llmax.ai
← Back
Legal

Privacy Policy

Last updated: August 10, 2026
Preliminary version published during the pre-launch phase; it may be updated before the service opens.

1. Data controller

The data controller is:

  • Name: HEGUZ CAPITAL, S.L., trading as llmax.ai ("we", "us" or "our").
  • Registered office: Calle Lepant 270, 08013 Barcelona, Spain
  • Email: legal@llmax.ai

We have not appointed a Data Protection Officer: the processing we carry out does not meet the criteria of Art. 37 GDPR. Privacy matters are handled at the address above.

2. Our principle

llmax.ai is built on one idea: process as little data as possible. We do not log your prompts or the model's responses, we do not use your content to train anything, and all compute happens inside the European Union.

3. What data we process

During pre-launch:

  • Email address: this site no longer collects addresses. Discount codes are issued one by one by us, from our internal admin panel, and sent only to people who have authorised us to write to them. We store the address to send you the code and to notify you on the service's launch day. You can unsubscribe or request its deletion at any time.
  • Name: only if we have it, and only so the email can address you by name. It is optional and it is never required.
  • Delivery data: the date of the last email sent to you and the identifier the email provider returns, so we can tell whether the code reached you and avoid sending it twice.
  • Technical data of older sign-ups: records created before August 2026, when this site still had a sign-up form, also hold the IP address, the country resolved from it and the browser's user agent of that request. They were used to detect automated or fraudulent sign-ups. We no longer collect any of the three, and they are erased together with the record they belong to.

Once the service is live:

  • Inference content (prompts and responses): never logged or stored. It lives in your session — the client, agent or app you use.
  • Usage metadata: to bill and to enforce the fair-use limits we do record, per API key, the volume consumed (tokens and requests) and its timestamp. This metadata never includes the content of your prompts or the model's answers.
  • Cluster technical metrics: aggregated operational signals (e.g. tokens/s, requests per minute), with no user content, to keep and secure the infrastructure.
  • Account and billing data: strictly what is needed to manage your subscription and meet tax obligations. If you sign in with GitHub, we receive the identifier and email address of that account.

4. Purposes and legal bases

  • Sending the discount code and launch notice: your consent and/or pre-contractual measures at your request (Art. 6(1)(a) and 6(1)(b) GDPR). We only write to an address whose owner has authorised us to do so, and every one of those emails carries a link to opt out of the launch notice.
  • IP address, country and user agent of older sign-ups: legitimate interest in preventing automated and fraudulent sign-ups through the form this site used to have (Art. 6(1)(f) GDPR). The form is gone and so is the collection; what remains is historical.
  • Usage metadata: performance of the contract — billing what you consume and applying the agreed limits (Art. 6(1)(b) GDPR).
  • Service technical metrics: legitimate interest in maintaining and securing the infrastructure (Art. 6(1)(f) GDPR).
  • Account and billing: performance of the contract and compliance with legal obligations (Art. 6(1)(b) and 6(1)(c) GDPR).

5. Retention periods

  • Pre-launch email and name: kept until the service launches (or until you unsubscribe or request their deletion).
  • IP address, country and user agent of older sign-ups: deleted together with the record they belong to. If you ask us to erase your address, the whole record goes, this technical data included.
  • Usage metadata: kept while the subscription is active and for the period needed to settle and justify the corresponding invoices.
  • Technical metrics: aggregated and kept only as long as needed to operate the service.
  • Billing data: for the periods required by tax and commercial law.

6. Where your data is processed

Inference runs on dedicated servers we rent inside the European Union and operate ourselves. We install and run the whole stack; the providers supply the machines and the datacenters and never access your prompts or the model's responses. They are listed as sub-processors in our DPA. We use more than one EU location and may add or move between them as capacity requires; what never changes is that inference stays within the Union. Your prompts and the model's answers are not sent to any third party, inside or outside the EU: that is the core of this service and it does not depend on anyone else's policy.

Some of the auxiliary providers listed in section 8 are companies based in the United States (website infrastructure, and sign-in with GitHub if you choose it). Where a transfer to a third country occurs, it is covered by the safeguards of Chapter V of the GDPR — standard contractual clauses and, where applicable, the EU–US Data Privacy Framework. This never affects your inference content, which does not leave our infrastructure.

7. We don't train on your data

Your content, your prompts and your code are never used to train, fine-tune or evaluate models. Ever.

8. Processors and third parties

These are every provider that may handle personal data on our behalf, what they do and where they are. All of them act as processors under a contract compliant with Art. 28 GDPR, except where noted otherwise:

  • Hosting providers (several, all established in the European Union) — the dedicated servers that run the inference stack. They supply and maintain the machines; they do not access your prompts or the model's responses, which are never written to disk. We will tell you which providers we currently use if you write to legal@llmax.ai.
  • Cloudflare, Inc. (United States, with infrastructure in the EU) — hosting of the website, DNS and the database of pre-launch sign-ups.
  • Scaleway SAS (France) — delivery of transactional email: the message with your discount code and the account emails. Processing takes place in its Paris region.
  • Creem — payment processing. Creem acts as merchant of record: it is the seller in the transaction and therefore an independent controller of your billing data, not our processor. Its own privacy policy governs that processing.
  • GitHub, Inc. (United States, Microsoft group) — only if you choose to sign in with GitHub, to verify your identity. If you sign in by email, GitHub receives nothing.

We do not sell or assign your data to anyone, and no provider on this list has access to your prompts or the model's answers.

If you use the service as a company and process personal data through it, we act as your processor. Our Data Processing Agreement governs that relationship and lists the sub-processors involved.

9. Cookies and local storage

This site uses no tracking or advertising cookies. We only use the browser's local storage (localStorage) to remember your theme preference. You can clear it from your browser at any time. The dashboard (dashboard.llmax.ai) sets only a strictly necessary session cookie to keep you signed in — being essential to the service you request, it requires no consent; it is removed on sign-out and expires after 30 days.

10. Security

All communication with the site and the API is encrypted with TLS. Once the service is live, inference is processed in memory and discarded — no prompts or responses are persisted — and we apply access controls and isolation across the infrastructure. If you find a vulnerability, email contact@llmax.ai for responsible disclosure.

11. Your rights

You may exercise your rights of access, rectification, erasure, objection, restriction and portability by writing to legal@llmax.ai. You can unsubscribe from the launch notice at any time from the email itself or by contacting us, and request deletion of your address. You have the right to lodge a complaint with the Spanish Data Protection Agency (aepd.es) or your competent supervisory authority.

12. Minors

The service is not directed to minors and we do not knowingly collect their data.

13. Changes to this policy

We may update this policy to reflect legal or service changes. The current version will be published on this page with its update date.

14. Contact

For any privacy or legal matter, email legal@llmax.ai.

llmax.ai Made in the EU · by developers for developers · © 2026 Privacy Policy Terms of Use DPA