ExeFast Privacy Policy
Last Updated: August 19, 2026 (adds Sponsorship)
EXEFAST INC, a Florida benefit corporation ("ExeFast," "we," "us," or "our") explains here how we collect, use, disclose, retain, and protect personal information when you use the ExeFast platform, websites, applications, APIs, AI agents, and related services (the "ExeFast Platform"), and your rights and choices.
This Policy does not apply to information processed independently by third parties (e.g., Stripe, Thunes, OpenRouter, Google, the cloud inference providers and model developers they route to, our web search provider, WhatsApp, or Telegram), each of which maintains its own privacy policy. For privacy inquiries or to exercise your rights, contact privacy@exefast.ai. Where the ExeFast Platform is offered to users in the EEA or UK, we have appointed representatives under Article 27 of the EU GDPR and the UK GDPR; their contact details are in Section 10 (Contact). Our primary data processing occurs in the United States.
1. Information We Collect
You provide:
- Account information: name, email, username, authentication credentials, and profile details, collected through our identity provider.
- Identity and tax verification (payout only): if and when you seek to receive a Referral Program payout, we will collect the information needed to pay you and to meet our tax-reporting obligations - legal name, address, date of birth, taxpayer identification (SSN, ITIN or EIN for U.S. persons; foreign taxpayer identification number and the certifications on Form W-8BEN or W-8BEN-E for others), payout or bank details, and, where you are paid as a business, business and beneficial-ownership information. We may use a tax-compliance provider to collect and validate this information. Any such provider is added to our sub-processor page before we share any information with it. This collection is invoked only when a payout is requested. It is not required to create an account, or to use, customize, or deploy an agent.
- Payment information: card and billing details are collected and processed by our payment providers; we do not store full card numbers.
- User Content and configurations: prompts, Gig and custom AI agents configurations, workflows, and uploaded files you create when using the ExeFast Platform. Content within a custom AI agent you deploy outside the ExeFast Platform is handled by you and your chosen platform, not by ExeFast.
- Communications: information you provide in support requests, feedback, or interactions over integrated messaging or voice channels.
- Referral information: referral links/codes used and information necessary to attribute referrals and pay rewards.
- Sponsorship information: if you sponsor a plan, the payment details you provide through our payment providers, the email address you supply for a named Slot, any country you select to restrict a pool Slot to, and any display name you opt to show. If you claim a sponsored plan, your account information as with any user, and โ for a pool Slot โ the choice you make at the point of claiming about whether your email or a display name is shown to the Sponsor.
Collected automatically: IP address, device and browser type, identifiers, access times, features used, API and inference usage metadata (volume, duration, success/failure), error and performance data, and essential cookies for authentication and security (analytics/performance cookies subject to consent where required). Approximate location is derived from IP for fraud prevention and compliance with our launch list; we do not collect precise geolocation unless you enable it for a feature.
We use cookies and similar technologies as described in our Cookie Policy. Where required (for example, in the EEA and UK), we set non-essential cookies only with your consent, collected through a consent banner, and you can change your choices at any time via the banner or your browser settings. We honor recognized opt-out signals, including Global Privacy Control (GPC), where applicable law requires.
From third parties: transaction and payout status from payment providers; where you request a payout, tax-form validation results from any tax-compliance provider we use; transient inference context routed through our routing partners to the model endpoints described in Section 3; message content and metadata from messaging providers where you use those channels; and aggregated or pseudonymized analytics from infrastructure providers.
We generally do not collect sensitive personal information except identity/verification data in the payout context, which is used only for verification, fraud prevention, tax, and regulatory purposes and is not sold or used for advertising.
Personal data you process through the Services (our role as processor)
When you use Gig, custom AI agents, or the ExeFast API to process personal data about third parties (for example, your own customers, contacts, or end-users handled by an agent or over a messaging channel), you act as the controller of that data and ExeFast acts as your processor, processing it on your documented instructions to provide the Services. You are responsible for providing any required notices to, and obtaining any required consents from, those individuals, and for having a lawful basis and the authority to process their data through the Services. Where the GDPR, UK GDPR, or similar laws apply, our Data Processing Addendum (DPA) governs this processing, is available at legal@exefast.ai, and prevails over this Policy for such processor processing.
