%20this,everyone%20runs%20locally.%20","structural_citation":"Privacy Policy › “Routing signals and chat content”"}]},{"tier":"Standard","surface":"privacy_data_use","verdict":"conditional","confidence":"high","citation_count":1,"citations":[{"finding_id":"6e28a655-49d1-4de4-a29f-097ddbd2b0c1","quote":" The website is hosted by a static-site host that keeps standard request logs (IP, user agent, requested URL, response status) for abuse handling. If first-party site analytics are enabled they are aggregate only, used to understand traffic, not to profile individuals. The website is separate from the engine: nothing you do on the site reaches your local models.","source_url":"https://www.conifer.build/privacy/","deep_link":"https://www.conifer.build/privacy/#:~:text=%20The%20website%20is,reaches%20your%20local%20models.","structural_citation":"Privacy Policy › “What the website logs”"}]},{"tier":"Standard","surface":"subprocessors_data_sharing","verdict":"conditional","confidence":"high","citation_count":1,"citations":[{"finding_id":"4678617b-d034-4aea-ba55-662238301659","quote":"\n Account and sign-in The account system. Your email and the timestamps of sign-in, so you have one account across devices. Optional for local-only use where it can be. No passwords stored, no browsing profile. \n Billing The payment processor, for consolidated billing across the models you used. It holds your card details; Conifer never sees them. We receive a customer reference and the amounts, not the card. \n Model downloads The weights host, started by you, only for the models you ask to install. \n Update check The release host, only when you check for updates. \n The website Standard web-server request logs from the host for abuse handling. First-party site analytics if enabled, aggregate only. No selling of data. ","source_url":"https://www.conifer.build/privacy/","deep_link":"https://www.conifer.build/privacy/#:~:text=%20Account%20and%20sign-in,selling%20of%20data.%20","structural_citation":"Privacy Policy › “The whole story one table”"}]}],"disclaimer":"Informational only, not legal advice. Every finding is a verbatim quote from a fully-read, gate-verified document; verify via snapshot_sha256 + wayback_url. Partially-verified platforms show findings only from their verified document(s).","benchmark":{"disclaimer":"Automated assessment against a published rubric — not legal advice.","bands":[]},"@jsonld":{"@context":"https://schema.org","@type":"Dataset","name":"Conifer — AI policy risk findings","description":"Verified, cited policy findings for Conifer across 13 risk surfaces.","url":"https://airinetwork.com/platform/conifer","creator":{"@type":"Organization","name":"AIRIN","url":"https://airinetwork.com"},"isAccessibleForFree":true,"license":"https://airinetwork.com/terms","additionalProperty":[{"@type":"PropertyValue","name":"verification","value":"partially_verified"},{"@type":"PropertyValue","name":"tier_condition_count","value":6}],"hasPart":[{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/prompt-ownership-25875de3114d60ced8d5","text":"Yours. Your key is stored encrypted and used only to call your provider for your request. Traffic passes through Conifer's gateway (2.5% fee) and your prompt goes to your provider under your agreement with them — HIPAA or no-training terms you hold with that provider govern that leg. Conifer keeps no conversation content from these calls unless the cloud chat content setting is on. ","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-41e2c05d350be0581806","text":"Each routed question sends numbers and categories describing the decision (request shape, timings, which side answered, what you did next), plus an irreversible fingerprint (one-way hash) of your message and system prompt, which cannot reconstruct the text. The text of what you typed and what a model wrote is never sent. Tied to your account; shown in the app's egress count. \n Cloud chat content (on by default, consent-versioned) On by default; turn it off anytime. The cloud lane necessarily transmits your prompt to serve the request (see Cloud-lane inference above); this consent governs whether we may retain it: encrypted per-account, erasable on withdrawal in one step. Retention limits and audit guarantees: section 03 below. \n Local chat content (on by default, separate) On by default and asked separately; turn it off anytime. Local conversations never leave your machine unless you allow sharing them for model improvement; sensitive-looking conversations are excluded on-device, and a conversation that ever looked sensitive never uploads its history. \n Your own API keys (BYOK) Your provider, under YOUR agreement with them. Your key is stored encrypted and used only to call your provider for your request; traffic passes through Conifer's gateway (2.5% fee). HIPAA or no-training terms you hold with that provider govern the provider leg. Conifer keeps no conversation content from these calls unless the cloud chat content consent is on. ","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-1b65fa8460a1d3783be1","text":" Conifer routes each query to the cheapest model that can do the job, and the cheapest lane is the free one on your own hardware. So by default, everyday queries run locally: the model, the prompt, and the generated tokens stay on your machine. The engine does not phone home. It has no analytics, no error reporting, no model-usage telemetry, and no background ping.