Ulam Alloy — Privacy Policy
Version: 1.0
Last updated: 26 June 2026
Product: Ulam Alloy — AI chat interface and API for AI/model routing
Controller / Operator: Yotta Content LTD, a private limited company registered in the United Kingdom under company number 12683376
Registered office: 71–75 Shelton Street, London, Greater London, United Kingdom, WC2H 9JQ
Product status: Experimental product — use at your own risk
Privacy contact: privacy@ulam.ai
Subprocessor, partner and external model provider list: https://chat.ulam.ai/subprocessors
1. Overview
This Privacy Policy explains how Yotta Content LTD collects, uses, stores, shares, and protects personal data in connection with Ulam Alloy.
Ulam Alloy is an experimental AI chat interface and API for AI/model routing. When you use Ulam Alloy, the prompts, files, messages, API requests, responses, outputs, and related data you submit may be processed by Yotta and may also be shared with partners, infrastructure providers, routing providers, and external AI/model providers.
API gateway diagnostic payload logs, where kept by Yotta, are intended to be retained for up to one month / 30 days. Web chat history, uploaded files, account records, usage records, billing records, security logs, backups, and external-provider records may be retained for longer as described below.
Ulam Alloy is experimental and not intended for sensitive, confidential, regulated, production, or high-risk data by default. Do not submit data to Ulam Alloy if the retention or onward sharing described in this policy is not acceptable.
2. Who we are
Ulam Alloy is operated by:
Yotta Content LTD
Company number: 12683376
Registered office: 71–75 Shelton Street, London, Greater London, United Kingdom, WC2H 9JQ
Privacy contact: privacy@ulam.ai
For direct users of the Ulam Alloy web interface, Yotta generally acts as Controller for personal data processed to provide and operate Ulam Alloy.
For business and API customers that submit personal data on behalf of their own users, Yotta may act as Processor under a written Data Processing Agreement, except where Yotta acts as independent Controller for account administration, billing, security, abuse prevention, legal compliance, analytics, product improvement, and other purposes described in this policy.
3. What Ulam Alloy does
Ulam Alloy allows users and developers to submit prompts, messages, files, code, documents, API payloads, and related data to AI systems and external model providers through a web interface and API.
Ulam Alloy may:
- receive prompts, messages, files, and API requests;
- route requests to external AI/model providers and partners;
- return generated outputs;
- store API gateway diagnostic payload logs, where kept by Yotta, for up to one month / 30 days;
- store web chat history, uploaded files, account records, usage records, billing records, security logs, backups, and external-provider records for longer where needed;
- monitor reliability, errors, usage, and safety;
- review usage for abuse prevention, security, debugging, and support;
- evaluate and improve the product.
4. Personal data we collect
Depending on how you use Ulam Alloy, we may process the following categories of personal data.
| Category | Examples |
|---|---|
| Account data | Name, email address, organisation name, workspace name, user ID, role, settings, plan |
| Authentication data | Login details, API keys, access tokens, workspace IDs, project IDs, account permissions |
| Prompt and input data | Prompts, chat messages, system messages, uploaded files, pasted text, images, documents, code, structured JSON, tool calls, embeddings, vector data, and API request payloads |
| Output data | Model responses, generated text, summaries, classifications, transformed content, code, embeddings, tool outputs, and other generated or returned data |
| API metadata | Timestamp, request ID, model/provider selected, route selected, latency, token usage, status code, error details, retry/fallback details, rate-limit information |
| Usage data | Pages visited, features used, settings, feedback, ratings, experiments, logs, session information |
| Device and technical data | IP address, device type, browser type, operating system, approximate location from IP, diagnostic data |
| Support data | Support messages, screenshots, bug reports, attachments, issue history, contact details |
| Security data | IP address, device/browser metadata, suspicious activity signals, audit logs, abuse-prevention records |
| Billing data | Plan, usage, invoices, payment references, billing contact, tax information where applicable |
| Communications data | Emails, notices, service messages, product updates, survey responses, marketing preferences |
You control what you submit in prompts, files, and API requests. Ulam Alloy does not require sensitive personal data for ordinary use.
5. Data you should not submit
Unless Yotta has expressly agreed appropriate safeguards in writing, you must not submit:
- special category personal data;
- health or medical data;
- biometric data used for identification;
- genetic data;
- children's personal data;
- criminal offence data;
- payment card data;
- bank account credentials;
- passwords, private keys, tokens, or production secrets;
- government identifiers;
- trade secrets;
- confidential legal material;
- export-controlled data;
- regulated financial information;
- information subject to professional secrecy or statutory confidentiality;
- data requiring zero retention or provider-specific restrictions.
