1. Introduction
LLMBase, operated by Eyloo GmbH, provides AI chat, model comparison, inference APIs, and related AI tools. This Privacy Policy explains how we process personal data when you use our website, account area, applications, and services.
We process personal data in accordance with the GDPR and applicable German data protection law. For business customers, our Data Processing Agreement provides the processor terms, technical and organizational measures, subprocessor information, retention commitments, and professional secrecy protections.
2. Controller and Contact
The controller responsible for the processing described in this Privacy Policy is:
Eyloo GmbH
Im Hemchen 29
56410 Montabaur
Germany
Email: privacy@llmbase.ai
3. Data We Process
Depending on how you use LLMBase, we process the following categories of data:
- Account Data: name, email address, authentication data, workspace membership, plan, and account settings.
- Customer Content: prompts, files, messages, chat history, API inputs, generated outputs, and workspace content you submit or create.
- Operational Metadata: model selections, timestamps, request identifiers, token and usage counters, feature interactions, error events, rate-limit data, and security logs.
- Billing Data: subscription, invoice, payment, tax, and transaction information.
- Support Data: messages, diagnostics, attachments, and contact details you provide when requesting support.
- Website and Analytics Data: page activity, referrer and campaign parameters, cookie preferences, device information, browser information, and approximate location derived from technical request data.
4. AI Processing and Model Use
4.1 Model-Hosting Providers
Requests from LLMBase Chat and the LLMBase Inference API are processed by model-hosting providers that run the requested models. These providers process prompts and responses to generate the output under their own terms. They may be established or process data outside the European Economic Area, including in the United States, Singapore, and the People's Republic of China. Through our configuration, requests are forwarded only to provider endpoints that, according to the information available to us on the providers' data policies, do not use inputs for training. Some of these providers still retain inputs for periods they determine; such retention is separate from use for training.
4.2 Optional External Model Paths
LLMBase may make optional external, lab, or proprietary model paths available in the product. We do not name those optional providers in this Privacy Policy. Customer Content is sent to those paths only where you select the path, activate the relevant provider or account setting, or give feature-specific approval.
For optional external, lab, or proprietary model paths, LLMBase sends only the content, model settings, and technical parameters needed to produce the selected response. LLMBase account identifiers, session tokens, billing data, and internal analytics identifiers are not included in the model prompt unless technically necessary for the specific feature.
4.3 No Model Training by LLMBase
We do not use Customer Content to train, fine-tune, or evaluate AI models, or to develop or improve our own models, request routing, or services. This applies to prompts, uploaded files, chat messages, generated outputs, and API payloads. Quality testing, monitoring, and model selection use only synthetic test inputs and Operational Metadata that does not contain Customer Content. Processing by model-hosting providers is described in section 4.1.
We may use Operational Metadata to operate, secure, debug, bill, and improve the usability of the service, including capacity planning and product analytics. Operational Metadata is not used to train, fine-tune, evaluate, or improve AI models.
5. Purposes and Legal Bases
We process personal data for the following purposes and legal bases:
- Contract performance (Art. 6(1)(b) GDPR): to provide accounts, workspaces, AI features, API access, subscriptions, support, and requested product functionality.
- Legitimate interests (Art. 6(1)(f) GDPR): to secure the service, prevent misuse and fraud, maintain reliability, debug errors, understand product usage, and improve the usability of the service without using Customer Content for AI model training or evaluation.
- Legal obligations (Art. 6(1)(c) GDPR): to comply with tax, accounting, commercial, security, and legal requirements.
- Consent (Art. 6(1)(a) GDPR): for optional cookies, marketing communications, and optional features that require consent. You can withdraw consent at any time with effect for the future.
