Privacy Policy
Last updated: March 12, 2026
Introduction
NoBurn ("we," "us," or "our") operates the NoBurn service at noburn.ai, a resilient streaming proxy for Large Language Model (LLM) APIs. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.
NoBurn is currently in beta. While we are committed to protecting your privacy at every stage, please be aware that the service and this policy may evolve as we approach general availability.
By accessing or using NoBurn, you agree to the terms of this Privacy Policy. If you do not agree with the practices described herein, please do not use our service.
1. Information We Collect
1.1 Account Information
When you register for NoBurn, we collect information necessary to create and manage your account, including:
- Email address
- Name or organization name
- Billing information (processed by our third-party payment processor; we do not store full payment card details)
- API keys that you generate for authentication (stored as SHA-256 hashes — we never store your raw API keys)
1.2 API Usage Data
We collect metadata about your use of the NoBurn proxy service, including:
- Request and response timestamps
- Upstream LLM provider endpoints you proxy through NoBurn
- Request counts, byte volumes, and stream durations (for metering and billing)
- Reconnection events and stream buffer utilization metrics
- Error rates and HTTP status codes
1.3 Temporarily Buffered Stream Content
NoBurn's core function is to buffer LLM API streaming responses so that clients can reconnect after network disruptions. When you proxy an LLM API call through NoBurn, we temporarily store the streamed response data in an encrypted buffer. This data is held for the duration of your configured time-to-live (TTL), which can range from a few hours up to 30 days, after which it is automatically and permanently deleted.
We treat buffered stream content as opaque data. We do not read, analyze, mine, or use the content of LLM responses for any purpose other than delivering it to your client upon reconnection. See Section 6 for more detail.
1.4 Webhook Configuration
If you configure webhooks, we store the callback URLs you provide. Webhook payloads contain stream status metadata (e.g., completion events, errors) but do not include the content of LLM responses unless you have explicitly configured your integration to do so.
1.5 Server Logs
We collect standard server logs that may include IP addresses, user agent strings, request paths, timestamps, and error details. These logs are used for operational monitoring, debugging, and security purposes and are retained for no more than 90 days.
1.6 Analytics
We may collect anonymized, aggregated analytics about how users interact with the NoBurn website and dashboard (e.g., page views, feature usage patterns). We use this information to improve the service and do not link analytics data to individual LLM stream content.
2. How We Use Your Information
We use the information we collect for the following purposes:
- Service Operation: To proxy, buffer, and deliver LLM API responses; to authenticate your requests; and to manage your account.
- Metering and Billing: To measure your usage of the service, generate invoices, and process payments.
- Debugging and Support: To diagnose technical issues, respond to support requests, and maintain service reliability.
- Service Improvement: To analyze aggregate usage patterns (not stream content) to improve performance, reliability, and features.
- Security: To detect and prevent fraud, abuse, and unauthorized access to the service.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
- Communication: To send you service-related notices, including beta updates, maintenance windows, and security alerts.
3. Data Retention
3.1 Stream Buffers
Buffered LLM stream data is inherently temporary. Each stream buffer has a configurable TTL (time-to-live) that you control, ranging from a few hours to a maximum of 30 days. Once the TTL expires, the buffer is automatically and permanently deleted. You may also manually delete buffered data at any time through the API.
3.2 Account Data
We retain your account information for as long as your account is active. If you delete your account, we will remove your personal information within 30 days, except where retention is required by law (e.g., billing records for tax compliance, which may be retained for up to 7 years).
3.3 Logs and Metrics
Server logs are retained for up to 90 days. Aggregated, anonymized usage metrics may be retained indefinitely as they cannot be linked to individual users or stream content.
4. Data Security
We implement technical and organizational measures designed to protect your data:
- API Key Hashing: All API keys are stored as SHA-256 hashes. We never store your raw API key after initial generation.
- Encryption in Transit: All data transmitted between your clients, NoBurn, and upstream LLM providers is encrypted using TLS.
- Network Isolation: Administrative endpoints and internal monitoring dashboards are isolated behind network-level access controls and are not exposed to the public internet.
- Multi-Tenant Isolation: Each customer's buffered data is logically isolated. Customers cannot access another customer's streams, keys, or usage data.
- Access Controls: Internal access to production systems is restricted to authorized personnel and follows the principle of least privilege.
While we strive to use commercially acceptable means to protect your data, no method of electronic storage or transmission over the internet is 100% secure. We cannot guarantee absolute security.