2. How We Use Information
We use personal information to: create, secure, and manage your account; provide and improve AI agents, Gig, the ExeFast API, runtime environments, and related features; process subscriptions and Referral Program rewards (via payment providers); operate the Sponsorship feature, including processing Sponsorship Pack purchases, determining eligibility to claim a country-restricted pool Slot, matching claims to Slots, and showing a Sponsor the status of what they purchased; deliver inference results (transient routing to the model endpoints described below); retrieve current information from the web where answering you requires it (described below and in Section 3); perform identity/payout verification, fraud prevention, sanctions screening, tax reporting, and other legal obligations; enforce our Terms and Acceptable Use Policy and investigate abuse; monitor and improve security, reliability, and performance; analyze usage in aggregated or pseudonymized form to improve the ExeFast Platform (we do not use your content, inputs, or outputs to train, fine-tune, or improve any AI or machine-learning model); and send transactional communications (which you cannot opt out of) and, with opt-out, promotional messages.
Where required (e.g., GDPR), our legal bases are performance of a contract, legitimate interests (security, fraud prevention, improvement), legal obligation, and consent (which you may withdraw).
Inference. When you run Gig, a custom AI agent, or otherwise use inference, your prompt and the conversation context are sent to a model endpoint to generate a response. We reach those endpoints through OpenRouter and directly through Google. OpenRouter in turn routes to cloud inference providers and model developers, and the endpoint that serves a particular request is selected automatically for availability and capacity. A request may therefore be served by a different endpoint than an earlier one, without any change to the terms below.
Your conversations are not used to train any model. Not by us, and not by the providers we route to. This is an absolute commitment and it is not subject to a plan tier, an opt-in, or a setting you have to find. The one thing we reserve is described at the end of this paragraph, and it is not training.
Providers do keep some material for safety and abuse monitoring, and the periods vary. When we select the models we make available, we prefer endpoints configured so that your prompts and outputs are not retained after your response is returned, and we disable data collection where a provider offers us that control. But a provider's own terms may still require it to hold a copy for safety and abuse monitoring, and how long varies by provider and by the plan we are on. For ordinary traffic those periods are usually short โ a matter of weeks. For a request a provider's own systems flag as potentially abusive, the outer bound across our current providers is up to two years, and one provider retains safety classification records for longer than that. This is not zero retention and we do not describe it as such. We name our current providers, and what each retains, on our sub-processor page at https://exefast.ai/subprocessors, and we update that page when a provider or a period changes. In every case the material is used for the provider's own safety and abuse work and is not used to train any model.
What we reserve. Where our own systems or a provider's flag content as potentially violating our Acceptable Use Policy or the law, we may review that content and act on it โ including by removing it, restricting a feature, or suspending an account. That review is done for safety and abuse purposes only, and nothing reviewed this way is used to train any model.
What this reservation does not do. It does not let us keep your conversation after you have deleted it. If you delete a conversation, it is gone, whether or not it was flagged โ see Section 5.1, which means what it says. What survives is our own record of the enforcement decision: that an account was flagged on a date, on what ground, and what we did about it. That record is ours rather than yours, it is described in Section 5.4, and it does not preserve a copy of your conversation. The only circumstance in which we hold your content past your deletion is a legal preservation obligation, which is described in Section 5.6 and is not something we choose.
Web search. Some questions can only be answered with current information from the web. Where that is so, we send a search query to a third-party search provider and use the results it returns to compose your answer. Search is a different arrangement from inference and we describe it separately: what we send, what the provider keeps and for how long, and who the provider is, are all set out in Section 3 and on our sub-processor page.