\n A local query touches the network zero times, unless one of the sharing settings is on (the usage-data setting above, or section 03). Those settings are on by default and each can be turned off in the app — the app's Local-only switch turns every one of them off at the wire in a single step. The only other outbound calls the engine makes are ones you start: downloading the weights for a model you asked to install, and checking for updates when you ask it to. Neither call carries your prompts or your data.","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-43d556ae481d57572855","text":" Everything that does or does not cross the wire, in one glance: the local lane where it does not, and the cloud lane and account system where it can. The sections below say the same thing in full.\n Local inference Stays on your machine. The default lane for everyday queries: the model, the prompt, and the generated tokens run on your hardware and are not sent anywhere. The engine has no analytics, no error reports, no usage telemetry, and no phone-home. \n Cloud-lane inference The model provider you chose, and only if you allowed the cloud at all. The prompt and context for that one query cross the wire only when the router escalates a query local could not handle well. Disclosed in the run, never silent. Never happens in privacy-first mode. \n Usage data (on by default) On by default; turn it off anytime in the app's settings. While on, the app sends anonymized usage notes and, during the demo phase, the text of your prompts. Your device strips text that looks like keys, tokens, passwords, emails, or card numbers first; that redaction is best-effort, so assume anything you type may be included. This pipeline carries no model outputs and none of your files, and it is keyed to a random anonymous id, not your account. It is separate from the account-tied routing signals below, and the two are not joined. Every upload shows in the app's egress count. \n Routing signals (on by default) On by default; turn it off anytime. ","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-11a1973884da78a62c5f","text":" Conifer is the front door to all inference: a router sends each query to the cheapest model that can do the job, starting with the free ones on your own hardware. By default everyday queries run locally, so the model, the prompt, and the tokens stay on your machine. The router may send a query to a cloud model when local is not good enough, and only if you allowed the cloud at all. This page covers exactly what can cross the wire, when, and to whom.","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-2f98e3fa273fb8a5c331","text":" ┌─ your machine \n │ the local model · your prompts · the tokens \n │ your files · your keys · your chats \n └─ stays here by default. \n cloud lane ──▸── only a query you allowed, only when local is not enough. ","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-84bfd6b152d587fbc73f","text":" The three questions that decide whether you can use Conifer professionally, answered up front. The desktop app answers the same three from live state in Settings → Privacy & data.\n Does anything from my local chats leave my machine? By default, yes: Conifer shares conversation data and anonymized routing signals to improve routing, and usage data (including prompt text during the demo, captured only after best-effort on-device redaction — pattern redaction cannot catch everything). Turns that look sensitive are excluded on-device from every content channel: chat-content sharing and the usage prompt channel both apply the same sensitivity check before anything is stored or sent. Turn the sharing settings off in the app — or flip its Local-only switch — and the answer becomes no: local chats stay on your machine, enforced at every send path, and the app's egress ledger shows what actually left. \n Can I control what stays local? Yes. Prompts that look sensitive stay local by default (keep-sensitive-local); any chat can be pinned On-device; and the Local-only switch sets the whole app offline — chats, voice, sharing uploads, and scheduled workflow cloud steps make no cloud calls, checked at each send path (your signed-in session itself stays alive). When the router escalates a query, that one prompt and its context go to the provider for that single query — disclosed in the run, never silent. \n I brought my own API keys — whose terms apply? ","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-9235947144c12a4c64cf","text":" The router may escalate a query to a cloud model when a local model is not good enough for it, and only if you allowed the cloud at all. When that happens, the prompt and the context for that one query go to the model provider you chose. We say so in the run; it is never silent.\n Once a query is on the cloud lane, the provider you chose handles it under their own terms, including whatever logging and retention their policy describes. Read the policy of the provider you route to. Conifer passes the query through; it does not keep its own copy unless you separately said yes to cloud chat content retention (section 03), and outside that consent the content is dropped after a short operational window.\n Privacy-first mode pins every query to a local model. Nothing crosses the wire in that mode: the cloud lane is not reached, no matter what the router would otherwise have chosen.","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-d4483b344ea007c09e63","text":" Everything in this section is on by default and can be turned off individually in the app's settings, one consent at a time; no setting here implies another, and turning one off never turns off the rest. Each grant is versioned: you agree under a stated version of the consent terms, and if the terms change, sharing pauses until you re-confirm under the new ones. Every upload any of these settings causes is counted in the app's egress log.