Legal

Discrezo Privacy Policy

Effective: 19 August 2026

Privacy is not an optional feature of Discrezo. It is part of how the service is designed.

This Privacy Policy explains how Discrezo ("Discrezo", "we", "us" or "our") collects, uses, processes, stores and discloses personal information when you use our websites, applications, AI assistant, waitlist, subscriptions and related services (collectively, the "Services").

Our registered address is:

Discrezo 333 West San Carlos Street San Jose, CA 95110 United States

For privacy questions or requests:

support@discrezo.com

Our Terms of Use govern your use of the Services.

01

The most important thing to understand

Discrezo is designed differently from a conventional AI account.

The architecture separates:

who you are

from:

what you ask.

The account side of Discrezo may know information such as:

  • your email address;
  • your account;
  • your subscription;
  • your plan;
  • your billing relationship; and
  • whether you are entitled to use the Service.

The AI inference side needs information such as:

  • your prompt;
  • relevant context;
  • routing information; and
  • the model's response.

Discrezo is designed so that ordinary AI inference does not require both sets of information to be combined.

Our simplified explanation is:

Discrezo knows who, not what.

The AI knows what, not who.

Nobody gets both.

There are important qualifications to this statement, which we explain below.

02

Discrezo still processes your prompt

Privacy does not mean that an AI system can answer a question without processing the question.

When you send a prompt through Discrezo, the inference systems involved in routing and answering that request necessarily process the prompt and any relevant context.

In Standard Mode, the selected AI provider also receives the prompt and relevant context required to generate the answer.

Our privacy architecture is designed to prevent your ordinary Discrezo account identity from travelling with that request.

It is not designed to make the words you type invisible to the AI processing them.

03

Information you put inside a prompt

Identity separation cannot remove identifying information that you deliberately write inside the prompt itself.

For example, if you write:

"My name is Jane Smith and I work at Example Corp."

the AI provider processing the request can read those words.

The same applies to information such as:

  • your name;
  • employer;
  • address;
  • telephone number;
  • financial information;
  • medical information;
  • confidential information; or
  • information relating to another person.

You should consider what information you choose to include in a prompt.

Discrezo's architecture separates your account identity from your AI request.

It does not anonymise information you voluntarily include inside the content of the request.

04

Information we collect

The information we collect depends on how you interact with Discrezo.

It falls into several distinct categories.

A. Account information

When you create or manage a Discrezo account, we may collect:

  • email address;
  • account identifier;
  • authentication information;
  • account settings;
  • subscription plan;
  • account status;
  • account creation date;
  • subscription entitlement; and
  • other information required to operate your account.

We design our systems so this account information does not need to accompany your ordinary AI requests.

B. Waitlist and Founding Member information

If you join the Discrezo waitlist or reserve Founding Member pricing, we may collect:

  • your email address;
  • the date and time you joined;
  • whether you reserved Founding Member pricing;
  • the plan associated with that reservation;
  • whether you applied for early access;
  • whether your email has been verified;
  • survey responses you voluntarily provide;
  • the page or campaign from which you joined;
  • referral information;
  • source information; and
  • campaign parameters such as UTM information.

We use this information to:

  • administer the waitlist;
  • preserve Founding Member eligibility;
  • manage early-access invitations;
  • communicate with you about launch;
  • understand how people discover Discrezo; and
  • measure the effectiveness of our launch and marketing activity.

Joining the waitlist does not require you to provide payment card details.

C. Subscription and billing information

If you purchase a Discrezo subscription, we collect information necessary to administer that subscription.

This may include:

  • your plan;
  • subscription status;
  • billing dates;
  • payment status;
  • transaction history;
  • customer or payment identifiers;
  • applicable tax information; and
  • limited billing information supplied by our payment processor.

Payment card processing may be performed by third-party payment processors.

Discrezo does not need your payment identity in order to route an AI request.

D. Prompt and response content

When you use the Discrezo assistant, your prompt and relevant conversation context must be processed so that:

  • the request can be understood;
  • an eligible model can be selected;
  • the selected AI can generate an answer; and
  • that answer can be returned to you.

This is different from storing your conversation as account-readable server data.

Discrezo is designed so that prompt and response bodies are not placed into ordinary operational logs.

