LEGAL

Privacy policy

Last updated 2026-09-26.

This policy describes what systemonemodels.tech ("the registry"), operated by Biplov Gautam trading as System One Models, collects about you and why. The short version: we collect what an account and a registry need, we do not sell it, and we do not run advertising.

What we collect

Account data. Your email address, a hash of your password (never the password), your username, and whatever you choose to add to your profile: a display name, a bio, a website, a picture. Publishing needs a verified address, so we also keep the time your address was verified.

What you publish. Models, files, manifests, model cards, versions, builds, comments and articles you submit, and the organisations you belong to. Public content is visible to everyone, including search engines and AI crawlers, and may be downloaded by anyone under the licence you state.

Access tokens and sessions. We store hashes of tokens and session identifiers, the name and scope you gave a token, and when it was last used.

Request logs. Like every web service, our servers record the requests they receive: the address they came from, the page or endpoint, the time, and the browser's user-agent string. We use these to keep the service running, to rate-limit abuse and to investigate incidents. They are kept for a short period and are not used to profile you.

Cookies. One cookie, for keeping you signed in. It is set only when you sign in and deleted when you sign out. Some preferences (such as your colour theme) are kept in your own browser's storage and never sent to us. We use no advertising or cross-site tracking cookies.

Download counts. We count downloads per model and per file. Counts are aggregate numbers; we do not keep a per-person download history.

Who else sees it

We run on infrastructure from providers who process data for us under their own terms: Cloudflare (network, edge caching and file storage, which means uploaded files are stored in Cloudflare R2 and served through Cloudflare's network), Hostinger (servers), and Resend (transactional email such as verification codes and password resets). Your email address reaches Resend when we send you a message. Nobody else receives your data unless the law requires it or you ask us to share it.

Models you download from a maker's own hosting (for example a file on Hugging Face that a version references) are fetched by your client directly from that host, which then sees your request.

How long we keep it

Account data stays while your account exists. Deleted content disappears from the service at once and from backups within 30 days; backups are encrypted at rest and kept in a private bucket. Request logs are kept for no more than 30 days. Aggregate statistics contain nothing that identifies you.

Your rights

You can see and change your profile in settings, export your models with the CLI, revoke tokens, and delete your models and your account. If you want a copy of the data we hold about you, want it corrected or deleted, or object to how we use it, email [email protected]. We answer within 30 days. If you are in the EU or UK you also have the right to complain to your data protection authority.

Children

The service is not for children under 16 and we do not knowingly collect their data. If you believe a child has an account, tell us and we will remove it.

Security

Passwords are hashed with Argon2; tokens are stored only as hashes; traffic is encrypted in transit; uploads are verified against their checksums. No system is perfect. If we learn of a breach that affects you, we will tell you without undue delay.

Changes

We will update this policy as the service changes, and the date at the top of this page changes with it. Questions: [email protected].