3. How We Share Information
We do not sell personal information or share it for cross-context behavioral advertising. We share only with: payment providers (Stripe, Thunes) for transactions and payouts, and any tax-compliance provider we use in connection with a Referral Program payout; cloud and inference providers (Google Cloud for hosting; and the routing and inference providers described below); analytics, monitoring, and support tools under data-processing agreements; and professional advisers under confidentiality. We also disclose to comply with law or lawful requests, to protect rights, property, or safety, and in a merger or asset sale (with notice and successor obligation to honor this Policy). Messaging and voice providers process the content and metadata necessary to deliver those channels under their own policies. We may use and share aggregated or de-identified data that does not identify you. Inference and cloud providers. We share your prompts and context with the providers that operate the model endpoints, transiently and for the sole purpose of returning a response to you. The providers we engage directly for inference are OpenRouter and Google. OpenRouter in turn routes to cloud inference providers - among them Amazon Web Services and Microsoft Azure - and to the model developers whose models are served from those endpoints. Because endpoints are selected automatically, the provider serving a particular request varies, and we do not contract directly with every provider in the chain. We require our routing partners to impose data-protection terms on the providers they engage that are no less protective than our own, including the retention and training restrictions in Section 2.
Search and retrieval. When you ask Gig or a custom AI agent something that requires current information from the web, we send a search query to our web search provider and use the results it returns to answer you. We send the query text and nothing else - not your name, your email, your account identifier, your subscription details, or your conversation history - and we do not record your search queries against your account. Our current search provider is named on our sub-processor page, together with what it retains and for how long. That provider keeps a log of the queries our systems send it, for a limited period and for its own billing, troubleshooting, and abuse-prevention purposes, and it does not receive any identifier that would link a query to you. Because you compose the query yourself, please do not put information into a search request that you would not want sent to a search provider. You can ask us to disable web search for your account or for a particular agent by emailing privacy@exefast.ai.
Sponsorship. If someone sponsors a paid plan for you, or you sponsor one for someone else, we share limited information between the Sponsor and the person who claims it (the "Beneficiary") so the sponsorship can work and so the Sponsor can see what their purchase accomplished. This is a commercial purchase from ExeFast, not a donation โ see Terms of Service Section 5A.
If you are a Sponsor who names a Beneficiary at purchase, we tell you, as the Slot is used, whether and when it was claimed โ using the email address you yourself supplied. We are not disclosing anything to you that you did not already give us.
If you are a Sponsor who releases a Slot to the pool (general, or restricted to a country you selected), you will always be told whether and when it was claimed โ that is fulfillment of what you paid for, and we do not withhold it. If you restricted the Slot to a country, we use that same claim-eligibility check to confirm a claimant qualifies; this does not give you the claimant's precise or approximate location โ you learn only what this Section says a Sponsor learns. Whether you also learn who claimed a pool Slot depends on a choice the Beneficiary makes at the moment of claiming. Before a pool claim completes, we tell the person claiming, plainly, that the Sponsor will see that the Slot was claimed and when, and we ask them to choose whether their email or a display name is also shown to the Sponsor. If they choose not to share it, the Sponsor sees that the Slot was claimed and when, and nothing that identifies who claimed it.
If you are a Beneficiary, you can change your mind later by contacting privacy@exefast.ai to stop sharing your identity with a Sponsor going forward. This does not undo a disclosure already made, but it stops any further disclosure tied to that Slot's status.
Where GDPR or similar law applies: telling a Sponsor that a named Slot was claimed, and when, rests on our legitimate interest and our contract with the Sponsor to confirm delivery of what they purchased, weighed against the low impact on a Beneficiary whose email the Sponsor already held. Confirming eligibility for a country-restricted pool Slot rests on the same basis โ it is necessary to perform the Sponsor's purchase as configured. Showing a Sponsor who claimed a pool Slot rests on the Beneficiary's consent, collected at the point of claiming and revocable afterward as above; where a Beneficiary does not consent, only claim status and timestamp are shared. We apply this same notice-and-choice model everywhere we operate, not only where consent is legally required, because Beneficiaries may be located anywhere (Section 7).
A Sponsor who receives your information under this Section receives it as an independent controller of it for their own limited purposes โ recognizing that their sponsorship was used, and, for a named Slot, reaching the person they intended to sponsor โ not as our processor, and not to use for any other purpose. Our Terms and Acceptable Use Policy require a Sponsor not to market to a Beneficiary using this information, not to re-disclose it, and not to contact a Beneficiary outside the ExeFast Platform.
A Sponsor's own name, if they opt in to display it, appears only on the claim page and the Public Slots Page, where the Sponsor controls it. A Beneficiary's identity is never displayed publicly, on either page or anywhere else we control, regardless of whether it was shared with the Sponsor.