E. Saved conversations and memory

If you choose to save conversation history or use memory features, saved content is designed to be encrypted on a trusted user device before it is synced.

Discrezo may therefore store:

  • encrypted conversation data;
  • encrypted memory data;
  • encrypted indexes or related encrypted user data;
  • information required to synchronise encrypted data; and
  • limited information about storage and synchronisation.

Discrezo's backend is designed not to hold the key required to decrypt your saved conversation content.

This means:

we can store the encrypted data without being able to read the underlying conversation.

We do not claim that nothing is stored.

Encrypted data may be stored to provide history and synchronisation.

F. Operational and usage information

We collect limited operational information needed to run, secure and improve the Service.

Depending on the feature, this may include information such as:

  • service usage;
  • feature usage;
  • routing outcome;
  • model or provider used;
  • latency;
  • token or compute usage;
  • error categories;
  • service availability;
  • timestamps;
  • subscription allowance usage; and
  • aggregated performance information.

Our operational systems are designed so that ordinary telemetry does not become a second database of readable conversations.

G. Website and device information

When you visit our website or access the Services, we may receive information automatically from your browser, device or network.

This may include:

  • IP address;
  • browser type;
  • operating system;
  • device type;
  • approximate geographic area;
  • date and time;
  • pages visited;
  • referring page;
  • session information; and
  • interactions with the website.

Some of this information is required for ordinary internet communications, fraud prevention, security and service delivery.

The fact that our website or account systems may receive your IP address does not mean that we intentionally pass that originating network identity to the AI provider answering your prompt.

H. Cookies and similar technologies

We may use cookies or similar technologies to:

  • keep you signed in;
  • remember preferences;
  • protect accounts;
  • understand website performance;
  • measure conversions;
  • preserve campaign attribution; and
  • improve the website.

Where applicable law requires consent for non-essential cookies, we will request that consent before using them.

More information may be provided in our Cookie Notice and Your Privacy Choices controls.

I. Communications

If you contact us, we may collect:

  • your email address;
  • your name if provided;
  • the contents of your message;
  • attachments you send us; and
  • information necessary to respond.

Please do not send conversation encryption keys, passwords or other credentials to customer support.

J. Surveys and feedback

If you choose to answer a survey or send feedback, we may collect:

  • your responses;
  • ratings;
  • product feedback;
  • feature requests; and
  • related information you voluntarily provide.

Survey participation is voluntary unless we clearly tell you otherwise.

05

What the AI provider receives

In Standard Mode, the AI provider selected to answer a request receives information necessary to perform inference.

This can include:

  • your prompt;
  • relevant conversation context;
  • instructions necessary to generate the response;
  • model parameters; and
  • request information required to operate the service.

Discrezo is designed so that the provider does not need to receive your:

  • Discrezo account ID;
  • Discrezo account email;
  • payment identity; or
  • originating network identity

as part of the ordinary AI request.

The provider can still see identifying information you write in the prompt itself.

06

Standard Mode

Standard Mode allows Discrezo to route requests across eligible supported AI models.

Depending on the task, this may include models provided by companies such as:

  • OpenAI;
  • Anthropic;
  • Google; and
  • supported open-model or other inference providers.

The provider processing the request receives the prompt and context required to answer it.

Standard Mode therefore provides identity separation, not content invisibility.

07

Private Mode

Private Mode changes which routes are permitted.

When Private Mode is enabled, Discrezo restricts routing to supported open-model routes.

Private Mode requests are not intentionally routed to:

  • OpenAI;
  • Anthropic; or
  • Google.

The infrastructure operating the selected open model may still need to process the prompt in order to answer it.

Private Mode therefore does not mean:

"no computer outside your device ever sees the prompt."

It means the routing rules exclude the major proprietary AI providers specified above.

08

How automatic routing affects your privacy

Discrezo automatically evaluates a request to determine an appropriate eligible AI model.

The routing process may consider characteristics such as:

  • the kind of task;
  • difficulty;
  • context requirements;
  • privacy mode;
  • model capability;
  • provider availability; and
  • service health.

The routing system does not need your account email, payment identity or billing information to decide which AI should answer the request.

Automated routing is used to select a model.

It is not intended to make decisions about you that produce legal or similarly significant effects.

09

We do not use your conversation as advertising data

Discrezo does not use readable prompt or response content to build advertising profiles about you.

