Skip to content

Privacy Policy

Last updated: June 25, 2026

1. Information We Collect

When you use Denpex, we collect training job logs and failure data that you voluntarily submit through our diagnostic tools. This may include error messages, stack traces, system metrics, and configuration data from your ML training jobs.

We do not collect training data, model weights, training datasets, or proprietary model architectures unless explicitly included in your logs.

2. How We Use Your Information

We use the information we collect to:

  • Provide and maintain our diagnosis services
  • Generate failure analyses and recommended fixes
  • Improve our pattern matching and diagnosis accuracy using de-identified, aggregated failure signatures and confirmed-fix metadata. These de-identified signals. Never your raw logs, and never anything that identifies you or your infrastructure. Are pooled across our fleet so that a failure pattern confirmed on one cluster helps diagnose the same pattern for other customers
  • Send you notifications about diagnosed failures on channels you have explicitly added in Settings (email, SMS, push, Slack, PagerDuty, or webhook)
  • Respond to your requests and support inquiries

We never use your logs to train AI models, and we never share your raw logs or any data that identifies you or your infrastructure. The only signals shared across our fleet are the de-identified, aggregated failure signatures and confirmed fixes described above.

3. Legal Basis for Processing (GDPR)

For customers in the European Economic Area, the UK, or Switzerland, we process your personal data on the following legal bases:

  • Contract: providing the Denpex service you signed up for
  • Legitimate interest: securing the service and preventing fraud and abuse
  • Consent: all analytics and marketing technologies, marketing communications, and optional integration cookies. None of which operate before you opt in
  • Legal obligation: tax, accounting, and compliance with law enforcement requests

4. Data Handling and Security

Your training logs contain sensitive information about your infrastructure and models. We take the following steps to protect your data:

  • Logs are encrypted in transit (TLS 1.3) and at rest (AES-256) by Cloudflare D1
  • We scan for and mask PII / PHI on your side before any log is transmitted (client-side redaction); only the redacted content is sent to our diagnosis service
  • Scale, Growth, and Data Center plans: the Denpex agent can be deployed inside your own VPC (the in-VPC agent option). In that deployment your raw logs stay within your boundary and only de-identified failure signatures (failure type, fix, timestamps) are sent off-cluster
  • Free and Team plans: raw logs are stored encrypted and automatically deleted after 30 days. De-identified failure signatures and resolution metadata are retained for 90 days
  • Data Center customers can supply their own AES-256-GCM encryption keys (BYOK) for sensitive log metadata, and air-gapped Data Center deployments support customer-managed HSM keys. Revoking a key renders the corresponding data unreadable, including to Denpex
  • All access to user data is recorded in a tamper-evident audit log (SHA-256 hash chain) retained for SOC 2 purposes

5. Data Retention

Retention is enforced by a daily scheduled job (see Security). Current values:

  • Raw crash logs (Free and Team): retained for 30 days, then hard-deleted
  • Diagnosis results, failure signatures, and follow-up chat (Free, Team, and Scale): retained for 90 days so you can revisit past incidents
  • Diagnosis history (Growth and Data Center): retained for 365 days. These tiers act as your system of record for training-failure history
  • Alert delivery log (subject, recipient, timestamp): retained for 90 days
  • Rate-limit counters (hashed IP token only): retained for 2 days
  • Login attempts (email + IP, for brute-force defense): retained for 30 days
  • Cookie-consent receipts: retained for 3 years (CIPA limitations window)
  • Audit log (tamper-evident): retained for 2 years for SOC 2 compliance
  • Billing records: retained for 7 years to meet US tax obligations
  • Free plan only: the dashboard history view shows only the last 7 days, even though the underlying data is kept for 90 days. Upgrade to Team to see the full 90-day window
  • Scale, Growth, and Data Center plans (in-VPC agent option): when the agent runs inside your VPC, raw logs stay within your infrastructure; only de-identified failure signatures are stored off-cluster, and you control their retention
  • Account data: deleted immediately when you delete your account via Settings → Account. No 30-day grace period — deletion is hard and irreversible

6. Sub-Processors and International Transfers

We use a small set of sub-processors (hosting, payment, email). The full list is at /legal/subprocessors. We give 30 days' notice of changes via email and the changelog RSS feed.

For transfers from the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on the EU Standard Contractual Clauses, included in our DPA.

7. Information Sharing

We do not sell, trade, or rent your training logs or diagnostic data to third parties, and we never share your raw logs. As described in Section 2, we do pool de-identified, aggregated failure signatures and confirmed fixes across our fleet so that a pattern confirmed on one cluster improves diagnosis for all customers. These signals contain nothing that identifies you or your infrastructure.

8. Cookies and Tracking

We use essential cookies for authentication and session management. No analytics, advertising, marketing, or session-recording technology loads on page load. We do not run a Meta/Facebook pixel, a TikTok pixel, or any session-recording tool. Any optional analytics or marketing technology runs only after your prior, affirmative opt-in in our cookie banner, and never before. To the extent the California Invasion of Privacy Act (CIPA) or pen register / trap-and-trace rules require consent, that consent is obtained before any such technology operates. See our cookie policy.

9. Your Rights (GDPR & CCPA)

You have the right to:

  • Access your personal data
  • Correct inaccurate personal data
  • Delete your personal data (right to be forgotten)
  • Restrict or object to processing
  • Data portability
  • Withdraw consent at any time
  • Lodge a complaint with your supervisory authority

To exercise any of these rights, contact privacy@denpex.com. We respond within 30 days.

10. Children's Privacy

Denpex is not directed at children under 16. We do not knowingly collect personal data from children.

11. Changes to this Policy

We may update this policy. Material changes will be notified via email and announced on the changelog. Continued use after changes constitutes acceptance.

12. Contact Us

For privacy-related questions, contact our Data Protection Officer at privacy@denpex.com.

Denpex, Inc. · 2261 Market Street #5030 · San Francisco, CA 94114 · USA