Privacy Policy
LatentForce Intelligence Private Limited ("LatentForce", "we", "us") provides LatentGraph, a context graph layer for codebases. This Privacy Policy explains what data we collect, how we use it, and your rights. If you are an Enterprise customer with an executed Data Processing Addendum (DPA), the DPA controls in the event of any conflict.
§1Scope
This policy covers personal data we process when you:
- Visit our website (
www.latentforce.ai) - Create or use a LatentGraph account
- Interact with our support, sales, or marketing
- Use our CLI, MCP server, or APIs
It does not cover the practices of third-party websites that link to or from us.
§2Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account data | name, email, organisation, password hash, role | You |
| Billing data | billing address, last 4 digits of card, GSTIN (India only), invoice history | You, via our payment processor |
| Workspace data | repository names, file paths, commit metadata, generated graph artifacts | You / your repo |
| Customer Content | source code, comments, configuration files, annotations | You / your repo |
| Usage data | features used, API calls, error logs, performance metrics | Automatic |
| Device data | IP address, browser/CLI version, OS | Automatic |
| Communications | support tickets, sales emails, feedback | You |
We do not knowingly collect personal data from children under 16.
§3How We Use Data
We process the data above to:
- Provide and operate the Service (generate and sync graphs, serve MCP requests)
- Authenticate users and prevent fraud or abuse
- Bill you and prevent payment fraud (via our payment processors)
- Provide support
- Improve product reliability and performance (aggregate analytics only)
- Send service announcements and, with your consent, product updates
- Comply with legal obligations
Our legal bases under GDPR are: (a) performance of the contract with you, (b) our legitimate interests in operating and securing the Service, (c) your consent where required (e.g., marketing emails), and (d) compliance with legal obligations.
§4AI Models and Training
This is the question that matters most for an AI tool that reads your code, so we are explicit:
- LLM inference for graph generation runs through hosted platforms — currently AWS Bedrock, Google Cloud (Vertex AI), and OpenRouter. Where supported by the underlying provider, we configure these platforms for zero retention of prompts and completions. For OpenRouter, retention depends on which underlying model handles a given request; we select routes that support zero retention where feasible. Our current list is published on our Subprocessors page.
- For Enterprise customers, additional controls are available, including dedicated isolation and bring-your-own-key (BYOK) for LLM access.
- We may use aggregated, fully anonymised metrics (e.g., “average graph size”) to improve the product. We never use these aggregates to reconstruct or expose any individual customer's content.
If we ever change this posture, we will notify you by email at least 30 days before the change takes effect, and your prior content will not be retroactively used.
§5Subprocessors
We rely on a limited set of vetted subprocessors to operate the Service — currently cloud infrastructure, LLM inference providers, and payment processing. The current list, what each one processes, and the location of processing is maintained at:
latentforce.ai/legal/subprocessors
You can subscribe to subprocessor change notifications from that page. We give at least 30 days' notice before adding a new subprocessor that processes Customer Content.
§6Sharing
We do not sell personal data, and we do not engage in cross-context behavioural advertising.
We share data only with:
- Subprocessors acting on our behalf under written agreements (see Section 5)
- Authorities, when required by valid legal process — we will challenge overbroad requests and notify you where lawful to do so
- Successors, in the event of a merger, acquisition, or asset sale; the same protections continue to apply
§7Data Location and Transfers
LatentGraph runs on Amazon Web Services (AWS) inside our isolated VPC. Customer Content does not leave AWS. Enterprise customers may request a specific AWS region.
Where data is transferred out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (and the UK IDTA where applicable) and, where appropriate, additional safeguards such as encryption and access controls.
§8Retention
| Data | Retention |
|---|---|
| Account data | Life of account + 90 days after deletion |
| Customer Content (repos, graphs) | Life of account; deleted within 30 days after account closure |
| Billing records | 7 years (tax/accounting requirements) |
| Usage logs | 13 months |
| Support tickets | 24 months |
Backups are retained for an additional 35 days and then deleted on the next rotation.
§9Security
We maintain a written security program, including: TLS 1.3 in transit, AES-256 at rest, role-based access controls, audit logging, vendor reviews, and a defined incident response process. We will notify affected users of a confirmed personal data breach without undue delay and in accordance with applicable law.
§10Your Rights (GDPR, UK GDPR)
If you are in the EEA, UK, or Switzerland, you have the right to: access, rectify, erase, restrict processing, object, and port your personal data, and to withdraw consent at any time. To exercise any of these, email contact@latentforce.ai. We will respond within 30 days. You also have the right to complain to your supervisory authority.
§11Your Rights (India — DPDP Act, 2023)
If you are in India, you have the right to: access a summary of personal data we process, request correction, completion or update, request erasure (subject to legal retention), nominate another person to exercise your rights in case of death or incapacity, and grievance redressal. You may withdraw consent at any time where processing is based on consent. We act as a Data Fiduciary under the DPDP Act, 2023 for personal data we determine the purposes and means of processing.
To exercise these rights or raise a grievance, contact our Grievance Officer at contact@latentforce.ai. We will acknowledge within 48 hours and resolve within the timelines required by the DPDP Act and any rules issued thereunder. If the matter is not resolved to your satisfaction, you may approach the Data Protection Board of India.
§12Your Rights (US State Laws)
If you are a resident of California, Colorado, Connecticut, Virginia, Utah, or another US state with a comprehensive privacy law, you have the right to know what we collect, request deletion or correction, opt out of "sale" (we do not sell) and targeted advertising (we do not engage in cross-context behavioural advertising), and to non-discrimination for exercising your rights. To exercise these rights, email contact@latentforce.ai.
We honor the Global Privacy Control (GPC) signal as an opt-out signal.
§13Cookies and Tracking
We use a small number of cookies for authentication, security, and product analytics. We do not use advertising cookies. Details and controls are available on our cookie banner and at contact@latentforce.ai.
§14Changes
We may update this Privacy Policy from time to time. For material changes, we will notify active customers by email at least 30 days before the change takes effect, and update the "Effective" date above.
§15Contact
If you are in the EU and require an EU representative under Article 27 of the GDPR, please contact contact@latentforce.ai and we will direct you to our appointed representative.