We do not use the subjects you discuss with the AI to decide which advertisements to show you.

We do not sell your readable conversations to advertisers.

We do not sell access to your saved conversation history.

10

Model training

Discrezo does not operate its privacy model on the assumption that your private conversation should become training data.

We do not use your readable saved conversation history to train foundation AI models.

We do not build advertising or customer profiles from the contents of your encrypted conversation history.

Operational and aggregate information may be used to:

  • improve routing;
  • improve reliability;
  • understand product performance;
  • prevent abuse;
  • manage capacity; and
  • improve the Services.

Where third-party AI providers process prompts, we select provider arrangements and configurations based in part on privacy and security requirements.

Provider practices may vary, and our Routing and Privacy materials may provide further information about the routes currently supported.

11

How we use personal information

We use personal information where necessary to:

Provide the Services

Including to:

  • create accounts;
  • authenticate users;
  • administer plans;
  • provide AI access;
  • route requests;
  • return responses;
  • synchronise encrypted history; and
  • provide customer support.

Process subscriptions

Including to:

  • take payment;
  • manage subscription status;
  • provide plan entitlements;
  • administer Founding Member pricing; and
  • manage cancellations.

Operate the waitlist

Including to:

  • reserve Founding Member pricing;
  • manage the first 5,000 early-access programme;
  • verify email addresses;
  • contact users about launch; and
  • administer invitations.

Protect the Services

Including to:

  • detect fraud;
  • prevent account abuse;
  • prevent automated resale;
  • protect provider credentials;
  • investigate suspicious activity;
  • enforce usage limits; and
  • maintain security.

Improve Discrezo

Including to:

  • understand service performance;
  • evaluate routing quality;
  • diagnose errors;
  • improve reliability;
  • improve product design; and
  • develop new functionality.

Communicate with you

Including to send:

  • account notifications;
  • security messages;
  • service announcements;
  • billing communications;
  • launch notifications;
  • early-access notices; and
  • marketing communications where permitted.

Comply with law

Including where necessary to:

  • satisfy legal obligations;
  • maintain financial records;
  • respond to valid legal process;
  • resolve disputes; and
  • protect legal rights.
12

Marketing communications

If you join the waitlist, we may email you about:

  • your Founding Member reservation;
  • email verification;
  • early-access status;
  • launch;
  • your invitation to activate Discrezo; and
  • closely related information about the Service.

Where we send optional marketing communications, you can unsubscribe using the link provided in the message.

Unsubscribing from marketing does not necessarily prevent us from sending essential transactional or account messages.

13

When we disclose information

We may disclose personal information in the circumstances described below.

AI and inference providers

We disclose the prompt and context necessary for an eligible provider to answer your request.

We design the inference request so that ordinary Discrezo account identity does not need to accompany it.

Service providers

We may use companies that help us provide functions such as:

  • infrastructure;
  • authentication;
  • payment processing;
  • email;
  • customer support;
  • security;
  • fraud prevention;
  • analytics;
  • error monitoring; and
  • other operational services.

These providers receive information appropriate to the service they perform.

A provider operating our account systems does not thereby need access to readable conversation content.

Legal requirements

We may disclose information when we reasonably believe disclosure is required to:

  • comply with applicable law;
  • respond to valid legal process;
  • protect our legal rights;
  • investigate fraud or abuse;
  • protect the security of the Services; or
  • protect people from serious harm.

Our ability to disclose information depends on what information we actually possess.

If saved conversation content is encrypted and Discrezo does not possess the key required to decrypt it, we cannot simply turn that encrypted content into readable conversation history.

Corporate transactions

If Discrezo is involved in:

  • a merger;
  • acquisition;
  • financing;
  • reorganisation;
  • sale of assets;
  • insolvency proceeding; or
  • similar corporate transaction,

personal information may be disclosed as part of the transaction where legally permitted.

Any successor would remain subject to applicable privacy obligations relating to information it receives.

With your direction

We may disclose information where you direct us to do so or where you use a feature that intentionally shares information with another party.

14

What we do not give an AI provider merely to answer a prompt

Our ordinary inference architecture is designed so the provider answering your request does not need:

Your Discrezo email

Your account identity

Your billing identity

Your payment details

Your originating network identity

to generate an answer.

