LLM.co, a DEV.co company (“LLM.co,” “we,” or “us”) helps organizations deploy private and on-premises large language models. This notice describes the personal information we handle through llm.co, our communications, and our services (the “Services”), and the choices you have.
Because our customers operate in environments where data residency and confidentiality are non-negotiable, restraint with data is built into how we work. Using the Services signifies that you have read and understood this notice.
Who we are & what this covers
This notice addresses information for which we determine the purpose and means of processing — chiefly information about website visitors, prospects, and the people we work with at customer organizations.
Where we deploy or operate a private model on behalf of a customer, we generally handle the data flowing through that system on the customer’s behalf and under its instructions, governed by a separate data processing agreement. In those cases the customer is the data controller; the section “Data inside private deployments” describes our commitments.
The information we handle
Details you give us
When you complete a form, email us, book a call, or correspond with our team, we receive your name, work email, organization, role, and whatever you include in your message.
Details gathered automatically
Our servers and analytics record technical signals such as IP address, approximate location, device and browser characteristics, referring URLs, and the pages you view.
Details from partners
We may supplement records with business-contact information from reputable data and analytics providers, and we receive information through integrations you elect to connect.
Why we process information
To run, maintain, secure, and improve our website and Services.
To answer questions, prepare proposals, and carry out engagements.
To keep you informed about your project and, with your permission, share relevant material.
To measure how our content and site perform.
To safeguard against fraud, abuse, and security threats.
To meet legal, regulatory, and contractual obligations.
We neither sell personal information nor use a customer’s confidential data to train foundation models or any model offered to other customers.
Lawful grounds (EEA & UK)
For individuals in the European Economic Area or United Kingdom, our processing rests on one or more of: the performance of a contract; our legitimate interests in running and developing the business, weighed against your interests; your consent, which you can withdraw at any time; and compliance with legal duties.
Cookies, analytics & your choices
Essential cookies keep the site working; analytics and similar technologies help us understand usage. You can manage non-essential cookies through your browser or our consent tools, and we respect recognized opt-out preference signals where the law requires.
When we disclose information
We share information with vendors that host and support our operations under confidentiality and data-protection terms; with advisers and authorities where the law requires or to protect rights and safety; in connection with a corporate transaction such as a financing or sale; and at your direction.
Data inside private deployments
Our core promise is that a private LLM keeps your data under your control. When we stand up a model in your environment, we engineer for that outcome:
Models and retrieval run inside your perimeter — on-premises, in your own cloud tenancy, at the edge, or fully air-gapped — so prompts, documents, and outputs need not leave your environment.
We do not train shared or third-party models on your data; any fine-tuning happens on models you control, for you alone.
Retrieval-augmented generation operates over your corpus with access controls you define; we do not repurpose that corpus.
Access by our personnel is least-privilege, time-bound, and logged, and is removed at the end of an engagement per the governing agreement.
The data-handling terms of an engagement live in its data processing agreement and statement of work, which prevail over this notice for that engagement.
Sub-processors & model providers
Where we use sub-processors or third-party model providers, they are disclosed and bound by contract. For hosted models, we favor configurations under which prompts and completions are not retained or used for provider training, and we document the choice for each deployment.
How long we keep information
We keep personal information only as long as needed for the purposes above and to satisfy legal, accounting, and dispute-resolution requirements. Data within a customer deployment is retained and deleted according to that customer’s agreement and instructions.
How we protect information
We apply layered safeguards — encryption in transit, access management, network segmentation, monitoring, and vendor review — appropriate to the sensitivity of the data. No system is perfectly secure, and we cannot promise absolute security.
Cross-border transfers
We operate from the United States and may process information there and elsewhere. For transfers originating in the EEA, UK, or Switzerland, we rely on recognized mechanisms such as the Standard Contractual Clauses and the UK Addendum, with additional measures as appropriate.
Your choices & rights
EEA & UK
You may request access, correction, deletion, restriction, objection, or portability, and may withdraw consent or complain to a supervisory authority.
California
California residents may exercise rights to know, access, correct, delete, and to opt out of any “sale” or “sharing” and limit use of sensitive information. We do not sell personal information for money, and we will not retaliate for exercising these rights. Categories we may have collected in the last 12 months include identifiers, internet activity, commercial and professional information, and inferences.
Other states
Residents of Virginia, Colorado, Connecticut, Texas, Utah, and similar jurisdictions may hold comparable rights.
Making a request
Email [email protected] and we will verify and respond within the period the law allows. Authorized agents may submit requests where permitted.
Children
Our Services are built for organizations and are not directed to anyone under 16. We do not knowingly gather children’s information; tell us if you believe we have and we will remove it.
Links to other sites
Our site may reference third-party services we do not operate. Their own privacy notices, not this one, govern your use of them.
Updates to this notice
We may revise this notice as our practices or the law evolve. We will change the “Last updated” date and give further notice of material changes where required. Continued use after an update indicates acceptance.
Reaching us
For privacy questions or requests, write to [email protected]. We will respond in good faith.
Private AI On Your Terms
Tell us your use case and constraints — on-prem, cloud, or edge — and we'll map a compliant deployment within one business day.
Talk to an AI Expert