Privacy Policy
Last updated: June 25, 2026
This policy explains what Common Compute LLC, a Utah limited liability company (“Common Compute”, “we”) collects, why, how we use it, and your rights. It covers customers who submit workloads, providers who run them, and visitors to commoncompute.ai.
1. Plain-English summary
- We do not sell your data. Ever.
- We do not retain your task inputs or outputs by default beyond what is needed to deliver the result.
- Provider machines see only the bytes needed to execute your task — not your email, name, or account metadata.
- We collect the minimum account, billing, and telemetry data required to operate the network.
- Once a job has finished, you can delete its inputs and outputs yourself. Full account deletion and data export are handled by request today, not self-serve.
2. What we collect
Account data
Email, hashed password, display name, role (customer or provider), email-verification state, API key hashes, and audit timestamps. We use this to authenticate you and deliver the service.
Billing data
We use Stripe for payments. Stripe holds your card details; we store only the Stripe customer ID, the last 4 digits of the card (when returned by Stripe), and ledger entries for your usage and earnings. Stripe’s own privacy policy applies to payment processing.
Workload data (customers)
When you submit a job, we process your inputs only as long as needed to dispatch, execute, and return the result. Inputs and outputs are held in Cloudflare R2, which encrypts objects at rest, and are reached through short-lived signed URLs bound to the running job. A daily sweep deletes both once they pass 30 days — that window is enforced in code, not by policy. Once a job has reached a final state you can also delete its payloads yourself with DELETE /v1/jobs/:id/data, or from the job’s page in the dashboard. For anything broader — a date range, or an entire account — email hello@commoncompute.ai; that path is manual today and we do not promise a fixed turnaround for it. Request and response metadata (job ID, workload type, token count, duration, cost, provider ID) is retained for auditing and billing, and outlives the payloads it refers to.
Device telemetry (providers)
The provider app reports device capability (Apple Silicon chip family, unified memory, macOS version, available runtimes), health (CPU/GPU/thermal state), and uptime. We use this to match jobs to capable devices and to surface your earnings accurately. We do not read files, screenshots, clipboard contents, or non-job network traffic.
Website data
We collect standard HTTP logs (IP address, user-agent, path, timestamp) for abuse prevention and debugging. Logs are retained for up to 30 days. If we enable a product-analytics tool we will update this policy and announce it via email before turning it on.
3. How we use data
- Authenticate accounts and authorize API requests.
- Match workloads to capable providers and settle per-job billing and earnings.
- Send transactional email (verification, receipts, security notices) via Cloudflare Email Service.
- Prevent fraud, abuse, and violations of the acceptable-use policy.
- Improve reliability and performance of the network.
We do not use your inputs, outputs, or telemetry to train or fine-tune machine-learning models.
4. Subprocessors
We use a small number of well-established vendors to operate the service. Each is bound by a data processing agreement and processes personal data only on our instruction:
- Cloudflare (Workers, D1, R2, Durable Objects, Email Service) — application hosting, storage, and transactional email delivery.
- Stripe — payment processing.
- Independent provider operators — task execution on their own Apple Silicon Macs. The assigned machine processes your input in plaintext; its operator controls it and we do not.
We will announce material subprocessor changes in this policy at least 14 days before they take effect.
5. Your rights
Depending on where you live, you may have rights under GDPR, CCPA, or other laws to access, correct, port, or delete your personal data; to object to certain processing; and to lodge a complaint with a supervisory authority. Email hello@commoncompute.ai with the subject line “Privacy request” and we will respond within 30 days.
6. Security
Passwords are hashed with PBKDF2-HMAC-SHA256 (100,000 iterations, salted and peppered); API keys are hashed on storage; all traffic to the API is over TLS. Task inputs and outputs are held in encrypted object storage with short-lived presigned URLs. Provider devices fetch job inputs only through a gate that permits HTTPS to public hosts and refuses private, loopback, and link-local addresses even across redirects. Report security issues to security@commoncompute.ai; we acknowledge within 7 days.
7. International transfers
Our service runs on Cloudflare’s global edge. Depending on routing, your data may be processed in the United States, the European Union, or other regions where Cloudflare operates data centers. Transfers from the EEA or UK rely on Standard Contractual Clauses.
8. Children
The service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.
9. Changes
We may update this policy. Material changes will be announced by email to the address on your account at least 14 days before they take effect.
10. Contact
Common Compute LLC — Utah, USA. hello@commoncompute.ai