CommonCompute
Get startedExplore workloads
Privacy

Privacy Policy

Last updated: September 19, 2026

This policy explains what Common Compute LLC, a Utah limited liability company (“Common Compute”, “we”) collects, why, how we use it, and your rights. It covers customers who submit workloads, providers who run them, and visitors to commoncompute.ai.

Privacy at a glance
What the app and service collect, in App-Store-card form. The detail is below.
Linked to you
  • Email + display name
  • Hashed password
  • Billing identifiers (Stripe customer ID, last-4 of card)
  • API key hashes
  • Job metadata: workload type, duration, cost, provider ID
Not linked to you
  • Device capability (chip, memory, OS)
  • Anonymous crash + performance reports (Apple MetricKit)
  • HTTP request logs (IP, user-agent, path) — retained ≤30 days
Never collected
  • Your personal files — the app only reads job inputs it fetched itself
  • Screenshots, clipboard, microphone, camera
  • Browsing history, other apps' data
  • Job content used to train ML models
You can turn off
  • Diagnostics (Settings → Advanced → Diagnostics in the macOS app)
  • Email notifications (per your account settings)
  • Provider participation (sign out or quit the app)

1. Plain-English summary

  • We do not sell your data. Ever.
  • Task inputs and outputs follow the deletion schedule below; they are not guaranteed to disappear immediately after execution.
  • Provider machines see only the bytes needed to execute your task — not your email, name, or account metadata.
  • We collect the minimum account, billing, and telemetry data required to operate the network.
  • Once a job has finished, you can delete its inputs and outputs yourself. You can also delete your whole account from Settings — it is purged 7 days later, and you can cancel before then. Data export is still handled by request.

2. What we collect

Account data

Email, hashed password, display name, role (customer or provider), email-verification state, API key hashes, and audit timestamps. We use this to authenticate you and deliver the service.

Billing data

We use Stripe for payments. Stripe holds your card details; we store only the Stripe customer ID, the last 4 digits of the card (when returned by Stripe), and ledger entries for your usage and earnings. Stripe’s own privacy policy applies to payment processing.

Workload data (customers)

When you submit a job, we process your inputs only as long as needed to dispatch, execute, and return the result. Inputs and outputs are held in Cloudflare R2, which encrypts objects at rest, and are reached through short-lived signed URLs bound to the running job. Inputs for terminal jobs become eligible for an early purge after a one-hour grace period; a separate sweep deletes stored task artifacts after 30 days. These are outer operational controls, not a promise of immediate deletion. Once a job has reached a final state you can also delete its payloads yourself with DELETE /v1/jobs/:id/data, or from the job’s page in the dashboard. To delete the whole account, use Settings → Danger zone: we confirm your password, schedule the deletion 7 days out, and email you a link that cancels it without signing in. On that date we delete your job payloads from object storage, your API keys and credentials, your chat history, your devices’ identifying details, and your profile. Request and response metadata (job ID, workload type, token count, duration, cost, provider ID) is retained for auditing and billing, and outlives the payloads it refers to.

Device telemetry (providers)

The provider app reports device capability (Apple Silicon chip family, unified memory, macOS version, available runtimes), health (CPU/GPU/thermal state), and uptime. We use this to match jobs to capable devices and to surface your earnings accurately. We do not read files, screenshots, clipboard contents, or non-job network traffic.

Website data

We collect standard HTTP logs (IP address, user-agent, path, timestamp) for abuse prevention and debugging. Logs are retained for up to 30 days. If we enable a product-analytics tool we will update this policy and announce it via email before turning it on.

3. How we use data

  • Authenticate accounts and authorize API requests.
  • Match workloads to capable providers and settle per-job billing and earnings.
  • Send transactional email (verification, receipts, security notices) via Cloudflare Email Service.
  • Prevent fraud, abuse, and violations of the acceptable-use policy.
  • Improve reliability and performance of the network.

We do not use your inputs, outputs, or telemetry to train or fine-tune machine-learning models.

4. Subprocessors

We use the following parties to operate the Service. Their role depends on the data and purpose. Common Compute determines the purposes of account, security, fraud-prevention, billing, tax, legal, and platform governance records. For Customer Content covered by a separately signed DPA, the signed order may define Common Compute as a processor or service provider for the documented workload instructions.

  • Cloudflare (Workers, D1, R2, Durable Objects, Email Service) — application hosting, storage, and transactional email delivery.
  • Stripe — payment processing.
  • Independent provider operators — task execution on their own compatible Mac computers with Apple silicon. The assigned machine processes the plaintext needed for the Task; its operator controls it and we do not.

The current Provider Agreement is published for acceptance, but fleet-wide enforcement remains off while coverage is collected. New Devices remain out of dispatch until their account accepts. A reviewed United States DPA framework is available to qualified business customers by separately signed order; it is not automatically incorporated into the Terms. Review this page before using the Service because vendors and provider participation may change as the beta develops.

5. Your rights

Depending on applicable law, you may have rights to confirm processing; access, correct, obtain, or delete personal data; opt out of certain sale, targeted-advertising, or profiling activity; withdraw consent; or appeal a decision. We do not sell personal data or use Customer Content for targeted advertising. Account deletion is available from Settings → Danger zone. For anything else, email contact@commoncompute.ai with the subject line “Privacy request” and we will respond within 30 days.

What deletion does not cover

Three things deliberately survive an account deletion, and we would rather name them than let you discover them.

Billing and tax records. Invoice lines, ledger entries, Stripe customer references and dispute records are kept. We are required to retain them, and both GDPR Art. 17(3)(b) and CCPA carve this out. They reference your payloads by ID and hash; they do not contain them.

Your email suppression record. If you have unsubscribed or bounced, we keep the minimal record of that. Erasing it would re-enable emailing an address that asked us to stop — the erasure request would undo your own objection.

Copies on provider machines. A job that ran on a provider’s Mac was written to that machine’s disk. The Provider Software performs terminal cleanup and the Provider Agreement prohibits retention. We cannot guarantee remote erasure of an unreachable or provider-preserved copy after the Task. Account deletion covers systems we control and triggers the documented provider obligations; it does not prove every independent-device replica has disappeared.

6. Security

Passwords are hashed with PBKDF2-HMAC-SHA256 (100,000 iterations, salted and peppered); API keys are hashed on storage; all traffic to the API is over TLS. Task inputs and outputs are held in encrypted object storage with short-lived presigned URLs. Provider devices fetch job inputs only through a gate that permits HTTPS to public hosts and refuses private, loopback, and link-local addresses even across redirects. Report security issues to contact@commoncompute.ai; we acknowledge within 7 days.

7. International transfers

The Service runs on Cloudflare’s global edge. Depending on routing, data may be processed in the United States or other regions where Cloudflare operates. The standard DPA framework does not include Standard Contractual Clauses, the UK Addendum, or another international transfer mechanism unless a signed order expressly adds one. Do not use the beta for data that requires an arrangement not fully executed before submission.

8. Children

The service is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.

9. Changes

We may update this policy. Material changes will be announced by email to the address on your account at least 14 days before they take effect.

10. Contact

Common Compute LLC — Utah, USA. contact@commoncompute.ai