The provider instead receives what it needs to perform inference.

This is the central privacy boundary behind Discrezo.

15

Data minimisation

Our objective is not simply to promise that people will avoid looking at unnecessary information.

Our objective is to prevent unnecessary information from being available to the component in the first place.

For example:

billing needs to know whether an account is paid;

it does not need to know what that account asked an AI;

and:

the inference system needs to know the question;

it does not need the customer's payment identity.

We design around that separation.

16

Operational logging

A reliable service requires operational telemetry.

Discrezo may record information such as:

  • route;
  • model or provider;
  • latency;
  • token usage;
  • timing;
  • availability; and
  • error category.

Our systems are designed to exclude readable prompt and response bodies from ordinary operational logs.

They are also designed to avoid placing account identity into ordinary inference logging.

This allows us to operate and diagnose the Service without intentionally creating a second readable copy of your conversation in our logs.

17

Encrypted conversation history

Saved conversation history is treated differently from account information.

Where supported:

  • your device has access to readable conversation content;
  • saved content is encrypted before sync;
  • encrypted data is uploaded;
  • Discrezo stores the encrypted form; and
  • Discrezo's backend does not hold the key required to read it.

The backend may still be able to observe limited metadata associated with storage or synchronisation, such as:

  • that encrypted data exists;
  • approximate storage volume;
  • or that synchronisation occurred.

Encryption does not make every form of metadata disappear.

18

Your device matters

A trusted device is one place where your conversation must legitimately exist in readable form for you to use it.

If your device, browser, operating system or account is compromised, information available on that device may also be compromised.

Discrezo's server-side privacy architecture cannot protect information from malware or an attacker who already controls a trusted device.

You should protect your devices and credentials appropriately.

19

Security

Discrezo uses technical and organisational controls intended to protect personal information and preserve the separation described in this Policy.

Discrezo holds ISO/IEC 27001 certification.

Our security programme includes controls relating to areas such as:

  • access;
  • security risk management;
  • credentials;
  • software changes;
  • incident response;
  • monitoring; and
  • security testing.

No certification, encryption system or software architecture makes a service impossible to compromise.

For more information, see our Security page.

20

Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it is processed, subject to legal, security and operational requirements.

Retention depends on the type of information.

For example:

Account information

May be retained while your account remains active and for a reasonable period afterwards where required for security, disputes, compliance or legal obligations.

Subscription and transaction records

May be retained for periods required by accounting, tax, payment, fraud-prevention and legal requirements.

Waitlist information

May be retained while we administer the waitlist, Founding Member reservation and launch programme, unless you ask us to delete it where applicable.

Support communications

May be retained for as long as reasonably necessary to address the request, maintain support records, resolve disputes and improve support.

Operational information

Is retained according to operational, security and reliability needs and is designed not to include readable conversation bodies in ordinary logs.

Encrypted conversation history

May remain stored while you choose to retain or synchronise it.

Where supported, deleting conversations or your account will cause associated encrypted data to be scheduled for deletion, subject to reasonable backup cycles, legal requirements and technical limitations.

21

Deletion does not always mean every record disappears immediately

Certain information may need to be retained after a deletion request where permitted or required by law.

Examples can include information required for:

  • tax;
  • accounting;
  • fraud prevention;
  • legal claims;
  • security;
  • regulatory obligations; or
  • demonstrating that a deletion request was honoured.

Where information has been irreversibly aggregated or de-identified so that it no longer identifies you, it may no longer constitute personal information.

22

Aggregate and de-identified information

We may create aggregate or de-identified information that does not reasonably identify an individual.

We may use this information to:

  • analyse usage;
  • understand demand;
  • evaluate product performance;
  • improve routing;
  • improve reliability; and
  • plan capacity.

Where information is maintained as de-identified information, we do not intend to attempt to re-identify it except where required for security validation or permitted by law.

23

International processing

Discrezo is based in the United States.

Our service providers and AI providers may operate in the United States and other countries.

As a result, personal information may be processed outside the country where you live.

Where applicable data-protection law requires safeguards for international transfers, we use or require an appropriate lawful transfer mechanism.

These mechanisms may include:

  • an adequacy decision;
  • approved standard contractual clauses;
  • an applicable UK international-transfer mechanism; or
  • another mechanism permitted by applicable law.