Online-Kündigung („Verträge hier kündigen“)
Wenn Sie über unsere Kündigungsseite einen Vertrag kündigen, verarbeiten wir die von Ihnen angegebenen Daten (E-Mail-Adresse, Vertragsart, Art und gewünschter Zeitpunkt der Kündigung, ggf. Kündigungsgrund) sowie Datum und Uhrzeit des Eingangs. Wir nutzen sie, um Ihre Kündigung Ihrem Vertrag zuzuordnen, sie auszuführen, Ihnen den Eingang und das Vertragsende zu bestätigen und die Kündigung nachweisen zu können. Rechtsgrundlagen sind die Erfüllung unserer gesetzlichen Pflichten aus § 312k BGB (Art. 6 Abs. 1 lit. c DSGVO) und die Durchführung bzw. Beendigung des Vertrags (Art. 6 Abs. 1 lit. b DSGVO). Die Aufbewahrung als Nachweis beruht auf unserem berechtigten Interesse, Rechtsansprüche geltend zu machen oder abzuwehren (Art. 6 Abs. 1 lit. f DSGVO).
Zum Schutz vor automatisiertem Missbrauch setzen wir auf dieser Seite Cloudflare Turnstile ein (Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA). Dabei werden Ihre IP-Adresse und technische Merkmale Ihres Browsers an Cloudflare übermittelt (Art. 6 Abs. 1 lit. f DSGVO). Für Übermittlungen in die USA stützen wir uns auf das EU-U.S. Data Privacy Framework bzw. auf Standardvertragsklauseln. Ihre Kündigung nehmen wir auch dann entgegen, wenn diese Prüfung fehlschlägt.
Zur Begrenzung missbräuchlicher Anfragen speichern wir statt Ihrer IP-Adresse nur einen mit einem geheimen Schlüssel gebildeten Hashwert (HMAC) und löschen ihn nach 24 Stunden (Art. 6 Abs. 1 lit. f DSGVO). Wird eine Kündigung ohne Anmeldung ausgeführt, senden wir die Bestätigung zusätzlich an die im Kundenkonto hinterlegte E-Mail-Adresse, damit der Vertragsinhaber eine nicht von ihm veranlasste Kündigung erkennen und rückgängig machen kann (Art. 6 Abs. 1 lit. b und f DSGVO).
Auf der Kündigungsseite findet keine Webanalyse statt. Wir löschen die Kündigungsdaten 3 Jahre nach Ablauf des Kalenderjahres, in dem der Vertrag beendet wurde, soweit keine längeren gesetzlichen Aufbewahrungspflichten bestehen.
6. Processors, Subprocessors, and Transfers
We use carefully selected processors and subprocessors for hosting, authentication, database infrastructure, security, analytics, billing, support, and optional AI model paths. Business customers can review the current subprocessor list in the Data Processing Agreement.
- Cloudflare, Inc. (USA) – Hosting, Datenbank, Sicherheit, E-Mail-Versand
- Hetzner Online GmbH (Deutschland) – Infrastruktur und Dateispeicher
- Hanko GmbH (Deutschland) – Authentifizierung
- Stripe, Inc. (USA) und RevenueCat, Inc. (USA) – Zahlungen und App-Käufe
- Functional Software, Inc. (Sentry, USA; US-Region) – Fehlerüberwachung
- PostHog Inc. (USA; EU-Cloud) – Produktanalyse im Chat
- Zoho Corporation (Zoho Mail, USA) – E-Mail-Postfächer
- MVP Stack LLC (Piqo) – Web-Analytics
- Pirsch Analytics (Emvi Software GmbH, Deutschland)
When you use search, lookup, or research tools in LLMBase Chat, queries derived from your conversation (for example search terms, place names, or links) are sent to the relevant external service, such as search, map, weather, scholarly, or documentation services. The Data Processing Agreement (Annex A) lists these services.
Where processing outside the European Economic Area is necessary, we use appropriate safeguards such as adequacy decisions, Standard Contractual Clauses, transfer impact assessments, encryption, access controls, and data minimization. Inference by model-hosting providers can involve processing in third countries (see 4.1). Optional external, lab, or proprietary model paths additionally require product selection, account activation, or feature-specific approval.
We configure analytics and security tools to reduce personal-data exposure where practical, including IP truncation or minimization, access controls, limited retention, and cookie controls where required.
