Privacy Policy
Last Updated: September 29, 2026
This policy explains how Salad Technologies, Inc. ("Salad", "we") handles information when you visit our websites, run the Salad desktop app as a Chef, or use SaladCloud as a customer. SaladCloud means the SaladCloud Portal and API, Salad Container Engine, Job Queues, Salad Simple Storage Service (S4), Salad Transcription API, Salad AI Gateway, Salad Gateway Service, Salad Dedicated, and any other product we offer through the Portal or API.
If you are an end user of a product one of our customers built on SaladCloud, this policy does not cover that product. We process your information on the customer's instructions; direct questions to them.
1. WHAT WE COLLECT
From everyone. Contact details and messages you send us; IP address, browser, device, and pages viewed, collected through cookies and similar technologies (see Section 6).
From Chefs. Your email address and sign-in credentials; a persistent machine identifier and your computer's CPU, GPU, RAM, storage, operating system, and driver details; your public IP address and the country and region derived from it; uptime, heartbeat, workload lifecycle, performance, and error data; your balance, earning history, and the details needed to deliver rewards you redeem (for example a PayPal email, a phone number for verification, or a shipping address); and how you use the app.
From SaladCloud customers. Your name, email, company, business address, and sign-in credentials; billing details processed by Stripe (we do not store full card numbers) or, for crypto payments, settled on the public blockchain; the resources you create and the compute you consume; Portal and API activity such as IP address, API key identifiers, and timestamps; support and sales communications; and how you use the Portal.
Workload Data. The content customers process through SaladCloud: container images, environment variables and secrets, container logs and metrics, Job Queue payloads, S4 files, transcription media and transcripts, and AI Gateway inputs and outputs. Workload Data belongs to the customer. We process it only to provide the service, keep the platform secure, enforce our Terms, and comply with law. We do not use it to train machine learning models, and we do not sell it. Where Workload Data includes personal information about a customer's users, the customer is the controller and we are the processor.
2. WHY WE USE IT
To run accounts and authenticate users; to match workloads to eligible machines; to pay Chefs and bill customers; to operate, secure, and troubleshoot the network, including detecting fraud, multi-accounting, abuse, and tampering; to comply with sanctions, export, tax, and other legal obligations; to provide support; to send service messages; to send marketing you can opt out of; and to understand how our products are used so we can improve them. We do not sell personal information. We share website visitor data with advertising partners as described in Sections 5 and 6; you can opt out as described in Section 6.
3. WORKLOAD DATA ON THE DISTRIBUTED NETWORK
SaladCloud runs workloads on two kinds of infrastructure. Community Cloud workloads run through Salad Container Engine on computers owned by Chefs, each inside an isolated environment. Container images and configuration are encrypted in transit and at rest. Chefs agree in their Terms of Service not to access customer workloads, and we may remove machines that attempt to. No security control is absolute, and Community Cloud is not intended for data that requires guaranteed physical control of the host. Other workloads, including Salad Dedicated, run on hardware operated by Salad or by partners under contract with us, and are not placed on Chef machines. Details are on our security page.
Salad receives the logs your workload writes, resource metrics, and lifecycle events so we can operate the platform and show them to you. Our personnel access Workload Data only to operate and troubleshoot the platform, to provide support you request, to investigate abuse or security incidents, or to comply with legal process.
| Product | Retention |
|---|---|
| Container images and credentials | Encrypted copies held on Salad servers and cached on Chef machines; customer registry credentials used once, then discarded |
| Container logs and metrics | Up to 95 days |
| Transcription API | Media and transcripts kept as needed to complete and return your job |
| AI Gateway | Content not stored; metadata per Section 4 |
4. AI GATEWAY DATA POLICY
Salad AI Gateway is designed with privacy by default.
We do not train on your data. Inputs and outputs sent through the AI Gateway are never used to train, fine-tune, or evaluate models, ours or anyone else's.
