Privacy Policy
Last updated: July 28, 2026
This Privacy Policy (this “Policy”) describes the practices of Unbox Inc., doing business as Openlayer (“Openlayer,” “Unbox,” “us,” “we,” or “our”) for collecting, using, maintaining, disclosing, and otherwise processing (collectively, “processing”) the information that we collect from you via this website, when you use our platform and services, or that we receive from others, as well as how we protect and secure your data. Openlayer provides an AI and machine learning evaluation, testing, observability, and monitoring platform. If anything in this Policy conflicts with specific terms in any agreement you may have with Openlayer, those terms apply. If you have questions about this Policy, please contact us at support@openlayer.com.
Controller and Processor Roles
When you visit our website, contact us, or sign up for and administer an account, Openlayer acts as a “controller” of your personal information, and this Policy governs that processing. Separately, our clients use our platform to test, evaluate, and monitor their own AI and machine learning systems, and in doing so may send us data, including datasets, model inputs and outputs, prompts and completions, traces, and logs, that can contain personal information about third parties (“Customer Data”). With respect to Customer Data, Openlayer acts merely as a “processor,” processing the data on behalf of and subject to the direction and control of our client, who is the “controller.” This Policy does not govern our processing of Customer Data; that processing is governed by our agreement with the relevant client, including our Data Processing Agreement, and by that client’s own privacy policy. It is our policy to treat all Customer Data with at least the same care described in this Policy. If you believe a client of ours is processing your personal information unlawfully, please contact that client directly, and you may also contact us at support@openlayer.com.
1. Information We Collect
We collect both Personal Information and Non-Personal Information. We collect it when you provide it to us, when you purchase or inquire about our goods or services, when you register for or use our platform, when you provide it to our clients for processing using our platform, and, in certain circumstances, automatically when you visit our website or use our services through cookies and other tracking technologies.
When we say “Personal Information,” we are referring to information that can be used to identify, locate, or contact you, a natural person, as well as any other information about you that we may connect with Personal Information to identify you, and any other information that is otherwise defined as personal information under applicable law. Personal Information we collect might include:
- Contact information such as your first and last name, email address, phone number, company, job title, and physical address;
- Account and authentication information such as your username, password (stored only in hashed form), single sign-on identifiers (for example, Google or GitHub), and multi-factor authentication settings;
- Relationship information such as your preferences or potential interest in our goods and services;
- Transactional and billing information such as purchases, services requested, subscription and payment details (processed by our payment processor), customer service inquiries, session data, customer account activity, and other customer account information; and
- Identifiable internet, device, and usage information, such as IP address, browser and device information, browser history and usage information, product usage and feature interactions, and interactions with our website or advertisements, to the extent such information is kept in a form that can identify you.
Separately, when your data is processed by a client of ours using our platform, it is processed as Customer Data. The personal information within Customer Data is specific to that client’s use of the platform and could include the categories of Personal Information described above, as well as more sensitive personal information, such as your opinions on various topics, your location, your gender, sex, or age, your financial information, or your health or biometric information, among other things, depending entirely on what the client chooses to submit. As described above, we do not collect Customer Data from you ourselves and act only as a processor with respect to it.
“Non-Personal Information,” on the other hand, is information that does not identify you as a natural person and is not identifiable to you as a natural person. For example, Non-Personal Information that we collect includes:
- Cookies and other tracking technologies that are processed strictly in a non-identifiable way;
- Information that is anonymous or that we anonymize by rendering it unidentifiable to a natural person;
- Information that is aggregated or that we aggregate by combining it with other data in such a way that no natural person can be identified; and
- The name, form, contact details, relationship information, transactional information, or financial information of legal persons and their representatives.
2. How We Use Personal Information
We collect Personal Information for a variety of purposes depending on the information being processed. For example, we may collect your contact information so that we can provide you with details of our goods and services, set up and operate your account, or offer you goods and services in which we think you might be interested.
