Legal

Privacy Policy

LatentForce Intelligence Private Limited ("LatentForce", "we", "us") provides LatentGraph, a context graph layer for codebases. This Privacy Policy explains what data we collect, how we use it, and your rights. If you are an Enterprise customer with an executed Data Processing Addendum (DPA), the DPA controls in the event of any conflict.

Effective 01/03/2026

§1Scope

This policy covers personal data we process when you:

  • Visit our website (www.latentforce.ai)
  • Create or use a LatentGraph account
  • Interact with our support, sales, or marketing
  • Use our CLI, MCP server, or APIs

It does not cover the practices of third-party websites that link to or from us.

§2Data We Collect

CategoryExamplesSource
Account dataname, email, organisation, password hash, roleYou
Billing databilling address, last 4 digits of card, GSTIN (India only), invoice historyYou, via our payment processor
Workspace datarepository names, file paths, commit metadata, generated graph artifactsYou / your repo
Customer Contentsource code, comments, configuration files, annotationsYou / your repo
Usage datafeatures used, API calls, error logs, performance metricsAutomatic
Device dataIP address, browser/CLI version, OSAutomatic
Communicationssupport tickets, sales emails, feedbackYou

We do not knowingly collect personal data from children under 16.

§3How We Use Data

We process the data above to:

  • Provide and operate the Service (generate and sync graphs, serve MCP requests)
  • Authenticate users and prevent fraud or abuse
  • Bill you and prevent payment fraud (via our payment processors)
  • Provide support
  • Improve product reliability and performance (aggregate analytics only)
  • Send service announcements and, with your consent, product updates
  • Comply with legal obligations

Our legal bases under GDPR are: (a) performance of the contract with you, (b) our legitimate interests in operating and securing the Service, (c) your consent where required (e.g., marketing emails), and (d) compliance with legal obligations.

§4AI Models and Training

This is the question that matters most for an AI tool that reads your code, so we are explicit:

We do not use Customer Content to train, fine-tune, or evaluate any AI models, and we do not permit our LLM providers to do so.
  • LLM inference for graph generation runs through hosted platforms — currently AWS Bedrock, Google Cloud (Vertex AI), and OpenRouter. Where supported by the underlying provider, we configure these platforms for zero retention of prompts and completions. For OpenRouter, retention depends on which underlying model handles a given request; we select routes that support zero retention where feasible. Our current list is published on our Subprocessors page.
  • For Enterprise customers, additional controls are available, including dedicated isolation and bring-your-own-key (BYOK) for LLM access.
  • We may use aggregated, fully anonymised metrics (e.g., “average graph size”) to improve the product. We never use these aggregates to reconstruct or expose any individual customer's content.

If we ever change this posture, we will notify you by email at least 30 days before the change takes effect, and your prior content will not be retroactively used.

§5Subprocessors

We rely on a limited set of vetted subprocessors to operate the Service — currently cloud infrastructure, LLM inference providers, and payment processing. The current list, what each one processes, and the location of processing is maintained at:

latentforce.ai/legal/subprocessors

You can subscribe to subprocessor change notifications from that page. We give at least 30 days' notice before adding a new subprocessor that processes Customer Content.

§6Sharing

We do not sell personal data, and we do not engage in cross-context behavioural advertising.

We share data only with:

  • Subprocessors acting on our behalf under written agreements (see Section 5)
  • Authorities, when required by valid legal process — we will challenge overbroad requests and notify you where lawful to do so
  • Successors, in the event of a merger, acquisition, or asset sale; the same protections continue to apply

§7Data Location and Transfers

LatentGraph runs on Amazon Web Services (AWS) inside our isolated VPC. Customer Content does not leave AWS. Enterprise customers may request a specific AWS region.

Where data is transferred out of the EEA, UK, or Switzerland, we rely on Standard Contractual Clauses (and the UK IDTA where applicable) and, where appropriate, additional safeguards such as encryption and access controls.

§8Retention

DataRetention
Account dataLife of account + 90 days after deletion
Customer Content (repos, graphs)Life of account; deleted within 30 days after account closure
Billing records7 years (tax/accounting requirements)
Usage logs13 months
Support tickets24 months

Backups are retained for an additional 35 days and then deleted on the next rotation.

§9Security

We maintain a written security program, including: TLS 1.3 in transit, AES-256 at rest, role-based access controls, audit logging, vendor reviews, and a defined incident response process. We will notify affected users of a confirmed personal data breach without undue delay and in accordance with applicable law.

§10Your Rights (GDPR, UK GDPR)

If you are in the EEA, UK, or Switzerland, you have the right to: access, rectify, erase, restrict processing, object, and port your personal data, and to withdraw consent at any time. To exercise any of these, email contact@latentforce.ai. We will respond within 30 days. You also have the right to complain to your supervisory authority.

§11Your Rights (India — DPDP Act, 2023)

If you are in India, you have the right to: access a summary of personal data we process, request correction, completion or update, request erasure (subject to legal retention), nominate another person to exercise your rights in case of death or incapacity, and grievance redressal. You may withdraw consent at any time where processing is based on consent. We act as a Data Fiduciary under the DPDP Act, 2023 for personal data we determine the purposes and means of processing.

To exercise these rights or raise a grievance, contact our Grievance Officer at contact@latentforce.ai. We will acknowledge within 48 hours and resolve within the timelines required by the DPDP Act and any rules issued thereunder. If the matter is not resolved to your satisfaction, you may approach the Data Protection Board of India.

§12Your Rights (US State Laws)

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, or another US state with a comprehensive privacy law, you have the right to know what we collect, request deletion or correction, opt out of "sale" (we do not sell) and targeted advertising (we do not engage in cross-context behavioural advertising), and to non-discrimination for exercising your rights. To exercise these rights, email contact@latentforce.ai.

We honor the Global Privacy Control (GPC) signal as an opt-out signal.

§13Cookies and Tracking

We use a small number of cookies for authentication, security, and product analytics. We do not use advertising cookies. Details and controls are available on our cookie banner and at contact@latentforce.ai.

§14Changes

We may update this Privacy Policy from time to time. For material changes, we will notify active customers by email at least 30 days before the change takes effect, and update the "Effective" date above.

§15Contact

LatentForce Intelligence Private Limited
A company incorporated under the Companies Act, 2013.
Registered office: 3rd Floor, Sree Gururaya Mansion, 8th Main, JP Nagar III Phase, Bangalore South, Bangalore - 560078, Karnataka
Privacy / Data Protection: contact@latentforce.ai
Grievance Officer (DPDP Act, 2023): contact@latentforce.ai

If you are in the EU and require an EU representative under Article 27 of the GDPR, please contact contact@latentforce.ai and we will direct you to our appointed representative.