Privacy

How we collect, use, protect, and retain information across the Varsten website and service.

Last updated July 21, 2026

01

Scope and who we are

This policy describes how Varsten Systems, Inc. handles personal information through varsten.ai, the Varsten application, customer communications, and related services. A signed agreement or data processing addendum controls if it conflicts with this policy.

02

Information we collect

We collect information provided directly by users and information produced when the service operates.

  • Account and contact details, including name, work email, company, and authentication identifiers.
  • Commercial and support communications, form submissions, and procurement information.
  • Service metadata such as provider, model, token counts, timestamps, workload labels, cost, routing decisions, and diagnostic events.
  • Website and device information such as page path, referrer, campaign parameters, browser details, IP-derived security signals, and anonymous analytics identifiers.
  • Billing records supplied by payment providers. Varsten does not directly store complete payment-card numbers.

03

AI requests and credentials

The savings ledger is metadata-oriented; prompt and completion text are not its default record. Inline integrations necessarily process request and response content in transit. Content-backed features, including semantic caching or approved replay, may retain content only when configured for that purpose and subject to applicable retention controls.

Varsten project keys and connected provider credentials are secrets. They are not analytics properties and must not be submitted through forms, URLs, or support messages.

04

How we use information

  • Provide, secure, troubleshoot, and improve the service.
  • Authenticate users, enforce tenant boundaries, and prevent abuse.
  • Calculate spend, evaluate optimization opportunities, and produce savings evidence.
  • Respond to inquiries, deliver requested communications, and manage commercial relationships.
  • Meet legal obligations and enforce agreements.

05

Sharing and subprocessors

We share information with infrastructure, authentication, communications, analytics, payment, monitoring, and model-provider services only as needed to operate Varsten. We may also disclose information when required by law, to protect rights or safety, in a corporate transaction, or at a customer’s direction.

Varsten does not sell personal information or share it for cross-context behavioral advertising.

06

Retention and deletion

We retain information for the period needed to provide the service, maintain security and financial records, resolve disputes, and meet legal obligations. Retention can vary by data class and contract. Customers with specific requirements should agree on them before sending production traffic. Backup copies may persist for a limited period after deletion.

07

Security and international processing

We use administrative, technical, and organizational measures intended to protect information. No system is completely secure. Varsten and its service providers may process information in the United States and other locations where they operate, subject to applicable contractual and legal safeguards.

08

Your choices and rights

Depending on location, individuals may have rights to access, correct, delete, restrict, object to, or export personal information, and to withdraw consent where consent is the basis for processing. We may need to verify identity and may retain information where legally permitted or required.

09

Children

Varsten is a business service and is not directed to children under 13. We do not knowingly collect personal information from children through the service.

10

Changes and contact

We may update this policy as the service and legal requirements change. The date above identifies the current version. For privacy requests or questions, contact contact@varsten.ai.