\n routing signals Numbers and categories describing each routing decision (request shape, timings, which side answered, what you did next), plus an irreversible fingerprint (a one-way hash) of your message and of the system prompt. A fingerprint cannot reconstruct the text; we use it only to spot duplicates and join records. The text of what you typed and what a model wrote is never sent. Tied to your account. \n cloud chat content A retention consent, not a new transmission: the cloud lane already carries your prompt to serve the request (section 02). With this consent we may keep that request and the model's answer, encrypted with a per-account key, to improve routing and models. Without it, cloud content is dropped after a short operational window. Withdrawal is one step and erases what was kept by destroying your account's encryption key. \n local chat content Asked separately, and never implied by anything else. Local conversations stay on your machine unless you allow sharing them, encrypted per-account, to improve the models everyone runs locally. ","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-d909dda008784accc396","text":" One account, one interface across the models you use. Signing in involves the account system, which holds:\n email The address you signed in with. Used to identify your account and contact you about it. No browsing profile is built from it. \n created_at Timestamp of first sign-in. \n last_sign_in Timestamp of the most recent sign-in. \n An account is optional for local-only use where it can be: running a local model does not require signing in. The account exists so that consolidated billing and cloud routing can be tied to you when you use them.","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-fbf87c8aef53711f1098","text":" The marketplace, where you pick and enable models, and the cloud routing lane are the two places a query can leave your machine. Choosing a model in the marketplace involves your account. Sending a query to a chosen cloud model involves that provider, as described in section 02.\n The local tier and privacy-first mode are the places a query does not leave your machine. If you never allow the cloud, or you pin to privacy-first mode, the router keeps every query on your hardware.","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-d8174d2356367fcaa821","text":" The website is hosted by a static-site host that keeps standard request logs (IP, user agent, requested URL, response status) for abuse handling. If first-party site analytics are enabled they are aggregate only, used to understand traffic, not to profile individuals. The website is separate from the engine: nothing you do on the site reaches your local models.","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/privacy-data-use-644a96ff36612a6d5203","text":" Conifer is not intended for children under 13 and does not knowingly collect data from them. If you learn that a child has signed up, write to the address above and the account will be deleted.","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/moderation-enforcement-550e2a7fccb8427d1d48","text":" For regulated teams, Conifer supports fleet governance: spend caps, and a routing policy that can be set to local-only so no query on those machines is allowed to reach a cloud provider. The policy is attestable and enforced client-side, on the device, so a machine can report exactly which routing posture it is under.\n Under a local-only fleet policy, the cloud lane is closed for every user on those machines, and inference stays on the endpoint.","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/subprocessors-data-sharing-a793299effb3b7246827","text":"\n Account and sign-in The account system. Your email and the timestamps of sign-in, so you have one account across devices. Optional for local-only use where it can be. No passwords stored, no browsing profile. \n Billing The payment processor, for consolidated billing across the models you used. It holds your card details; Conifer never sees them. We receive a customer reference and the amounts, not the card. \n Model downloads The weights host, started by you, only for the models you ask to install. \n Update check The release host, only when you check for updates. \n The website Standard web-server request logs from the host for abuse handling. First-party site analytics if enabled, aggregate only. No selling of data. ","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/subprocessors-data-sharing-50ac0900eed8f70b26d1","text":" Conifer gives you one bill across every model you used, local and cloud. Local inference on your own hardware is the free tier: it costs nothing to run and adds nothing to the bill. When you use paid cloud models, billing runs through the payment processor.\n The payment processor holds your card details; Conifer never sees them. We receive a customer reference and the amounts charged, which we keep next to your account so we can show you what you spent and on which models. We do not sell this data.","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}},{"@type":"Quotation","@id":"https://airinetwork.com/platform/conifer/finding/audit-rights-dpa-residency-f0ac81bcffbbcdd4015d","text":" Write to [email protected] from the address tied to your account and ask for a copy, a correction, or a deletion of the account and billing records held for you. We will do it within 30 days and confirm when it is done. EU and UK residents have the rights enumerated under GDPR; California residents have the rights enumerated under CCPA. Both reduce, in practice, to the email above. Local data on your own machine is yours to delete directly; the engine keeps no copy of it anywhere else.","isBasedOn":"https://www.conifer.build/privacy/","dateCreated":"2026-07-20T00:07:37.39132+00:00","identifier":{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"}}],"variableMeasured":[{"@type":"PropertyValue","name":"prompt_ownership","value":"unknown","description":"Yours. Your key is stored encrypted and used only to call your provider for your request. Traffic passes through Conifer's gateway (2.5% fee) and your prompt goes to your provider under your agreement with them — HIPAA or no-training terms you hold with that provider govern that leg. Conifer keeps no conversation content from these calls unless the cloud chat content setting is on. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Three questions answered first”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=Yours.%20Your%20key%20is,setting%20is%20on.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":"Each routed question sends numbers and categories describing the decision (request shape, timings, which side answered, what you did next), plus an irreversible fingerprint (one-way hash) of your message and system prompt, which cannot reconstruct the text. The text of what you typed and what a model wrote is never sent. Tied to your account; shown in the app's egress count. \n Cloud chat content (on by default, consent-versioned) On by default; turn it off anytime. The cloud lane necessarily transmits your prompt to serve the request (see Cloud-lane inference above); this consent governs whether we may retain it: encrypted per-account, erasable on withdrawal in one step. Retention limits and audit guarantees: section 03 below. \n Local chat content (on by default, separate) On by default and asked separately; turn it off anytime. Local conversations never leave your machine unless you allow sharing them for model improvement; sensitive-looking conversations are excluded on-device, and a conversation that ever looked sensitive never uploads its history. \n Your own API keys (BYOK) Your provider, under YOUR agreement with them. Your key is stored encrypted and used only to call your provider for your request; traffic passes through Conifer's gateway (2.5% fee). HIPAA or no-training terms you hold with that provider govern the provider leg. Conifer keeps no conversation content from these calls unless the cloud chat content consent is on. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “The whole story one table”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=Each%20routed%20question%20sends,consent%20is%20on.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Conifer routes each query to the cheapest model that can do the job, and the cheapest lane is the free one on your own hardware. So by default, everyday queries run locally: the model, the prompt, and the generated tokens stay on your machine. The engine does not phone home. It has no analytics, no error reporting, no model-usage telemetry, and no background ping.\n A local query touches the network zero times, unless one of the sharing settings is on (the usage-data setting above, or section 03). Those settings are on by default and each can be turned off in the app — the app's Local-only switch turns every one of them off at the wire in a single step. The only other outbound calls the engine makes are ones you start: downloading the weights for a model you asked to install, and checking for updates when you ask it to. Neither call carries your prompts or your data.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Local inference stays local”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20routes%20each,prompts%20or%20your%20data."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Everything that does or does not cross the wire, in one glance: the local lane where it does not, and the cloud lane and account system where it can. The sections below say the same thing in full.\n Local inference Stays on your machine. The default lane for everyday queries: the model, the prompt, and the generated tokens run on your hardware and are not sent anywhere. The engine has no analytics, no error reports, no usage telemetry, and no phone-home. \n Cloud-lane inference The model provider you chose, and only if you allowed the cloud at all. The prompt and context for that one query cross the wire only when the router escalates a query local could not handle well. Disclosed in the run, never silent. Never happens in privacy-first mode. \n Usage data (on by default) On by default; turn it off anytime in the app's settings. While on, the app sends anonymized usage notes and, during the demo phase, the text of your prompts. Your device strips text that looks like keys, tokens, passwords, emails, or card numbers first; that redaction is best-effort, so assume anything you type may be included. This pipeline carries no model outputs and none of your files, and it is keyed to a random anonymous id, not your account. It is separate from the account-tied routing signals below, and the two are not joined. Every upload shows in the app's egress count. \n Routing signals (on by default) On by default; turn it off anytime. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “The whole story one table”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20Everything%20that%20does,it%20off%20anytime.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Conifer is the front door to all inference: a router sends each query to the cheapest model that can do the job, starting with the free ones on your own hardware. By default everyday queries run locally, so the model, the prompt, and the tokens stay on your machine. The router may send a query to a cloud model when local is not good enough, and only if you allowed the cloud at all. This page covers exactly what can cross the wire, when, and to whom.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Local by default. The cloud only when you allow it.”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20is%20the,when%2C%20and%20to%20whom."