Sub-processors and how the list changes. We maintain the current list of the sub-processors we engage to process personal data - including payment providers, cloud infrastructure, routing partners, and messaging and voice providers - on our sub-processor page at https://exefast.ai/subprocessors, which also links to our routing partners' own current lists of the providers they engage. We may add or replace a provider, and when we do we update that page and give notice as described in our Data Processing Addendum. A copy is also available on request at privacy@exefast.ai.
4. Data Residency and Security
Primary storage is in the United States (Google Cloud, us-central1 or equivalent U.S. regions). We do not intentionally store personal information outside the U.S. except for transient routing to the inference endpoints described in Sections 2 and 3, or as needed to provide the service through third-party providers. We apply reasonable technical, administrative, and physical safeguards (encryption in transit and at rest where feasible, access controls, logging, monitoring, vendor due diligence). No system is fully secure; you are responsible for safeguarding your credentials and API key and for reporting suspected incidents. We notify affected users and regulators of confirmed incidents as required by law.
5. Retention
We keep personal information only as long as we need it for the purpose we collected it for, or as long as the law requires us to keep it. We group what we hold into four classes, because they are kept for different reasons and for different periods.
5.1 Class 1 - Conversation content
This is what you and an AI agent say to each other: your prompts and messages, the agent's responses, and the files you attach to a conversation, on the ExeFast Platform or on an integrated messaging or voice channel.
We keep your conversations until you delete them. Your conversation history is part of what you are paying for: it is what lets an agent pick up a thread days or weeks later instead of starting over. It stays available to you for as long as you want it, and the conversation is available to the model when it generates a response. We do not delete it on a timer, and we do not ask you to re-create work you have already done.
Deleting is yours to do, and it takes effect at once. You can delete a conversation, or all of your conversations, at any time from your settings. Deletion of conversation content is immediate and irreversible: the conversation is removed from our live systems straight away and is not returned to the service, and we cannot get it back for you or for anyone else. There is no restore window, so delete it only if you mean it. Deletion acts on the conversation itself; it does not reach short-lived diagnostic records that a system failure may have touched, which are described in Section 5.4 and expire on their own schedule.
Temporary conversations are not saved. You can start a conversation that is not written to your history at all. It is available while you are having it and is not kept afterwards.
We start keeping conversation content on a channel only after we have given you notice on that channel. That notice may be a message sent on the channel itself, or an activation, sign-up, or consent step that presents this Policy and the Terms and records your acceptance before any conversation begins โ whichever the channel supports. Messages exchanged before that notice is delivered are used only to deliver it and are not written to your conversation history.
When your account closes, your conversation content is held for 30 days so that you can reopen your account and retrieve it, and is then deleted. See Section 5.6.
STOP. On an integrated messaging channel, sending STOP stops us sending you further messages on that channel. It does not delete your conversation content and it does not close your account. To delete conversation content, use the delete controls in your settings, which are described above and which delete content across every channel. To close your account, see Section 5.6.
5.2 Class 2 - Work you create
This is what you author: custom agents and Gig configurations, skills, saved prompts, workflows, and files you upload to build with.
We keep this for the life of your account. We do not currently delete it on any timer โ not by age and not by inactivity. We delete it when you ask us to, and not otherwise, except where the law requires removal, where the Terms of Service or Acceptable Use Policy require it, or where we introduce a retention period in future and give you advance notice of it as described in Section 5.5.
Deleting is yours to do, and you have 30 days to change your mind. When you delete an item in this class we hold it for 30 days before the deletion becomes final, so that you can restore it. During that period the item is out of the service and we do not use it for anything โ we are holding it only so that you can get it back. After 30 days it is removed from our live systems and is not returned to the service.
This is deliberately different from how conversations are deleted, and the difference is not an oversight. Deleting a conversation is immediate and irreversible because a conversation is a record of something that happened. The work in this class is something you built, sometimes over hours, and a mistaken deletion is a real loss. We would rather give you a way back.
You can export before you delete. You can export this class at any time, including before deleting an item and before closing your account.
A statutory erasure request is not held for 30 days. Where you ask us to erase your data under Section 6 rather than using the delete control, we act on that request directly.
