Privacy Policy

PomexAI — Operated by Pomex Inc.

Last Updated: June 8, 2026

Pomex Inc., a company incorporated in the United States, referred to as PomexAI, we, us, or our, respects your privacy and is committed to protecting it through our compliance with this Privacy Policy. This Privacy Policy describes our policies regarding the collection, use, and disclosure of personal data and the choices you have associated with that information. Capitalized terms used but not defined in this Privacy Policy have the meaning given to them in our Terms of Service.

This Privacy Policy applies to all personal data collected through any written, electronic, or oral communications, as you access the website located at https://pomex.ai and all corresponding webpages and websites that link to this Privacy Policy, interact with applications on third-party websites and services that link to this Privacy Policy, or utilize our API services and platform.

Before using our Site and Service, please carefully read our Terms of Service and this Privacy Policy. By using this Site or Service, you consent to the collection and use of your personal data in accordance with this Privacy Policy and our Terms of Service. If you do not feel comfortable with any part of this Privacy Policy or our Terms of Service, you should not use or access our Site or Service.

We may modify this Privacy Policy at any time. If we make changes, a revised Privacy Policy will be posted to our Site; the date of the last revision is included at the top of the page. We will provide registered users with advance notice by email if we make any material changes to how we collect, use, or disclose personal data or that impact their rights under this Privacy Policy.

Your continued use of the Site or Service following the posting or notice of a revised Privacy Policy means that you accept and agree to the changes.

1. Our Core Data Principle: Multimodal Pass-Through Architecture

PomexAI is designed as a transparent, multimodal pass-through routing platform. We route your AI inference requests, including text prompts, images, videos, audio, and other visual or structural assets, directly to upstream model providers such as Azure OpenAI, AWS Bedrock, Google Cloud Vertex AI, and others and stream the responses back to you in real time. PomexAI may also process Inputs transiently in volatile memory to generate lightweight, non-content Derived Feature Metadata for internal analytics, reliability, routing optimization, abuse prevention, billing/account administration, customer reporting, and product planning; this classifier processing does not store raw prompts, completions, Inputs, Outputs, embeddings, reversible hashes, or other content-bearing fields. Our core data commitments are:

Pass-Through Processing; Reserved Record Rights: PomexAI generally routes your AI inference requests, including text prompts, images, videos, audio, voice recordings, document scans, files containing human features, and other permitted payloads, to the selected upstream provider in real time and streams responses back to you. Subject to this Privacy Policy and our Terms of Service, PomexAI reserves the right to record, log, store, retain, review, and disclose prompts, Inputs, Outputs, request content, related files, and suspected violation evidence when reasonably necessary for billing, security, compliance, abuse prevention, enforcement, supplier or upstream provider requirements, legal obligations, audits, or investigation of misuse.

No Biometric Identification by PomexAI; Customer Responsibility: PomexAI does not claim ownership, licensing, portrait, likeness, or voice rights over images, videos, or audio assets uploaded by users. PomexAI does not intentionally create biometric templates, facial recognition profiles, voiceprints, or biometric identifiers for identification purposes. Content that contains human likeness, voice, image, video, or biometric-adjacent information may be processed or retained only as described in this Privacy Policy and the Terms of Service. Users are responsible for obtaining all required rights, consents, notices, and permissions.

No Training on Customer Data: We will never use your Inputs, Outputs, or any other customer content to train, fine-tune, or improve any AI or machine learning models, whether our own or any third party's. Derived Feature Metadata is used only as non-content operational, analytical, billing, security, compliance, reporting, and planning metadata and is not used to train, fine-tune, or improve AI or machine learning models.

Billing, Security, Compliance, and Provider Audit Records: PomexAI may retain account, request, usage, security, and generation records, including token counts, model identifiers, timestamps, request status codes, request IDs, hashed or pseudonymous user or account IDs, IP addresses, API key identifiers or hashes, generation parameters, routing metadata, logs, Derived Feature Metadata, and suspected violation evidence. Where feasible, these records are de-identified, pseudonymized, hashed, minimized, or access-restricted.

Transient Routing with Limited Exceptions: During ordinary routing, request and response data is processed for the minimum duration required to complete the API call. After delivery, PomexAI does not retain broader copies of request or response content except as permitted for billing, security, compliance, supplier requirements, legal obligations, audits, abuse prevention, enforcement, or suspected violation investigations. Internal classifier processing is non-critical, may be sampled, and may be skipped or silently dropped under load or error conditions without affecting the request-response flow.

We do not control, and are not responsible for, upstream AI model providers' handling of your Inputs or Outputs, including any use for model training or biometric data processing. To understand how your Inputs are used by specific AI models, please check the terms and privacy policies of the applicable upstream providers.