With respect to Customer Data, the reason we have this information is because the client providing it is using our platform. We do not access or otherwise use Customer Data except as necessary to provide, secure, and support the platform for that client, and to assess, maintain, improve, and develop our services. We do not share Customer Data between clients. We do not use Customer Data to train, fine-tune, or otherwise develop our own or any third party’s foundation or machine learning models, and we do not sell Customer Data.
With respect to Personal Information that we collect as a controller, including contact information, account information, relationship information, transactional information, and identifiable internet information, we may process this information to provide and operate our services and to further our legitimate business interest in communicating offers for goods and services, including targeted offers based on your potential interests and a profile created based on your industry, company, role or function, email address, and search history. We will provide you with the opportunity to opt out of direct marketing communications or market research inquiries, but we will still need to gather certain Personal Information as necessary to accomplish the other purposes described here. In short, we process Personal Information to:
- serve our clients and provide our platform and services;
- oversee and complete transactions with our clients;
- prepare, deliver, maintain, secure, and otherwise provide our goods and services;
- support, improve, and develop our goods and services;
- set up and maintain your user account and allow you to interact with us;
- provide customer service by resolving disputes, addressing complaints, and troubleshooting technical problems;
- measure and understand the effectiveness of our goods and services; and
- comply with applicable laws and regulations.
If we would like to process your Personal Information for any other purpose, we will disclose this to you at the time we collect it and may request your express consent. With respect to Non-Personal Information, because this information does not identify you, we may use and process it for any purpose. We do not sell, rent, or lease your Personal Information to others.
3. Storage and Processing
Our cloud (SaaS) platform is hosted on Amazon Web Services (AWS) in the United States (primarily the AWS us-west-2 region). Within that environment, we store account, workspace, billing, and configuration data in managed relational databases (PostgreSQL); inference logs, traces, spans, and evaluation results in analytical and document data stores (such as ClickHouse and MongoDB); files and datasets in object storage (such as Amazon S3); and use in-memory data stores (such as Redis) for queuing and caching. Sensitive credentials and secrets are encrypted before storage, and data is encrypted in transit and at rest.
Openlayer also offers self-hosted and on-premise deployments. When the platform is deployed in a customer-controlled environment, Customer Data remains in that environment, billing integrations are disabled, and the product telemetry and analytics described below are disabled by default. The model providers and integrations used in a self-hosted deployment are those the customer chooses to configure.
4. AI and Large Language Models
Certain features of our platform rely on third-party large language model providers. For our managed AI features (such as the Openlayer Assistant and AI-assisted insights), we transmit relevant portions of Customer Data to a model provider we engage as a subprocessor (currently OpenAI), under terms intended to prohibit it from using the data we send to train its models and to limit retention.
For evaluations and LLM-as-a-judge, and where you otherwise connect your own model providers, you configure the model provider and supply your own credentials (for example, OpenAI, Anthropic, Microsoft Azure OpenAI, Amazon Web Services (Bedrock), Google, or Cohere). In that case the data is processed under your own account and agreements with that provider, and the provider is your vendor, not an Openlayer subprocessor.
We do not use Customer Data to train, fine-tune, or otherwise develop our own or any third party’s foundation or machine learning models. Where we improve our own services, we do so using configuration, performance, and usage information, and using aggregated or de-identified data that does not identify any natural person.