5.3 Class 3 - Account, identity, and billing records
This is your account and profile record, transaction, billing and referral-reward records, tax records, the identity- and payout-verification records described in Section 1, and Sponsorship Pack purchase, billing, and claim records (who purchased a Pack, any country selected for a pool Slot, Slot claim status and timestamps, and any identity a Beneficiary chose to share). A Beneficiary's withdrawal of identity-sharing consent (Section 3) governs future disclosure to the Sponsor; it does not delete the underlying record described here, which we keep on the same basis as any other billing record.
We keep these because the law requires us to, for as long as it requires us to. The periods are not ours to choose: they are set by the tax, accounting, anti-money-laundering, sanctions-screening, consumer-protection, and limitation rules that apply to us. In practice this commonly means three to seven years for financial and transaction records, and five years for identity-verification records, measured from the record or from the closure of your account.
One reservation, for records that are actually in issue. Where a specific record is the subject of a dispute, a chargeback, a claim, an investigation, or an actual or reasonably anticipated legal proceeding โ or where we need it to prevent or investigate fraud, or to protect the security of the service or our users โ we keep that record until the matter is resolved and any resulting appeal or limitation period has run, even where that is longer than the periods above. We keep only what the matter requires, we do not use it for any other purpose, and we delete it when the matter ends.
Because these are legal obligations rather than choices, we cannot delete these records on request while the obligation lasts. When it ends, we delete or de-identify them.
5.4 Class 4 - Operational records
These are our per-turn usage log, our security logs, and the diagnostic logs our systems produce when something fails. They are not all the same kind of record and we do not describe them as though they were.
Our usage log has a fixed set of fields - account identifier, timestamp, the model used, and token counts - and cannot contain the content of your messages. The protection here is the schema rather than the calendar: the record cannot reveal what you said, because there is nowhere in it to put what you said. This is the record that meters your allowance and produces your bill, and it is the one we can guarantee.
Our diagnostic logs are a weaker guarantee and we would rather say so. Application and infrastructure logs exist to tell us that something broke and where. They are not designed to record what you wrote and we do not write your messages into them deliberately. But a diagnostic record made at the moment of a failure can capture a fragment of whatever was being processed when it failed, and we are not willing to promise you that this never happens. So: we do not use these logs to reconstruct conversations, we do not make them searchable by content, they are short-lived, and they expire on the schedule below whether or not you have deleted anything. If you delete a conversation, we do not go looking through diagnostic logs for it, and we would not find a usable copy if we did โ but the deletion described in Section 5.1 acts on the conversation itself, not on every diagnostic record that a failure may have touched.
These records do identify your account, so they are still personal information. We keep each kind for as long as it serves the purpose it exists for - billing and allocation accuracy, quota enforcement, fraud and abuse investigation, security-incident evidence, and defending legal claims - and no longer:
- Operational and application logs, including infrastructure request logs and application and database logs. These exist for troubleshooting and short-term security investigation, and we keep them for a period measured in weeks rather than months.
- Security-audit records we generate about your account, such as records of automated geographic blocking and spend-control decisions. These exist to evidence security decisions and support fraud investigation, and we keep them for a period measured in months, after which they are deleted or aggregated.
- Usage records that support billing: the same periods as the financial records in Class 3, because they substantiate what you were charged. Where we no longer need the per-request detail, we reduce these to aggregated totals.
You can ask us at privacy@exefast.ai what period currently applies to any of these and we will tell you. We keep a specific record beyond these periods only where an open investigation, a legal hold, a claim, or a legal preservation obligation (Section 5.6) requires it.
Logs about our own infrastructure. Our cloud provider keeps administrative audit logs recording actions taken by our personnel on the systems that run the Platform. These are records of our own operations rather than of you or your use of the Platform. Our provider sets their retention at up to 400 days and we are not able to shorten it.
5.5 Inactive accounts
We do not currently delete accounts for inactivity. If we introduce an inactivity period, we will give you advance notice before anything is deleted, and we will tell you what the period is and how to keep your account active.