7. Security and Confidentiality
We implement technical and organizational measures designed to protect personal data, including encrypted transport, access controls, role-based permissions, monitoring, logging, backup controls, vulnerability management, and confidentiality obligations for personnel with authorized access.
Access to Customer Content is limited to what is necessary for providing, securing, supporting, or legally administering the service.
8. Retention
We keep personal data only for as long as needed for the purposes described in this policy, unless a longer period is required by law:
- Account Data: retained while the account is active and deleted or anonymized within 30 days after account closure, unless legal retention duties apply.
- Customer Content: retained according to product settings and feature behavior, and deletable where supported in the product.
- Chat history: when you use LLMBase Chat with an account, we store your conversations, chat titles, uploaded files, and the text extracted from those files so you can continue your conversations later. We keep them until you delete the chat or your account. You can delete individual chats at any time, and deleting your account deletes all of your chats. Chats you use without an account are stored only in your browser.
- Workspace content: files, their extracted text, and instructions you add to a Workspace are stored until you delete them, the Workspace, or your account.
- Inference API requests: LLMBase does not store prompts, inputs, outputs, or tool content of requests to the LLMBase Inference API (api.llmbase.ai) in its application databases or logs after the response is completed. Requests are processed by model-hosting providers (see 4.1); some of these providers retain inputs for periods they determine under their own terms. This commitment applies only to the Inference API, not to LLMBase Chat or Workspaces.
- Operational Metadata: retained for limited periods needed for security, debugging, billing, analytics, and service reliability.
- Billing Data: retained for statutory tax and accounting periods, generally up to 10 years under German law.
- Support Data: generally retained for up to 3 years unless a longer period is needed for legal claims or compliance.
9. Professional Secrecy and Protected Content
Where customers process professional secrets or similarly protected information through LLMBase, we treat that content as confidential Customer Content. Our Data Processing Agreement includes additional professional secrecy obligations, confidentiality controls, access restrictions, breach notification duties, and deletion commitments.
10. Cookies and Analytics
We use essential cookies and similar technologies for authentication, session security, preferences, fraud prevention, and service operation. Until you accept functional cookies, we load Piqo in cookieless mode for website analytics. In this mode, Piqo does not set a Piqo visitor cookie and uses a daily rotating pseudonymous identifier for visitor and session measurement. If you accept functional cookies, Piqo uses a first-partypiqo_visitor cookie to keep visitor identity stable across sessions and support payment-source attribution. Your functional choice also enables optional advertising conversion measurement and other optional features where indicated.
You can manage cookie preferences through the cookie banner and your browser settings. Disabling essential cookies may affect service functionality.
Webanalyse mit Pirsch Analytics
Um die Nutzung unserer Website statistisch auszuwerten und zu messen, wie viele Besucherinnen und Besucher eine Registrierung oder einen Kauf abschließen, setzen wir Pirsch Analytics ein, einen Dienst der Emvi Software GmbH, Nickelstraße 1b, 33378 Rheda-Wiedenbrück, Deutschland. Pirsch verarbeitet die Daten in unserem Auftrag auf Grundlage eines Vertrags zur Auftragsverarbeitung (Art. 28 DSGVO) auf Servern in Deutschland (Hetzner Online GmbH, Nürnberg und Falkenstein).