5. Third-Party Services
NoBurn interacts with or relies on the following categories of third-party services:
5.1 LLM API Providers
NoBurn acts as a proxy between your client and the upstream LLM provider(s) you specify (e.g., OpenAI, Anthropic, Google, Mistral, and others). When you route a request through NoBurn, we forward your request — including any API keys and content you send — to the designated provider. The LLM provider's own privacy policy governs how they handle your data. NoBurn does not modify the content of requests or responses.
5.2 Payment Processors
We use third-party payment processors to handle billing transactions. These processors receive your payment information directly and are governed by their own privacy policies. We do not store complete credit card numbers or bank account details on our systems.
5.3 Infrastructure Providers
NoBurn runs on third-party cloud infrastructure. While our infrastructure providers may have physical access to the servers where data is stored, access to your data is governed by our agreements with those providers and our own access controls.
6. Data We Do NOT Collect or Use
To be explicit about our data practices:
- We do not read, analyze, or mine the content of your LLM streams. Buffered stream data is treated as opaque binary data. We do not inspect prompts, completions, or any content flowing through the proxy.
- We do not train machine learning models on your data. Your stream content is never used for model training, fine-tuning, or any form of AI development.
- We do not sell your data. We do not sell, rent, or trade your personal information or stream content to third parties for marketing or any other purpose.
- We do not profile you based on stream content. We do not build behavioral profiles or advertising profiles from your LLM usage.
7. Cookies and Tracking
NoBurn uses only strictly necessary, operational cookies and similar technologies. Specifically:
- Authentication Cookies: Session cookies to keep you signed in to the NoBurn dashboard.
- Security Cookies: CSRF tokens and similar mechanisms to protect against cross-site attacks.
We do not use third-party advertising trackers, social media pixels, or cross-site tracking cookies. We do not participate in ad networks or retargeting programs.
If we introduce optional analytics cookies in the future, we will update this policy and provide a clear opt-in mechanism.
8. Children's Privacy
NoBurn is a business-to-business (B2B) infrastructure service and is not directed at children. We do not knowingly collect personal information from anyone under the age of 16 (or 13 in jurisdictions where that is the applicable threshold). If we become aware that we have collected personal data from a child without parental consent, we will take steps to delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@noburn.ai.
9. International Data Transfers
NoBurn is operated from the United States. If you are accessing the service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States or other countries where our infrastructure providers operate.
Where we transfer personal data from the European Economic Area (EEA), United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of data protection, we rely on appropriate legal mechanisms such as Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms.
10. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
10.1 Access and Portability
You have the right to request a copy of the personal data we hold about you. We will provide this in a commonly used, machine-readable format where technically feasible.
10.2 Correction
You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.
10.3 Deletion
You have the right to request deletion of your personal data. You can delete your account at any time, which will trigger removal of your data as described in Section 3.2. You can also delete buffered stream data at any time via the API or by letting the TTL expire.
10.4 Restriction and Objection
You may have the right to restrict or object to certain processing of your personal data. If you object to processing that is necessary for providing the service, you may need to discontinue use of NoBurn.
10.5 Withdrawal of Consent
Where processing is based on consent, you have the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
10.6 Exercising Your Rights
To exercise any of these rights, please contact us at privacy@noburn.ai. We will respond to verified requests within 30 days (or sooner where required by applicable law). We may need to verify your identity before fulfilling a request.
11. GDPR Provisions
If you are located in the EEA, UK, or Switzerland, the following additional provisions apply:
- Legal Bases for Processing: We process your personal data on the following legal bases: (a) performance of our contract with you (to provide the NoBurn service), (b) our legitimate interests (service improvement, security, fraud prevention), and (c) compliance with legal obligations.
- Data Controller: NoBurn is the data controller for personal data collected through the service. For stream content that you transmit through NoBurn to upstream LLM providers, NoBurn acts as a data processor on your behalf.
- Supervisory Authority: You have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal data violates applicable law.
- Data Protection Officer: For GDPR-related inquiries, contact us at privacy@noburn.ai.
12. CCPA Provisions
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, our business purposes for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of personal information we have collected, subject to certain exceptions.
- Right to Opt-Out of Sale: We do not sell personal information. As such, there is no need to opt out of the sale of personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise these rights, contact privacy@noburn.ai or visit our dashboard to manage your data.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, the service, or applicable laws. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Post a notice on the NoBurn dashboard or website
- Send an email notification to registered users for significant changes
We encourage you to review this Privacy Policy periodically. Your continued use of the service after any changes constitutes acceptance of the updated policy.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at privacy@noburn.ai or visit noburn.ai.
We will make every effort to respond to inquiries within a reasonable timeframe and no later than 30 days from receipt.
This Privacy Policy is effective as of March 12, 2026. NoBurn is currently in beta, and this policy may be updated as the service evolves toward general availability.