If you submit such data, you are responsible for ensuring that you have the necessary lawful basis, notices, consents, authorisations, safeguards, and risk assessments.
6. How we use personal data
We may use personal data for the purposes below.
| Purpose | Examples | Typical lawful basis for direct users |
|---|---|---|
| Provide Ulam Alloy | Process prompts, API requests, files, and outputs; maintain sessions; authenticate users; return model responses | Contract; legitimate interests where no contract applies |
| Route requests to external models | Send prompts, files, outputs, and metadata to external model providers and partners | Contract; legitimate interests; consent where required |
| Operate the API | Manage API keys, usage, rate limits, integrations, developer tools, logs, and billing | Contract; legitimate interests |
| Retain request and chat data | Store API gateway diagnostic payload logs, where kept by Yotta, for up to one month / 30 days; store web chat history, uploaded files, account records, usage records, billing records, security logs, backups, and external-provider records for longer where needed | Contract; legitimate interests; consent where required |
| Debug and support | Investigate errors, support requests, abuse reports, and reliability issues | Contract; legitimate interests |
| Product experimentation and improvement | Test features, evaluate model/provider performance, compare routes, improve user experience | Legitimate interests; consent where required |
| Safety and abuse prevention | Detect misuse, malware, spam, fraud, prompt injection, policy violations, harmful use, or security threats | Legitimate interests; legal obligation where applicable |
| Security | Protect accounts, API keys, systems, partners, users, and infrastructure | Legitimate interests; legal obligation where applicable |
| Billing and administration | Process payments, invoices, taxes, accounting records, customer administration | Contract; legal obligation |
| Legal compliance | Respond to legal requests, enforce terms, preserve records, establish or defend claims | Legal obligation; legitimate interests |
| Communications | Send service notices, security alerts, account updates, support replies, and permitted marketing | Contract; legitimate interests; consent where required |
For API and business customers, the customer is responsible for identifying and documenting the lawful basis for personal data submitted through Ulam Alloy. Where Yotta acts as Processor, Yotta processes Customer Personal Data in accordance with the applicable Data Processing Agreement.
7. Prompt, file, request, and response handling
7.1 Retention
API gateway diagnostic payload logs, where kept by Yotta, are intended to be retained for up to one month / 30 days. Web chat history, uploaded files, account records, usage records, billing records, security logs, support records, legal records, backups, and external-provider records may be retained for longer.
This retention may be used for:
- service operation;
- debugging;
- reliability monitoring;
- user support;
- safety review;
- abuse prevention;
- fraud prevention;
- security monitoring;
- experimentation;
- product improvement;
- model/provider evaluation;
- billing and usage verification;
- investigation of errors or policy violations.
7.2 Deletion after retention period
After the intended one-month API gateway diagnostic payload retention period, we aim to delete or anonymise those diagnostic payload logs from active systems, unless longer retention is necessary for legal, security, fraud prevention, accounting, dispute resolution, backup, compliance, or other legitimate purposes. Web chat history and uploaded files may remain available in the user account until deleted by the user, removed by Yotta, or the account is closed, subject to product capabilities and legal retention needs.
7.3 Backups
Data may remain in backups, snapshots, disaster recovery systems, or archival copies for a limited period after deletion from active systems. Where immediate deletion from backups is not practical, the data will be protected from ordinary use and deleted or overwritten according to the normal backup lifecycle. Backups are protected using the security measures available for the relevant infrastructure; Yotta does not promise a specific backup encryption architecture unless expressly agreed in writing.
7.4 Metadata
Operational metadata, audit logs, security logs, usage records, billing records, and accounting records may be retained for longer than one month where necessary for security, service operation, legal compliance, dispute resolution, tax, accounting, billing, or fraud prevention.
7.5 Not zero data retention
Ulam Alloy is not zero-data-retention by default. Do not use Ulam Alloy for data or workloads requiring strict zero retention unless Yotta has separately agreed that configuration in writing.
8. Sharing with partners and external model providers
We may share personal data, prompts, files, request data, output data, and metadata with partners and external providers where needed to provide, operate, test, secure, debug, support, evaluate, or improve Ulam Alloy.