We do not store prompt or completion content. Request and response bodies are held in memory on the gateway and on the inference node while the request is processed. Salad does not write them to disk, a database, object storage, or a backup. Models may hold a short-lived cache in GPU memory to speed up subsequent requests; it is not persistent and does not constitute retention.
We do not log prompt content. Application logs, error logs, and traces do not record prompt or completion text.
We collect limited operational metadata only. Per request: the organization, user, and API key, a request identifier, the model, token counts, timing, status and error class, the serving node, and the client IP address and user agent. We use it to bill, rate-limit, route, secure, and improve the service. It does not include prompt or completion content.
Where inference runs. Requests are served on the distributed network described in Section 3, on Chef-owned and Salad- or partner-owned hardware, as described in Section 3. Contact us if you need requests restricted to specific hardware or jurisdictions.
Your data remains your data. You retain your rights in your inputs and, as between you and Salad, own the outputs. Do not send data you are not permitted to process, or data subject to sector-specific regulation, unless we have agreed in writing that the service is suitable for it.
5. WHO WE SHARE IT WITH
Service providers under contract: cloud hosting, identity, payments (Stripe and Coinbase) and payouts (PayPal), analytics, error monitoring, fraud prevention, content delivery and security, customer support, CRM, and email. A list of our infrastructure subprocessors is available through the Trust Center. Chefs and partner operators run workloads but do not receive customer identities. Reward providers receive what they need to fulfil a redemption. We also disclose information when the law requires it, to enforce our Terms, to protect Salad or our users, in a merger or sale of assets, and with your consent. We may share aggregated data that cannot identify you. Advertising and marketing services: we use third-party services on our websites for advertising measurement, advertising to people who have visited our sites, analytics, A/B testing, and identifying the companies and people who visit our sites. These providers receive identifiers, IP address, and browsing activity on our sites and may combine them with information they hold. The SaladCloud Portal uses analytics, marketing and advertising, error-monitoring, and support tools; the Chef app uses analytics and error-monitoring tools and does not use advertising services.
6. COOKIES
Our sites and apps use cookies and similar technologies to keep you signed in, remember preferences, secure the service, measure usage, test changes to our sites, and for the advertising and marketing purposes described in Section 5. You can limit this collection with browser settings or tracker-blocking extensions, and each advertising platform offers its own ad-preference settings. We do not currently act on Do Not Track or Global Privacy Control browser signals. Blocking essential cookies may break sign-in.
7. RETENTION
We keep account, billing, earning, and redemption information for as long as your account exists and afterwards for as long as we need it for tax, accounting, fraud prevention, dispute resolution, and legal obligations. Workload Data follows Section 3 and Section 4.
8. SECURITY
We use encryption in transit and at rest, access controls, logging, and independent audit. Salad has completed a SOC 2 Type I examination of the design of its security controls. Our Trust Center lists our controls and infrastructure subprocessors; the SOC 2 report is available on request. No system is perfectly secure. Report vulnerabilities at salad.com/report-abuse.
9. YOUR RIGHTS
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent. Email [email protected] from your account email. We will verify your identity and respond within the time the law requires. You can opt out of marketing email through the unsubscribe link or your account settings.
Salad is based in the United States, and we and our providers process information there and in other countries; Chef machines are located worldwide, and customers can restrict where their workloads run. For people in the EEA, the UK, and Switzerland: our legal bases are contract, our legitimate interests in operating and securing the network, legal obligation, and consent where we ask for it; we rely on standard contractual clauses for transfers; and you may complain to your local supervisory authority.
10. CHILDREN
You must be 18 or older to create an account. We do not knowingly collect information from anyone under 18; if a minor has created an account, tell us and we will delete it.
11. CHANGES
We will change the date at the top when we update this policy. If a change materially reduces your rights or changes how we handle Workload Data, we will notify Chefs and customers by email or in-product before it takes effect.
12. CONTACT
Salad Technologies, Inc. Privacy requests and support: [email protected].