CommonCompute
Get startedDownload the Mac app
Privacy

Privacy Policy

Last updated: June 25, 2026

This policy explains what Common Compute LLC, a Utah limited liability company (“Common Compute”, “we”) collects, why, how we use it, and your rights. It covers customers who submit workloads, providers who run them, and visitors to commoncompute.ai.

Privacy at a glance
What the app and service collect, in App-Store-card form. The detail is below.
Linked to you
  • Email + display name
  • Hashed password
  • Billing identifiers (Stripe customer ID, last-4 of card)
  • API key hashes
  • Job metadata: workload type, duration, cost, provider ID
Not linked to you
  • Device capability (chip, memory, OS)
  • Anonymous crash + performance reports (Apple MetricKit)
  • HTTP request logs (IP, user-agent, path) — retained ≤30 days
Never collected
  • Your personal files — the app only reads job inputs it fetched itself
  • Screenshots, clipboard, microphone, camera
  • Browsing history, other apps' data
  • Job content used to train ML models
You can turn off
  • Diagnostics (Settings → Advanced → Diagnostics in the Mac app)
  • Email notifications (per your account settings)
  • Provider participation (sign out or quit the app)

1. Plain-English summary

  • We do not sell your data. Ever.
  • We do not retain your task inputs or outputs by default beyond what is needed to deliver the result.
  • Provider machines see only the bytes needed to execute your task — not your email, name, or account metadata.
  • We collect the minimum account, billing, and telemetry data required to operate the network.
  • Once a job has finished, you can delete its inputs and outputs yourself. Full account deletion and data export are handled by request today, not self-serve.

2. What we collect

Account data

Email, hashed password, display name, role (customer or provider), email-verification state, API key hashes, and audit timestamps. We use this to authenticate you and deliver the service.

Billing data

We use Stripe for payments. Stripe holds your card details; we store only the Stripe customer ID, the last 4 digits of the card (when returned by Stripe), and ledger entries for your usage and earnings. Stripe’s own privacy policy applies to payment processing.

Workload data (customers)

When you submit a job, we process your inputs only as long as needed to dispatch, execute, and return the result. Inputs and outputs are held in Cloudflare R2, which encrypts objects at rest, and are reached through short-lived signed URLs bound to the running job. A daily sweep deletes both once they pass 30 days — that window is enforced in code, not by policy. Once a job has reached a final state you can also delete its payloads yourself with DELETE /v1/jobs/:id/data, or from the job’s page in the dashboard. For anything broader — a date range, or an entire account — email hello@commoncompute.ai; that path is manual today and we do not promise a fixed turnaround for it. Request and response metadata (job ID, workload type, token count, duration, cost, provider ID) is retained for auditing and billing, and outlives the payloads it refers to.

Device telemetry (providers)

The provider app reports device capability (Apple Silicon chip family, unified memory, macOS version, available runtimes), health (CPU/GPU/thermal state), and uptime. We use this to match jobs to capable devices and to surface your earnings accurately. We do not read files, screenshots, clipboard contents, or non-job network traffic.

Website data

We collect standard HTTP logs (IP address, user-agent, path, timestamp) for abuse prevention and debugging. Logs are retained for up to 30 days. If we enable a product-analytics tool we will update this policy and announce it via email before turning it on.

3. How we use data

  • Authenticate accounts and authorize API requests.
  • Match workloads to capable providers and settle per-job billing and earnings.
  • Send transactional email (verification, receipts, security notices) via Cloudflare Email Service.
  • Prevent fraud, abuse, and violations of the acceptable-use policy.
  • Improve reliability and performance of the network.

We do not use your inputs, outputs, or telemetry to train or fine-tune machine-learning models.

4. Subprocessors

We use a small number of well-established vendors to operate the service. Each is bound by a data processing agreement and processes personal data only on our instruction:

  • Cloudflare (Workers, D1, R2, Durable Objects, Email Service) — application hosting, storage, and transactional email delivery.
  • Stripe — payment processing.
  • Independent provider operators — task execution on their own Apple Silicon Macs. The assigned machine processes your input in plaintext; its operator controls it and we do not.

We will announce material subprocessor changes in this policy at least 14 days before they take effect.

5. Your rights

Depending on where you live, you may have rights under GDPR, CCPA, or other laws to access, correct, port, or delete your personal data; to object to certain processing; and to lodge a complaint with a supervisory authority. Email hello@commoncompute.ai with the subject line “Privacy request” and we will respond within 30 days.

6. Security

Passwords are hashed with PBKDF2-HMAC-SHA256 (100,000 iterations, salted and peppered); API keys are hashed on storage; all traffic to the API is over TLS. Task inputs and outputs are held in encrypted object storage with short-lived presigned URLs. Provider devices fetch job inputs only through a gate that permits HTTPS to public hosts and refuses private, loopback, and link-local addresses even across redirects. Report security issues to security@commoncompute.ai; we acknowledge within 7 days.

7. International transfers

Our service runs on Cloudflare’s global edge. Depending on routing, your data may be processed in the United States, the European Union, or other regions where Cloudflare operates data centers. Transfers from the EEA or UK rely on Standard Contractual Clauses.

8. Children

The service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.

9. Changes

We may update this policy. Material changes will be announced by email to the address on your account at least 14 days before they take effect.

10. Contact

Common Compute LLC — Utah, USA. hello@commoncompute.ai