5. How We Share Information
To operate, monitor, analyze, develop, improve, secure, and market our goods and services, we may share Personal Information with our service providers, vendors, subprocessors, or the developers and operators of our software. In the event we share Personal Information with any third party, we maintain adequate controls and oversight, including contractual obligations where appropriate, to ensure that any third party we engage will only have access to the Personal Information necessary to perform specific, designated tasks on our behalf, will only use the information for that purpose, and will protect your Personal Information to at least the same extent that we do. The categories of service providers and subprocessors with whom we may share information include:
- Cloud hosting and infrastructure: Amazon Web Services (backend and platform hosting) and Vercel (website hosting);
- AI model providers: OpenAI, which we engage to power our managed AI features (providers you connect with your own credentials for evaluations or LLM-as-a-judge are your vendors, not our subprocessors);
- Product analytics and error monitoring: PostHog and Mixpanel (product usage analytics), Sentry (error monitoring and diagnostics), and website analytics provided through Vercel and Google Tag Manager;
- Sales, marketing, and engagement: HubSpot (CRM), ZoomInfo (website visitor identification), and our scheduling provider for booking meetings;
- Communications and email: Google Workspace, Resend, and Slack;
- Authentication and identity: Google and GitHub (sign-in) and WorkOS (enterprise single sign-on and directory sync); and
- Payments: Stripe, our payment processor, for subscription billing.
We also use GitHub to host and review code, manage projects, and build our software. An up-to-date list of our subprocessors is available on our Trust Center at trust.openlayer.com. The cookies and tracking technologies that involve these providers, and how to control them, are described in our Cookie Policy.
This Policy applies only to information that we process and share with others; it does not apply to Personal Information that you share with others. With respect to Customer Data, the client for whom we process it necessarily has access to it, as they direct and control the processing. We may also share your Personal Information to comply with our legal obligations, such as responding to lawful requests from government or judicial entities. If we are asked to provide Personal Information pursuant to a lawful subpoena or court order, we will, to the extent reasonably practicable and legally permissible, attempt to first notify you to allow you the opportunity to seek protection from disclosure. Finally, we may disclose Personal Information as part of a sale or transfer of our assets, or to enforce our rights and protect the rights, property, or safety of others; any successor entity will only be permitted to access Personal Information if it is first subject to the same commitments we have made to you.
6. Data Retention
We keep different kinds of information for different lengths of time depending on the purpose for which we are processing the information and your specific situation, in accordance with our internal Data Management Policy. In any event, we will retain your Personal Information only as long as necessary to accomplish the relevant purpose, or as required to comply with our legal obligations, resolve disputes, and enforce our agreements, but no longer. With respect to Customer Data, retention is determined by our agreement with the relevant client; following termination, Customer Data is made available for export for a limited period and then deleted in the ordinary course.
7. Security
Taking into account the nature of the information gathered and prevailing industry standards, we maintain a comprehensive security program that is reasonably designed to protect the security, confidentiality, and integrity of your Personal Information through administrative, technical, and physical controls appropriate to the sensitivity of the information, including encryption of data in transit and at rest, access controls, and logging. We maintain security and privacy programs designed to comply with leading industry frameworks and regulations, including SOC 2, ISO 27001, GDPR, and HIPAA (in each case, as applicable to our operations). For more information about our information security program, including our certifications and security documentation, visit our Trust Center at trust.openlayer.com or contact us.
8. Your Choices
Your first choice is always to limit the information you provide. You may also opt out of certain marketing information by communicating your choices to us or by clicking “unsubscribe” at the bottom of marketing emails you receive.
Regarding cookies and other tracking technologies: a cookie is a small file placed on your device that helps analyze web traffic and lets a site recognize you across visits. We use a consent management tool to let you accept or decline non-essential cookies, and we honor the choices you make there. Our use of cookies and tracking technologies, the categories of cookies we use (strictly necessary, performance, functional, and targeting), and how to control them are described in our Cookie Policy.
You can choose to accept or decline cookies and other tracking technologies. Most web browsers automatically accept cookies, but you can usually modify your browser settings to decline them or to signal your preferences through features such as “Do Not Track.” In general, we will comply with your browser’s “Do Not Track” settings, and we honor recognized opt-out preference signals such as the Global Privacy Control (GPC); however, please note that disabling certain cookies may limit your ability to fully experience the features of our website.
We will support your ability to access, correct, and delete your Personal Information. If we have obtained your Personal Information from your employer, we may first have to confirm your request through them. Where your information is contained in Customer Data controlled by one of our clients, please direct your request to that client; we will support our client in responding to it. For assistance with exercising your choices, please contact us.