2. Collection of Personal Data

We collect personal data when you use our Site and our Service. Personal data is any information that relates to you, identifies you personally, or could be used to identify you, including but not limited to: your name, mailing address, email address, and telephone number.

2.1 Personal Data You Voluntarily Provide to Us

The personal data we collect from you may include information that you provide by filling in forms on our Site or Service, billing and payment information processed through our third-party payment service providers, records and copies of your correspondence if you contact us, survey responses, and details of transactions you carry out through our Site, including credits purchases and usage records.

2.2 Billing, Usage, Security, and Compliance Records

For each API transaction processed through our Service, we may collect and retain the following records for billing, operational, security, compliance, supplier audit, abuse prevention, enforcement, investigation, internal analytics, reliability, routing optimization, customer reporting, and product planning purposes:

Timestamps of API requests.

Model identifiers.

Token counts.

Pricing tier and applicable discount information.

Request status codes.

Request IDs and hashed or pseudonymous user or account identifiers.

IP addresses, account identifiers, API key identifiers or hashes, routing metadata, and device or network information associated with the request.

Generation metadata, including generation parameters, model configuration, moderation or safety signals, request status, latency, and related logs.

Derived Feature Metadata generated from transient classifier processing, such as task category, task category source, language, prompt length bucket, feature flags such as has_code_block, has_math, or has_url, turn number, categorizer version, and customer-provided labels or headers such as X-Task-Category or X-Tenant-Tag. Derived Feature Metadata does not include raw prompts, completions, Inputs, Outputs, uploaded files, embeddings, reversible hashes, or other content-bearing fields.

Prompts, Inputs, Outputs, uploaded files, completions, multimodal payloads, and suspected violation evidence when reasonably necessary for compliance, security, abuse prevention, supplier or upstream provider requirements, legal obligations, audits, dispute resolution, enforcement, appeals, or investigation of misuse.

These records may be used to enforce our Terms of Service, investigate or prevent fraud and abuse, respond to legal or supplier requests, support audits, process appeals, and suspend, restrict, delete, block, or terminate accounts, Authorized Users, projects, API keys, features, or high-risk capabilities where appropriate. We de-identify, pseudonymize, hash, minimize, or access-restrict these records where feasible and consistent with the purpose of the processing.

2.3 Personal Data Collected Automatically

As you navigate through and interact with our Site or Service, we may use automatic data collection technologies to collect information about your device, browsing actions, and patterns, including details of your visits to our Site, information about your computer and internet connection, and information about your preferences to make your use of the Site more productive.

2.4 Cookies and Other Tracking Technologies

We may use cookies, embedded scripts, and other similar tracking technologies to collect additional personal data automatically as you interact with the Site and to personalize your experience. These technologies help us recognize you, customize or personalize your experience, and analyze the use of our Service.

The following types of cookies are used on our Site: strictly necessary cookies, functional or preference cookies, and performance or analytic cookies. Your browser may provide you with the option to refuse some or all browser cookies. If you disable or refuse cookies, some parts of the Site may be inaccessible or not function properly.

3. Use of Your Personal Data

We may use the personal data that we collect from or about you to present our Site and Service and its content to you; provide you with information, products, or services that you request from us; fulfill any other purpose for which you provide it; provide you with notices about your account; carry out our obligations and enforce our rights; notify you about changes to our Site or Service; improve our Site and Service; allow you to participate in interactive features; and use it in any other way we may describe when you provide the information.

3.1 Aggregated and De-identified Information

We may use aggregated, de-identified, or pseudonymized information, including billing metadata, usage metadata, generation metadata, security events, and Derived Feature Metadata, for internal analytics, reliability monitoring, routing optimization, abuse prevention, billing/account administration, customer reporting, product planning, and service improvement. For classifier-related analytics, we use non-content metadata and do not store raw prompts, completions, Inputs, Outputs, embeddings, reversible hashes, or content-bearing derived fields.

4. Disclosure of Your Personal Data

We may disclose aggregated information about our users, and information that does not identify any individual, without restriction. We may disclose personal data that we collect or you provide as described in this Privacy Policy to contractors, service providers, payment processors, hosting providers, analytics providers, professional advisers, affiliates, successors or buyers, and other parties as necessary to provide and operate the Service.

We may also disclose your personal data to comply with any court order, law, legal process, government or regulatory request, supplier or upstream provider request, audit obligation, or contractual obligation; to enforce our Terms of Service and other agreements; to investigate or prevent fraud, abuse, security incidents, policy violations, misuse, or illegal activity; and if we believe disclosure is necessary or appropriate to protect the rights, property, or safety of PomexAI, our customers, upstream providers, or others.