5.6 How deletion works, and where you decide instead of us
When we delete personal information it is removed from our live systems and is not returned to the service. On a deletion request we delete or de-identify information no longer required, subject to carve-outs for legally required retention and fraud prevention. We may retain de-identified or aggregated information that no longer identifies you. When you close your account we hold your conversation content and the work you have created for 30 days, and then delete them. During those 30 days you can reopen your account and export your content; we do not use it for anything else in the meantime. If you would rather not wait, you can ask us to delete it immediately, and an erasure request made under Section 6 is acted on directly rather than held for the 30 days. Records we are required by law to keep (Section 5.3) are retained for the remainder of the applicable period.
Legal preservation. In rare cases we may be required by law to preserve specific information beyond the point at which it would otherwise be deleted - for example under a court order, litigation hold, regulatory demand, or a law-enforcement preservation request. This is an exception to every deletion commitment in this Section, including deletion at your request. Where it applies, we preserve only what the obligation covers, we do not use the preserved information for any other purpose, we delete it as soon as the obligation ends, and we tell you where we are legally permitted to do so.
Where we act as your processor. The periods above are the defaults we apply. Where you use the Services to process personal data about your own customers, contacts, or end-users, you decide what retention applies to that data: these defaults apply unless you configure or instruct otherwise, and our Data Processing Addendum governs that processing.
6. Your Rights
Depending on your location, you may have rights to access, correct, delete, and port your information, to opt out of sale/sharing, to limit use of sensitive information, and to non-discrimination - and, under GDPR/UK GDPR, to restriction, objection, withdrawal of consent, and to lodge a complaint with a supervisory authority. To exercise any of these rights, email privacy@exefast.ai, which is monitored for this purpose. Tell us what you are asking for; you do not need to use any particular form of words or cite a legal provision. We may ask for information reasonably necessary to confirm your identity before we act, and we will not use that information for any other purpose. Acting on your request is free of charge, unless a request is manifestly unfounded or excessive, in which case we will tell you why. Under the GDPR and UK GDPR we respond within one month of receiving your request; that period may be extended by up to two further months where a request is complex or where you have made a number of requests, and if we extend it we will tell you within the first month and explain why. Under applicable US state privacy laws we respond within 45 days, extendable once by a further 45 days on notice to you. If you are in the EEA or the UK, you may also contact our Article 27 representative (Section 10), and the same time limits run from when your request reaches them. If we decline a request, you may appeal by replying to our decision or emailing privacy@exefast.ai. Rights are subject to legal exceptions (including required retention of verification, tax, and compliance records). You may opt out of promotional messages at any time; transactional messages continue.
Automated decision-making. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. We use automated tools for fraud, abuse, and risk detection (for example, anti-fraud signals and payout holds described elsewhere in this Policy and our Terms); where such a measure significantly affects you, you may request human review by contacting privacy@exefast.ai.
7. International Users, Transfers, and Channels
By using the ExeFast Platform you understand your information is processed in the United States, where laws may differ from your home jurisdiction. For transfers from the EEA, UK, Switzerland, or similar jurisdictions, we rely on appropriate safeguards such as Standard Contractual Clauses (or the UK Addendum), adequacy decisions, or your consent where required. If you use integrated messaging or voice channels (WhatsApp, Telegram, telephony), your messages and metadata are processed by those providers under their own policies and may involve cross-border processing outside our control. Service availability and region-specific measures are governed by our launch list; users in non-approved regions may have restricted functionality.
8. Children
The ExeFast Platform is not directed to children under 18 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under that age. If we learn we have, we delete it promptly; contact privacy@exefast.ai. This applies equally where a plan is sponsored for someone else: a Slot does not create an exception to this age requirement, and eligibility to claim one is governed by Terms of Service Section 5A and Section 2.
9. Changes
We may update this Policy and will provide notice of material changes (email, in-app notice, or an updated "Last Updated" date). Continued use after the effective date constitutes acceptance.
10. Contact
privacy@exefast.ai EXEFAST INC, 1200 Brickell Ave, Suite 800, Miami, FL 33131, United States
EU GDPR Article 27 Representative: Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria, office@prighter.com. EEA users may contact our EU representative on any matter relating to the processing of their personal data.
UK GDPR Representative: Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom, office@prighter.com. UK users may contact our UK representative on any matter relating to the processing of their personal data.
Data Protection Officer: For all privacy matters, contact privacy@exefast.ai. Our EU representative under Article 27 is Prighter EU Rep GmbH (details above).