8.1 Categories of recipients
| Recipient category | Purpose |
|---|---|
| External AI/model providers | Generate responses, process prompts, run inference, create embeddings, classify, transform, moderate, or evaluate content |
| Routing partners | Select models, manage fallbacks, monitor latency and availability, support routing logic |
| Cloud and hosting providers | Host the web app, API, databases, logs, storage, networking, and infrastructure |
| Observability and logging providers | Monitor reliability, errors, latency, usage, abuse, and security events |
| Analytics providers | Understand product usage, improve features, run experiments, subject to consent requirements where applicable |
| Support and communication providers | Provide customer support, send notices, manage support tickets and user communications |
| Payment and billing providers | Process payments, subscriptions, invoices, credits, taxes, and billing records |
| Security providers | Detect, prevent, and investigate abuse, fraud, security incidents, and misuse |
| Professional advisers | Legal, accounting, compliance, insurance, and audit support |
| Public authorities and courts | Where required by law or necessary to protect rights, safety, security, or legal interests |
Current provider list: https://chat.ulam.ai/subprocessors
8.2 External provider terms and policies
External model providers and partners may have their own terms, privacy policies, retention rules, training rules, security controls, and geographic processing locations.
Ulam Alloy does not currently make a blanket guarantee that every external model provider or partner:
- has zero data retention;
- will not log prompts or outputs;
- will not use submitted data for abuse monitoring, quality review, product improvement, model improvement, or training;
- processes data only in the United Kingdom or European Economic Area;
- is suitable for sensitive, confidential, regulated, or production workloads.
Users and customers should not submit data to Ulam Alloy unless this onward sharing is acceptable.
9. Training, model improvement, and experimentation
Ulam Alloy is experimental and may use prompt data, output data, metadata, feedback, ratings, logs, and support information to test, debug, evaluate, improve, and develop the product.
Yotta does not provide a universal no-training or no-improvement commitment covering all partners and external model providers. External providers may process submitted data under their own terms and policies.
Where legally required, Yotta will rely on an appropriate lawful basis or obtain consent before using personal data for optional purposes not necessary to provide, secure, or support the service.
Do not submit personal data, confidential information, or proprietary datasets where product improvement, evaluation, or onward sharing is not acceptable.
10. International transfers
Yotta is established in the United Kingdom. Personal data may be processed in the United Kingdom and may also be transferred to, accessed from, or processed in other countries where Ulam Alloy's partners, external model providers, cloud providers, support providers, or other vendors operate.
Where required, we use appropriate transfer mechanisms, such as:
- adequacy regulations or adequacy decisions;
- the UK International Data Transfer Agreement;
- the UK Addendum to the EU Standard Contractual Clauses;
- the European Commission Standard Contractual Clauses;
- another lawful transfer mechanism under applicable law.
Business and API customers are responsible for ensuring that their use of Ulam Alloy, including routing to external model providers and onward transfers, is lawful for the data, users, and jurisdictions involved.
11. Cookies, analytics, and similar technologies
Ulam Alloy may use cookies, local storage, pixels, SDKs, logs, and similar technologies to:
- keep users signed in;
- remember settings;
- secure accounts;
- prevent fraud and abuse;
- measure usage;
- debug errors;
- improve the product;
- support billing and analytics.
Where required by law, we will request consent for non-essential cookies or similar technologies.
Ulam Alloy currently uses essential cookies, local storage, and similar technologies for login, session management, security, preferences, abuse prevention, and service operation. We do not currently use advertising cookies in the Ulam Alloy product. If we add non-essential analytics, advertising, or similar tracking, we will update this policy and, where required, request consent or provide a preference mechanism.
12. Security
We use commercially reasonable technical and organisational measures designed to protect personal data.
Measures may include, as applicable:
- HTTPS/TLS for web and API traffic;
- account authentication;
- API keys and access controls;
- internal least-privilege access;
- logging and monitoring;
- abuse prevention;
- incident response processes;
- confidentiality obligations for personnel and contractors;
- vendor management;
- retention controls.
Because Ulam Alloy is experimental, you should not assume enterprise-grade security certifications, regulated-industry compliance, or dedicated infrastructure unless Yotta expressly confirms this in writing.