9. Children
We do not intend to collect Personal Information from children under the age of 16. If you believe a child is providing us Personal Information, please contact us directly and immediately so that we may investigate and delete it.
10. International Transfers
We are headquartered in the United States of America. We and our authorized processors must therefore transfer your information to, and access it from, the United States for the purposes described in this Policy. Where we transfer personal information from the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses. We protect the privacy and security of Personal Information in the manner described in this Policy regardless of where it is collected, stored, accessed, or otherwise processed.
11. European Economic Area Residents (GDPR)
The General Data Protection Regulation (“GDPR”), particularly Articles 15 to 21, affords you a number of rights as a data subject residing in the European Economic Area (EEA):
- Access: to request information about your personal information, including what data we have and how and why it is being processed;
- Rectification: to have inaccurate personal information corrected;
- Erasure: in some cases, to request that we erase your personal information;
- Restriction of Processing: in some circumstances, to have us process your personal information only with your consent;
- Objection to Processing: where we process on the grounds of legitimate interests, to object on grounds relating to your particular situation (and, for direct marketing, the processing will cease); and
- Data Portability: to request a copy of your personal information and to transfer it to someone else.
To the extent we process your personal information on the basis of your consent, you have the right to withdraw that consent at any time, without affecting the lawfulness of processing before its withdrawal. If you believe we have violated one of your rights, you have the right to lodge a complaint with a Data Protection Authority.
12. California Residents (CCPA)
This notice does not apply to employment-related Personal Information collected from California-based employees, job applicants, contractors, or similar individuals. The California Consumer Privacy Act, as amended by the California Privacy Rights Act (the “CCPA”), affords California residents certain rights:
- Access: to request that we disclose certain information about our collection and use of your Personal Information;
- Correction: to request that we correct inaccurate Personal Information we maintain about you;
- Erasure: in some cases, to request that we erase your Personal Information;
- Data Portability: to request a copy of your Personal Information and to transfer it to someone else (we will verify any third party that purports to represent you);
- Opt Out of Sale or Sharing: to direct us not to sell your Personal Information and not to “share” it for cross-context behavioral advertising. You may exercise this right through our cookie consent tool, by broadcasting an opt-out preference signal such as the Global Privacy Control (GPC), or by contacting us; and
- Limit Sensitive Personal Information: where applicable, to direct us to limit the use of your sensitive Personal Information to the purposes permitted by law.
We do not sell your Personal Information for money. To the extent our advertising or analytics cookies result in a “sale” or “sharing” under the CCPA, you may opt out as described above. We will not discriminate against you for exercising any of your CCPA rights. California’s “Shine the Light” law also permits you to request certain information regarding our disclosure of Personal Information to third parties for their direct marketing purposes. To make a request, contact us at support@openlayer.com, or through the form at https://openlayer.com/contact.
13. Changes to This Policy
It is our policy to post any changes to this Policy on this page; please refer to the “Last Updated” date above. Except where otherwise indicated in this Policy or where required by law, we may or may not contact you directly concerning changes, and we therefore encourage you to visit this page periodically. To the extent permitted by law, your continued use of our services after a change is deemed to be your consent to that change.
14. How to Contact Us
For questions about this Policy or to exercise any of the rights or choices described in this Policy, please contact us at support@openlayer.com, or through the form at https://openlayer.com/contact.
Data Protection Lead: Rishab Ramanathan, CTO, rishab@openlayer.com.
Our EU Representative
Under Article 27 of the GDPR, we have appointed an EU Representative to act as our data protection agent: Instant EU GDPR Representative Ltd., Adam Brogden, contact@gdprlocal.com, Tel +353 1 554 9700, Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland.
Our UK Representative
Under Article 27 of the UK GDPR, we have appointed a UK Representative to act as our data protection agent: GDPR Local Ltd., Adam Brogden, contact@gdprlocal.com, Tel +44 1772 217800, 1st Floor Front Suite, 27-29 North Street, Brighton, England.