Privacy policy

Last updated 22 September 2026

This policy explains what Fermi Technologies Inc. collects when you use Kill Switch, why we hold it, and what you can do about it. Kill Switch is a safety product, so much of what it stores exists specifically so that you can prove later what your AI systems did.

1. Who we are

Fermi Technologies Inc. is a Delaware corporation. In this document, Fermi, we, and us mean that company. You and your mean the organization that holds a Kill Switch account, and the people who use it under that account.

For customers in the European Economic Area and the United Kingdom, Fermi acts as a data processor for the message content you route through the service, and as a data controller for your account and billing records.

2. What we collect

Account data: the email addresses, names and roles of the people you add to your organization, plus your billing details. We keep this for as long as your account is open.

Message data: the content of the messages you send to the screening endpoint, the scores returned for them, the verdict, and the reason. This is the heart of the product. If you would rather not store the message text itself, you can switch your organization to hash-only mode in Settings, and we will store only a SHA-256 hash of each message. The hash chain still verifies in that mode, but transcripts stop being readable.

Operational data: API request logs, timestamps, latency, IP addresses and error traces, which we use to run and debug the service.

3. Why we keep an unchangeable log

The events and halts tables are insert-only by design. Update and delete are revoked from every database role, a trigger rejects them, and every row is hash-chained to the row before it. This is what lets you show a regulator or an enterprise buyer that a record was not edited after the fact.

One consequence is worth being plain about: within your retention window, we cannot selectively edit or delete individual rows in that log without breaking the chain and destroying its evidential value. If you need content removed sooner, use hash-only mode so that no readable content is written in the first place, or ask us to delete the entire organization.

4. Retention and deletion

Each organization sets its own retention period, which defaults to 90 days. When a record passes that period it is removed on a scheduled job.

You can ask us to delete your whole organization at any time. We remove the account, the members, the deployments and the full event log within 30 days, apart from records we are required to keep for tax and accounting purposes.

5. Who we share it with

We use Supabase for database hosting, authentication and realtime delivery, and a model provider for scoring. Which model provider depends on your configuration: on the hosted plans it is a commercial inference provider, and on Enterprise you can run the scorer entirely on your own infrastructure so that message content never leaves it.

We do not sell your data, and we do not use the content of your messages to train models.

Free-tier model endpoints are a special case. Some of them may log or train on the prompts they receive. They are suitable for evaluation only, and you should never route real customer conversations through one.

6. Where the data sits

Hosted data is stored in the United States by default. EU data residency is available on Enterprise plans.

For transfers out of the European Economic Area we rely on the European Commission's standard contractual clauses.

7. Your rights

Depending on where you live, you may have the right to ask for a copy of your personal data, to correct it, to delete it, to restrict how we use it, or to object to that use. Write to us and we will respond within 30 days.

If you are covered by the GDPR and think we have handled your data badly, you can complain to your local supervisory authority.

8. Security

Data is encrypted in transit and at rest. Access to production systems is limited to the people who need it and is logged. API keys are stored only as SHA-256 hashes, which is why a key is shown to you exactly once when it is created.

If we discover a breach affecting your data, we will tell you without undue delay and within 72 hours where the law requires it.

9. Changes

If we change this policy in a way that materially affects you, we will tell you by email and in the product at least 30 days before it takes effect.

Fermi Technologies Inc.

A Delaware corporation.

Questions about this document can go to legal@fermitech.io.