13. Data retention table
| Data type | Default retention | Notes |
|---|---|---|
| API gateway diagnostic payload logs | Intended up to 1 month / 30 days where kept by Yotta | Includes request/response payload excerpts or bodies only where logged for operation, support, debugging, safety, or abuse prevention |
| Web chat conversations | Account life or until deleted, subject to product capabilities and legal/security needs | Stored by the chat application so users can view conversation history; may be shared with partners and external models when generating responses |
| Uploaded files | Account life or until deleted, subject to product capabilities and legal/security needs | May remain in chat storage and backups unless deleted earlier or retained longer for support, abuse, legal, or security reasons |
| Responses and outputs | Account life or until deleted for web chat; intended up to 1 month / 30 days for API gateway diagnostic payload logs where kept by Yotta | External model providers may have separate retention rules |
| Request metadata | May be retained longer | Includes timestamps, model/provider, latency, token usage, status codes, errors, billing data |
| Security logs | May be retained longer | Used for abuse prevention, incident response, fraud detection, and platform security |
| Account data | Account life plus reasonable period | Needed for login, administration, support, compliance, and records |
| Billing and accounting data | As legally required | May be retained for tax, accounting, audit, dispute, and legal purposes |
| Support communications | As needed for support and records | May include attachments, screenshots, and diagnostic information |
| Backups | Deleted or overwritten on backup lifecycle | Data may remain temporarily beyond active-system deletion |
14. Your rights
Depending on your location and applicable law, you may have rights to:
- access your personal data;
- correct inaccurate personal data;
- request deletion of personal data;
- restrict processing;
- object to certain processing;
- receive personal data in a portable format;
- withdraw consent where processing is based on consent;
- object to direct marketing;
- not be subject to certain solely automated decisions with legal or similarly significant effects;
- complain to a supervisory authority.
To exercise rights, contact: privacy@ulam.ai.
We may need to verify your identity or authority before responding. Some data may be retained where necessary for legal, security, fraud prevention, accounting, dispute resolution, or compliance purposes.
If your personal data was submitted by an API or business customer, we may refer your request to that customer unless legally required to respond directly.
15. Complaints
If you are in the United Kingdom, you may complain to the UK Information Commissioner's Office.
If you are in the European Economic Area, you may complain to your local data protection supervisory authority.
We encourage you to contact us first at privacy@ulam.ai so we can try to resolve your concern.
16. Children
Ulam Alloy is not intended for children. Users must not submit children's personal data unless they have lawful authority to do so and appropriate safeguards have been agreed with Yotta in writing.
Where required by law, users must be at least the applicable minimum age for using online services in their jurisdiction.
17. Automated decision-making and AI outputs
Ulam Alloy generates AI outputs in response to prompts and API requests. Outputs may be inaccurate, biased, incomplete, outdated, offensive, unsafe, or unsuitable.
Yotta does not intend Ulam Alloy outputs to be used as the sole basis for decisions that produce legal or similarly significant effects for individuals.
Customers and users are responsible for human review, validation, explainability, fairness assessments, recordkeeping, and compliance where outputs are used in consequential contexts.
18. API and business customer notice
If you use the Ulam Alloy API or business workspace to process personal data on behalf of others, you are responsible for:
- providing your own privacy notice;
- establishing a lawful basis;
- obtaining consents where required;
- disclosing that data may be shared with partners and external model providers;
- disclosing the intended one-month / 30-day API gateway diagnostic payload retention period and the fact that web chat history, uploaded files, account records, usage records, billing records, security logs, backups, and external-provider records may be retained for longer;
- responding to data subject requests;
- assessing international transfers;
- avoiding restricted data unless separately agreed;
- entering into a Data Processing Agreement with Yotta before production use.
Suggested end-user notice:
This AI feature is powered by Ulam Alloy, operated by Yotta Content LTD. Prompts, files, responses, and related data may be retained by Yotta and may be shared with partners and external AI/model providers. API gateway diagnostic payload logs, where kept by Yotta, are intended to be retained for up to one month, while web chat history, uploaded files, account records, usage records, billing records, security logs, backups, and external-provider records may be retained for longer. Do not enter sensitive or confidential information. AI outputs may be inaccurate and should be reviewed before use.
19. Changes to this policy
We may update this Privacy Policy from time to time. Updated versions will be posted or otherwise made available.
Where required by law, we will provide additional notice of material changes or obtain consent.
20. Contact
For privacy questions or rights requests, contact:
privacy@ulam.ai
Yotta Content LTD
Company number: 12683376
Registered office: 71–75 Shelton Street, London, Greater London, United Kingdom, WC2H 9JQ