Sluice is a marketplace, not an advertising business. We collect the minimum required to run an account and an order book, we are direct about where it goes, and we never treat your information as a product to be sold.
This policy explains what information Sluice collects when you use the website and the API, why we collect it, how long we keep it, and the choices you have over it. It is written to be read, not to be survived. Where a section simplifies a legal concept for clarity, the intent is always to describe our actual practice rather than to grant ourselves room we do not need.
By creating an account or sending a request to the API, you agree to the handling described here. If you do not agree, the right move is simply not to use the service, and you can reach us with any concern before you decide.
We group what we hold into four plain categories, each tied to a function you can see in the product.
When you sign in, we receive the identifier you choose to authenticate with, an email address or a connected wallet. We use it to log you in, to recover access, and to attach your balance and history to the right account. We do not require your legal name to browse, read the documentation, or buy credits.
To run an order book we record your credit balance, the offers you post, and the trades you fill. This ledger is what lets the market settle correctly and lets you audit your own spend down to the credit.
When you top up by card or by crypto, we keep a record of the transaction for accounting and dispute handling. Card details themselves are processed by our payment partner. We never receive or store your full card number.
If you complete an identity check to sell or send credits, we store the outcome as a status flag on your account. We do not retain the underlying documents you submitted to the verification provider.
Every use maps back to running the service. We use your data to authenticate you, to operate the marketplace and settle trades, to process payments and prevent fraud, to meet legal and accounting obligations, and to respond when you contact us. We do not build advertising profiles, and we do not make automated decisions that produce legal effects about you without a human in the loop.
When you run a model, the prompt and its output are passed to the provider that serves the response, because that is how the result is produced. Sluice does not sell your prompts, and we do not mine them to train a profile of you. For sensitive work, privacy preserving models are available where the provider supports zero retention, so the content is processed to generate your answer and is not kept afterward.
Sluice uses only what is necessary to keep you signed in and to remember light preferences on the device in front of you, such as an API key you chose to save locally in the Studio. There is no third party advertising network embedded in the site watching where you go next, and we do not sell or share a cookie based identity with data brokers.
We share data only with the service providers required to operate, and only the slice each one needs. That includes a payment processor for card charges, an identity verification provider when you choose to verify, the model providers that serve your inference, and the infrastructure that hosts the application. Each is bound to use the data solely to perform its function for Sluice. We may also disclose information where the law genuinely requires it, and we will resist requests that are overbroad.
We keep account and ledger records for as long as your account is active, and for a reasonable period afterward where accounting, tax, or dispute obligations require it. Verification status is kept while it remains relevant to your ability to transact. When a record is no longer needed for any of these purposes, it is removed on our normal cycle.
We protect data in transit and at rest, scope API keys to the account that created them, and design payment and deposit flows to be idempotent so a single event cannot be charged or credited twice. No system is perfectly secure, and we will not pretend otherwise, but we treat the integrity of balances and identities as the part of the product that has to be right.
Sluice may be used from many regions, and by using it you understand your data may be processed in the locations where our providers operate. The service is not directed to children, and we do not knowingly collect information from anyone under the age required to form a binding agreement in their jurisdiction.
As the product grows, this policy may be updated. When a change is material, it will be visible rather than buried, and the date at the top will move. Continuing to use Sluice after an update means you accept the revised version.
Questions about your data, a correction, or a deletion request go through the contact page and reach a person, not a queue. Sluice is built by Thoth, in the open.
This page is written for clarity and transparency. It summarises our practice and is not a substitute for formal legal advice.