You may contact support@discrezo.com for additional information about applicable transfer safeguards.

24

Your privacy rights

Depending on where you live, you may have rights relating to your personal information.

These may include the right to:

  • request access to personal information;
  • request a copy of personal information;
  • correct inaccurate personal information;
  • request deletion;
  • restrict certain processing;
  • object to certain processing;
  • request data portability;
  • withdraw consent where processing relies on consent;
  • opt out of certain marketing; and
  • complain to a competent data-protection authority.

Not every right applies in every jurisdiction or circumstance.

To make a request, email:

support@discrezo.com

Subject:

Privacy Request

We may need to verify your identity before completing certain requests.

We will not discriminate against you for exercising a legally protected privacy right.

25

California privacy rights

If you are a California resident and applicable California privacy law applies, you may have rights including the right to:

  • know what categories of Personal Information we collect;
  • know the purposes for which we use it;
  • know categories of recipients to whom it is disclosed;
  • access specific Personal Information;
  • request deletion;
  • request correction;
  • opt out of certain sale or sharing of Personal Information;
  • limit certain uses or disclosures of Sensitive Personal Information where the law provides that right; and
  • exercise your rights without unlawful discrimination.

For the purposes of this section, "Personal Information" and "Sensitive Personal Information" have the meanings given to them under applicable California law.

Categories of Personal Information

Depending on how you use Discrezo, categories we may collect can include:

Identifiers

Such as:

  • email;
  • account identifiers;
  • IP address; and
  • related online identifiers.

Commercial information

Such as:

  • plan;
  • subscription;
  • transaction; and
  • Founding Member status.

Internet or network activity

Such as:

  • website interactions;
  • device information;
  • security events; and
  • operational usage.

Geolocation

Generally approximate location inferred from network information.

We do not need precise GPS location to provide the core Discrezo service unless a specific future feature clearly asks you to provide it.

Communications

Such as support messages or correspondence with us.

User-provided content

Prompts may contain Personal Information or Sensitive Personal Information depending on what you choose to type.

The treatment of prompt content is described separately throughout this Policy because our architecture deliberately handles it differently from ordinary account data.

26

Sale and targeted advertising

Discrezo does not sell your readable AI conversations.

We do not sell access to your saved conversation history.

We do not use the contents of your AI conversations to build advertising profiles about you.

Our website may use analytics or marketing technologies to understand campaign and website performance.

Where use of such technology constitutes a "sale", "sharing", targeted advertising or similar regulated activity under applicable law, we will provide the legally required notice and opt-out controls.

Where applicable, we will recognise legally valid opt-out preference signals.

27

Sensitive information

A user can choose to type highly sensitive information into an AI prompt.

That does not mean Discrezo wants or needs such information for your account.

We do not use sensitive information contained in prompts to:

  • target advertising;
  • infer characteristics about you for marketing; or
  • enrich your Discrezo account profile.

The information is processed as part of the request you chose to submit.

You should still consider carefully whether sensitive information needs to be included in a prompt.

28

European Economic Area, United Kingdom and Switzerland

If European or UK data-protection law applies to our processing, our lawful basis depends on why information is being processed.

We may rely on:

Performance of a contract

Where processing is necessary to provide a Service you requested.

Examples include:

  • maintaining your account;
  • authenticating you;
  • routing an AI request;
  • returning a response;
  • providing encrypted synchronisation;
  • administering your subscription; and
  • providing customer support connected with your Service.

Steps taken at your request before entering into a contract

For example, administering certain pre-launch or Founding Member registration activities.

Legitimate interests

Where necessary for legitimate interests that are not overridden by your rights.

These can include:

  • protecting the Service;
  • preventing abuse;
  • ensuring reliability;
  • improving product performance;
  • understanding aggregate product use;
  • protecting our legal rights; and
  • communicating about operational matters.

Consent

Where we ask you for consent, for example for:

  • certain marketing communications;
  • non-essential cookies; or
  • another specific optional purpose.

You may withdraw consent where applicable.

Legal obligations

Where processing is necessary to comply with legal requirements, including certain:

  • accounting;
  • tax;
  • regulatory;
  • legal-process; and
  • record-keeping requirements.
29

EEA, UK and Swiss rights

Where applicable, you may have rights including:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • portability; and
  • withdrawal of consent.