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" ┌─ your machine \n │ the local model · your prompts · the tokens \n │ your files · your keys · your chats \n └─ stays here by default. \n cloud lane ──▸── only a query you allowed, only when local is not enough. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Local by default. The cloud only when you allow it.”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20%E2%94%8C%E2%94%80%20your%20machine,is%20not%20enough.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" The three questions that decide whether you can use Conifer professionally, answered up front. The desktop app answers the same three from live state in Settings → Privacy & data.\n Does anything from my local chats leave my machine? By default, yes: Conifer shares conversation data and anonymized routing signals to improve routing, and usage data (including prompt text during the demo, captured only after best-effort on-device redaction — pattern redaction cannot catch everything). Turns that look sensitive are excluded on-device from every content channel: chat-content sharing and the usage prompt channel both apply the same sensitivity check before anything is stored or sent. Turn the sharing settings off in the app — or flip its Local-only switch — and the answer becomes no: local chats stay on your machine, enforced at every send path, and the app's egress ledger shows what actually left. \n Can I control what stays local? Yes. Prompts that look sensitive stay local by default (keep-sensitive-local); any chat can be pinned On-device; and the Local-only switch sets the whole app offline — chats, voice, sharing uploads, and scheduled workflow cloud steps make no cloud calls, checked at each send path (your signed-in session itself stays alive). When the router escalates a query, that one prompt and its context go to the provider for that single query — disclosed in the run, never silent. \n I brought my own API keys — whose terms apply? ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Three questions answered first”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20The%20three%20questions,whose%20terms%20apply%3F%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" The router may escalate a query to a cloud model when a local model is not good enough for it, and only if you allowed the cloud at all. When that happens, the prompt and the context for that one query go to the model provider you chose. We say so in the run; it is never silent.\n Once a query is on the cloud lane, the provider you chose handles it under their own terms, including whatever logging and retention their policy describes. Read the policy of the provider you route to. Conifer passes the query through; it does not keep its own copy unless you separately said yes to cloud chat content retention (section 03), and outside that consent the content is dropped after a short operational window.\n Privacy-first mode pins every query to a local model. Nothing crosses the wire in that mode: the cloud lane is not reached, no matter what the router would otherwise have chosen.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Cloud-lane routing”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20The%20router%20may,would%20otherwise%20have%20chosen."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Everything in this section is on by default and can be turned off individually in the app's settings, one consent at a time; no setting here implies another, and turning one off never turns off the rest. Each grant is versioned: you agree under a stated version of the consent terms, and if the terms change, sharing pauses until you re-confirm under the new ones. Every upload any of these settings causes is counted in the app's egress log.\n routing signals Numbers and categories describing each routing decision (request shape, timings, which side answered, what you did next), plus an irreversible fingerprint (a one-way hash) of your message and of the system prompt. A fingerprint cannot reconstruct the text; we use it only to spot duplicates and join records. The text of what you typed and what a model wrote is never sent. Tied to your account. \n cloud chat content A retention consent, not a new transmission: the cloud lane already carries your prompt to serve the request (section 02). With this consent we may keep that request and the model's answer, encrypted with a per-account key, to improve routing and models. Without it, cloud content is dropped after a short operational window. Withdrawal is one step and erases what was kept by destroying your account's encryption key. \n local chat content Asked separately, and never implied by anything else. Local conversations stay on your machine unless you allow sharing them, encrypted per-account, to improve the models everyone runs locally. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Routing signals and chat content”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20Everything%20in%20this,everyone%20runs%20locally.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" One account, one interface across the models you use. Signing in involves the account system, which holds:\n email The address you signed in with. Used to identify your account and contact you about it. No browsing profile is built from it. \n created_at Timestamp of first sign-in. \n last_sign_in Timestamp of the most recent sign-in. \n An account is optional for local-only use where it can be: running a local model does not require signing in. The account exists so that consolidated billing and cloud routing can be tied to you when you use them.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Account and sign-in”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20One%20account%2C%20one,when%20you%20use%20them."