Pirsch setzt keine Cookies und speichert keine Informationen auf Ihrem Endgerät. Bei Seitenaufrufen und bei bestimmten Ereignissen übermitteln unsere Server folgende Daten an Pirsch: Ihre IP-Adresse, die Browserkennung (User-Agent), die Spracheinstellung Ihres Browsers, vom Browser gesendete technische Angaben (Browsermarke, Gerätetyp, Betriebssystem), die aufgerufene Seite (ohne persönliche Parameter), die verweisende Website und Kampagnenparameter (z. B. utm_source, utm_medium, utm_campaign). Ereignisse sind: Abschluss einer Registrierung, Anmeldung, Start und Abschluss eines Kaufs oder einer Guthabenaufladung, Einrichtung und Abschluss der automatischen Guthabenaufladung sowie deren automatische Ausführung, Vormerkung einer Kündigung sowie Interaktionen auf unseren öffentlichen Seiten, etwa die Auswahl eines Tarifs auf der Preisseite, Klicks auf Handlungsaufforderungen (z. B. „Jetzt starten“) und Klicks auf Links zu anderen Websites. Diese Interaktionen sendet Ihr Browser an unseren Server, der sie mit den oben genannten Angaben an Pirsch weiterleitet. Zu Ereignissen übermitteln wir je nach Art zusätzlich: bei Kauf und Guthabenaufladung Produkt, Tarif, Abrechnungsart, Betrag und Währung; bei einer Kündigung Produktbereich, gekündigten Tarif und den Ort der Kündigung (z. B. Kontoeinstellungen); bei Interaktionen den gewählten Tarif oder das angeklickte Element und die Zielseite. Name, E-Mail-Adresse sowie Nutzer- oder Kundennummer übermitteln wir nicht an Pirsch. Damit eine Anmeldung nur einmal je Sitzung gezählt wird, speichern wir einen nicht umkehrbaren Hashwert der Sitzungskennung höchstens 35 Tage auf unseren Servern. Damit ein Kauf auch dann gezählt wird, wenn Sie nach der Zahlung nicht auf unsere Website zurückkehren oder die Zahlung erst später bestätigt wird, speichern wir IP-Adresse, User-Agent und Spracheinstellung beim Start des Bezahlvorgangs vorübergehend auf unseren Servern. Wir löschen diese Angaben, sobald das Kaufereignis an Pirsch übermittelt wurde oder der Bezahlvorgang abgebrochen bzw. abgelaufen ist, spätestens nach 14 Tagen.
Pirsch bildet aus IP-Adresse, User-Agent, dem aktuellen Datum und einem für unsere Website spezifischen Salt einen Hashwert als pseudonyme Besucherkennung. Weil das Datum einfließt, ändert sich diese Kennung täglich: Sie können nicht länger als 24 Stunden wiedererkannt und nicht über verschiedene Websites hinweg verfolgt werden. Die IP-Adresse wird von Pirsch weder vollständig noch teilweise gespeichert. Aus ihr wird über eine lokal betriebene Datenbank lediglich ein ungefährer Standort (Land, Stadt) abgeleitet. Den User-Agent speichert Pirsch getrennt von den Seitenaufrufen für bis zu drei Monate. Die statistischen Auswertungen bewahren wir auf, solange wir sie für die Produktsteuerung benötigen, höchstens 24 Monate.
Rechtsgrundlage ist unser berechtigtes Interesse an einer datensparsamen Reichweiten- und Erfolgsmessung zur Verbesserung unseres Angebots (Art. 6 Abs. 1 lit. f DSGVO). Sie können dieser Verarbeitung aus Gründen, die sich aus Ihrer besonderen Situation ergeben, jederzeit widersprechen (Art. 21 DSGVO), z. B. per E-Mail an privacy@llmbase.ai.
11. Your GDPR Rights
Subject to the legal requirements, you have the right to access, rectify, erase, restrict, object to processing, receive data portability, and withdraw consent where processing is based on consent.
To exercise your rights, contact privacy@llmbase.ai. We will respond within the period required by GDPR.
12. Children's Privacy
LLMBase is not intended for children under 16 years of age or the applicable age of digital consent in your jurisdiction. We do not knowingly collect personal data from children.
13. Changes
We may update this Privacy Policy to reflect product, legal, technical, or operational changes. We will post the updated version with a new "Last updated" date and provide additional notice where legally required.
14. Supervisory Authority
You have the right to lodge a complaint with a supervisory authority if you believe that our processing of personal data violates data protection law.
For Rheinland-Pfalz, the competent supervisory authority is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Rheinland-Pfalz
Website: www.datenschutz.rlp.de