You may also have the right to complain to the data-protection authority responsible for your location.

For UK residents, this may include the Information Commissioner's Office.

For EEA residents, you may contact the competent supervisory authority in your country.

You can first contact us at:

support@discrezo.com

We would like the opportunity to address your concern.

30

Automated decision-making

Discrezo uses automated technology to route AI requests.

For example, the routing system may automatically determine which eligible AI model should answer your question.

This routing decision determines how the Service processes your request.

It is not intended to make an automated decision about you that produces legal or similarly significant effects.

If we introduce functionality that materially changes this position, we will update our disclosures where required.

31

Children

Discrezo is not currently intended for children.

Unless a particular Service expressly states otherwise, you must be at least 18 years old or the age of legal majority where you live to create a Discrezo account.

We do not knowingly design the Services to collect personal information from children through ordinary consumer accounts.

If you believe a child has provided personal information to Discrezo contrary to this Policy, contact:

support@discrezo.com

32

Business customers

Discrezo may offer Business plans.

Where Discrezo processes personal information on behalf of a Business customer, additional Business Terms or a Data Processing Agreement may apply.

In those circumstances, the Business customer may determine certain purposes and means of processing and may be responsible for responding to requests relating to information it controls.

Where appropriate, we may direct a request to the relevant Business customer.

33

Your employer

Using a work email address does not automatically give an employer access to your private Discrezo conversations.

If you later join a Business account, the features and administrative controls available to that organisation will be disclosed as part of the Business product.

We will not silently convert an individual privacy model into an employer-readable conversation archive.

Any Business feature that materially changes who can access information must be disclosed appropriately.

34

Legal requests and encrypted data

Discrezo is subject to law.

We may be required to provide information we hold in response to valid legal process.

But there is an important distinction between:

information we possess

and:

information we have the technical ability to read.

For example, we may hold encrypted conversation data used for synchronisation.

If Discrezo does not hold the decryption key, possession of that encrypted data does not give us the ability to provide readable conversation content.

We do not claim that legal process can never result in disclosure.

We claim only what the architecture actually permits us to access.

35

Provider limitations

Discrezo controls the information it intentionally sends to an AI provider through the Discrezo architecture.

We cannot make information you type into the prompt itself invisible to the provider that must answer it.

AI providers and infrastructure also have their own technical systems, security risks and legal obligations.

Discrezo selects eligible routes based partly on privacy and security requirements, but no third-party service can be described as risk-free.

Private Mode exists for users who want to exclude specified major proprietary providers entirely from eligible routing.

36

Changes to providers

AI providers and models change frequently.

We may:

  • add providers;
  • remove providers;
  • replace models;
  • change routes;
  • restrict providers;
  • temporarily disable providers; or
  • update Private Mode eligibility.

When we make these decisions, providers must remain eligible for the privacy mode being used.

A provider becoming faster or more capable does not automatically override a privacy restriction.

37

Changes to this Privacy Policy

We may update this Privacy Policy as:

  • Discrezo changes;
  • new features are introduced;
  • privacy law changes;
  • providers change; or
  • our processing practices change.

When we update the Policy, we will update the effective date.

If a change materially affects how we use personal information or your rights, we will provide additional notice where required by law.

38

Contact us

For privacy questions, requests or complaints:

support@discrezo.com

Use the subject:

Privacy Request

Registered address:

Discrezo 333 West San Carlos Street San Jose, CA 95110 United States

The short version

If you remember only five things about Discrezo privacy:

1. Your account and your AI request are deliberately separated.

Discrezo knows who, not what. The AI knows what, not who.

2. An AI still needs to see the question to answer it.

Standard Mode is identity separation, not prompt invisibility.

3. Saved history is encrypted before sync.

Discrezo can store the encrypted data without holding the key required to read it.

4. Private Mode changes who is allowed to process the request.

Private Mode excludes OpenAI, Anthropic and Google from eligible routes.

5. We do not pretend privacy means no data exists.

Account data exists. Operational data exists. Encrypted history can exist. The architecture is designed to stop one party from unnecessarily holding the whole picture.

Discrezo is not affiliated with OpenAI, Anthropic or Google.

We only claim what the architecture technically enforces.