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" The marketplace, where you pick and enable models, and the cloud routing lane are the two places a query can leave your machine. Choosing a model in the marketplace involves your account. Sending a query to a chosen cloud model involves that provider, as described in section 02.\n The local tier and privacy-first mode are the places a query does not leave your machine. If you never allow the cloud, or you pin to privacy-first mode, the router keeps every query on your hardware.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “The marketplace and routing”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20The%20marketplace%2C%20where,query%20on%20your%20hardware."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" The website is hosted by a static-site host that keeps standard request logs (IP, user agent, requested URL, response status) for abuse handling. If first-party site analytics are enabled they are aggregate only, used to understand traffic, not to profile individuals. The website is separate from the engine: nothing you do on the site reaches your local models.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “What the website logs”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20The%20website%20is,reaches%20your%20local%20models."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"privacy_data_use","value":"unknown","description":" Conifer is not intended for children under 13 and does not knowingly collect data from them. If you learn that a child has signed up, write to the address above and the account will be deleted.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Children”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20is%20not,account%20will%20be%20deleted."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"moderation_enforcement","value":"unknown","description":" For regulated teams, Conifer supports fleet governance: spend caps, and a routing policy that can be set to local-only so no query on those machines is allowed to reach a cloud provider. The policy is attestable and enforced client-side, on the device, so a machine can report exactly which routing posture it is under.\n Under a local-only fleet policy, the cloud lane is closed for every user on those machines, and inference stays on the endpoint.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Enterprise governance”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20For%20regulated%20teams%2C,stays%20on%20the%20endpoint."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"subprocessors_data_sharing","value":"unknown","description":"\n Account and sign-in The account system. Your email and the timestamps of sign-in, so you have one account across devices. Optional for local-only use where it can be. No passwords stored, no browsing profile. \n Billing The payment processor, for consolidated billing across the models you used. It holds your card details; Conifer never sees them. We receive a customer reference and the amounts, not the card. \n Model downloads The weights host, started by you, only for the models you ask to install. \n Update check The release host, only when you check for updates. \n The website Standard web-server request logs from the host for abuse handling. First-party site analytics if enabled, aggregate only. No selling of data. ","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “The whole story one table”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20Account%20and%20sign-in,selling%20of%20data.%20"},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"subprocessors_data_sharing","value":"low","description":" Conifer gives you one bill across every model you used, local and cloud. Local inference on your own hardware is the free tier: it costs nothing to run and adds nothing to the bill. When you use paid cloud models, billing runs through the payment processor.\n The payment processor holds your card details; Conifer never sees them. We receive a customer reference and the amounts charged, which we keep next to your account so we can show you what you spent and on which models. We do not sell this data.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Billing”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20Conifer%20gives%20you,not%20sell%20this%20data."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]},{"@type":"PropertyValue","name":"audit_rights_dpa_residency","value":"unknown","description":" Write to [email protected] from the address tied to your account and ask for a copy, a correction, or a deletion of the account and billing records held for you. We will do it within 30 days and confirm when it is done. EU and UK residents have the rights enumerated under GDPR; California residents have the rights enumerated under CCPA. Both reduce, in practice, to the email above. Local data on your own machine is yours to delete directly; the engine keeps no copy of it anywhere else.","additionalProperty":[{"@type":"PropertyValue","name":"confidence","value":"high"},{"@type":"PropertyValue","name":"snapshot_sha256","value":"ae97831138903cbaf61e2bb0ae759e4614d8a0e890c7441cfdaff96f8dfc18a1"},{"@type":"PropertyValue","name":"wayback_url","value":""},{"@type":"PropertyValue","name":"source_url","value":"https://www.conifer.build/privacy/"},{"@type":"PropertyValue","name":"structural_citation","value":"Privacy Policy › “Your rights”"},{"@type":"PropertyValue","name":"citation_basis","value":"heading_path"},{"@type":"PropertyValue","name":"deep_link","value":"https://www.conifer.build/privacy/#:~:text=%20Write%20to%20%5Bemail%26%23160%3Bprotected%5D,of%20it%20anywhere%20else."},{"@type":"PropertyValue","name":"retrieved_at","value":"2026-07-20T00:07:37.39132+00:00"}]}]}}