5. Payment Information

We use third-party payment processors to process payments made to us. In connection with processing payments, we do not retain complete payment card information on our servers. Payment information is provided directly to our third-party payment processors whose use of your personal data is governed by their privacy policies. We may receive and retain limited billing information, such as transaction IDs, payment status, invoice information, credits purchase history, billing address, and payment method metadata.

6. Third-Party Websites and Services

Our Site and Service may contain links to third-party websites, services, or applications that are not operated by us. We have no control over and assume no responsibility for the content, privacy policies, or practices of third-party websites or services. Your use of upstream AI model providers is also subject to the terms, privacy policies, data processing terms, and retention practices of those providers.

7. Data Retention

PomexAI retains personal data for as long as necessary to provide the Service, comply with our legal and contractual obligations, resolve disputes, enforce agreements, process transactions, maintain business records, and support billing, security, compliance, fraud prevention, abuse prevention, supplier audit, enforcement, investigation, and reporting purposes.

Account, billing, usage, security, and compliance records may be retained for the periods reasonably necessary for the purposes described in this Privacy Policy and our Terms of Service, unless a longer retention period is required or permitted by law, supplier requirements, audit obligations, dispute resolution, enforcement, or investigation needs.

Derived Feature Metadata may be retained only as non-content operational, analytical, billing, security, compliance, reporting, or planning metadata. PomexAI does not retain raw prompts, completions, Inputs, Outputs, uploaded files, embeddings, reversible hashes, or other content-bearing fields solely because classifier processing was performed; classifier extraction occurs transiently in volatile memory and may be sampled or dropped when needed to protect request-response performance.

We may delete, de-identify, anonymize, aggregate, or pseudonymize data when it is no longer needed for the purposes for which it was collected, subject to our legal, contractual, and operational obligations.

8. Security of Your Personal Data

We use administrative, technical, and physical safeguards designed to protect personal data against accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use. These measures include access controls, encryption where appropriate, monitoring, logging, and internal policies designed to restrict access to personal data. However, no method of transmission over the internet or electronic storage is fully secure.

9. International Transfers

PomexAI is incorporated in the United States. If you access the Site or Service from outside the United States, your information may be transferred to, stored in, or processed in the United States or other countries where PomexAI, its affiliates, service providers, or upstream providers operate. These countries may have data protection laws that differ from those in your jurisdiction.

10. Children’s Privacy

Our Site and Service are not intended for children under 13 years of age, and we do not knowingly collect personal data from children under 13. If we learn that we have collected personal data from a child under 13 without parental consent, we will delete that information.

11. Your Privacy Rights and Choices

Depending on your location, you may have certain rights regarding your personal data, including the right to access, correct, delete, restrict, object to, or port your personal data. You may also have the right to withdraw consent where processing is based on consent. To exercise these rights, please contact us at the address below. We may need to verify your identity before responding to your request.

12. California and Other U.S. State Privacy Rights

If you are a resident of California or another U.S. state with applicable privacy laws, you may have additional rights regarding your personal information, including the right to know, access, correct, delete, or opt out of certain processing. We do not sell personal information as the term is commonly understood. We may share information with service providers, contractors, payment processors, analytics providers, hosting providers, and upstream providers as described in this Privacy Policy.

13. Categories of Personal Data and Purposes of Processing

13.1 Categories Collected

Depending on how you use the Site or Service, we may collect identifiers, contact information, commercial information, internet or network activity information, geolocation information inferred from IP address, billing and transaction information, account credentials, customer support information, and usage, security, compliance, generation, and Derived Feature Metadata. Derived Feature Metadata is limited to non-content structured attributes generated through transient classifier processing and may include task category, task category source, language, prompt length bucket, selected feature flags, turn number, categorizer version, and customer-provided labels or headers.

13.2 Purposes of Processing

We process these categories of personal data to provide, secure, maintain, improve, bill for, and enforce the Service; operate and troubleshoot the Site and Service; process transactions; prevent fraud and abuse; comply with legal, supplier, contractual, and audit obligations; respond to requests; communicate with you; perform internal analytics; monitor reliability; optimize routing; generate customer reporting; and plan product and service improvements. Derived Feature Metadata is processed for non-content operational, analytical, reliability, routing, billing, security, compliance, reporting, and planning purposes and is not used to train, fine-tune, or improve AI or machine learning models.

14. Data Security Incident Response

If we become aware of a security incident affecting personal data, we will take steps designed to investigate, contain, and remediate the incident and notify affected users, regulators, or other parties where required by applicable law.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as required by applicable law, including by posting the updated policy on our Site and updating the Last Updated date. Your continued use of the Site or Service after the effective date of the revised Privacy Policy means that you accept and agree to the revised policy.

16. Contact Information

If you have any questions about this Privacy Policy or our privacy practices, please contact us:

Pomex Inc.

16192 Coastal Highway

Lewes, Delaware 19958

United States

Email: contact@pomex.ai