1. Who operates Eight
Eight is a developer workspace operated under the Acetheticsx name. The production website is eight.ace-base.cc. The operator’s formal legal entity, postal address, and dedicated privacy contact should be published here before the service is offered broadly.
2. Information we may process
- Account and sign-in data: identifiers and authentication responses received through Ace ID, plus session state needed to keep you signed in.
- Workspace content: agent names, instructions, configuration, test prompts, and outputs you choose to create or submit.
- AI request data: the prompt and relevant context required to generate a response through the configured model provider.
- Technical and security data: request metadata, error details, and abuse-prevention signals generated while operating and protecting the service.
- Browser storage: essential session mechanisms and the consent preference you choose in the cookie banner.
3. How we use information
We use data to authenticate users, provide workspace and widget functionality, route AI requests, protect the service, diagnose failures, and respond to support or legal requests. We do not describe product usage as analytics unless a real measurement system is enabled.
4. AI providers and embedded widgets
When you submit a prompt for inference, the prompt and necessary context are sent from the server to the model provider configured for the deployment, such as Groq or OpenAI. The applicable provider’s terms and privacy policy may govern its processing. Do not submit passwords, payment details, sensitive personal information, or confidential data unless you are authorized to do so and have assessed the relevant provider terms.
Published widget instructions and configuration required by an embed may be visible to people who can access that widget. Never place API keys, private credentials, or secrets in agent instructions or embed snippets.
5. Storage and retention
Agent drafts are currently described by the product as browser-local and account-scoped; they are not necessarily synced across browsers. Authentication uses a server-managed session cookie. Optional database features may process data when configured. Retention periods depend on the data type, deployment configuration, security needs, and applicable obligations; the operator should document concrete deletion windows before launch.
6. Sharing and service providers
Information may be processed by infrastructure, authentication, database, and AI providers that are required to operate features you use. It may also be disclosed when required by law or when reasonably necessary to investigate abuse, protect users, or secure the service. The operator should maintain a current vendor and subprocessor list and link it here when finalized.
7. Your choices and rights
You can avoid submitting information that is not necessary, manage optional consent through “Cookie settings” in the footer, and stop using the service. Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, or to withdraw consent. A verified privacy contact and a documented request workflow are required to exercise those rights reliably.
8. Security
Eight is designed to keep model provider credentials server-side and use authenticated sessions for protected workspace routes. No online service can promise absolute security. Report suspected vulnerabilities through the instructions on our Security page.
9. Children and international processing
Eight is a developer tool and is not designed for children. Service providers may process information in locations different from yours. The operator should identify the actual processing locations and safeguards before launch.
10. Changes and contact
This policy may change as the product and its providers change. The date above identifies the current revision. The operator must publish a monitored privacy contact and its formal identity before treating this draft as a final, legally reviewed policy.