Privacy Policy
What AML Foundry collects when you use HundredOne, where it goes, and what you can ask us to do with it.
Version 2026-08-12. In effect from 12 August 2026.
The short version
- Your files are read in your browser. The original file is never uploaded to us; only the text your app needs to search is stored.
- Answering a question sends the relevant passages, and your question, to the model provider that produces the answer. That is unavoidable in a hosted service, and it is why organisations that cannot allow it run a private deployment instead.
- We do not sell your data, and we do not use your material to advertise to you.
- You can ask us for a copy of your data, or for its deletion, at any time.
What we collect
What you give us
- Account details. Your name, email address and workspace name. Your password is stored only as a scrypt hash, and we cannot read it.
- App content. The apps you configure, and the text extracted from the documents you add. Every version of an app is kept so you can restore an earlier one.
- What you send an app. Questions and text you put into an app in order to get an answer.
- Anything you write to us. Enquiries sent through the contact form.
What the service records
- Sessions. A random token in a cookie that is httpOnly and SameSite, stored on our side only as a hash. It is strictly necessary to keep you signed in, and we set no advertising or analytics cookies.
- Usage events. One record per run of an app: which app, which workspace is charged, which account ran it and when. Every run has an account behind it, because nothing beyond our public pages can be reached without signing in.
- Ordinary server logs kept by our hosting provider for operating and securing the service.
Where your material goes
When an app answers, we send the relevant passages of your material and the question to the model provider we have selected for that app. We choose the provider and may change it as better models appear, which is part of what the service does for you. We do not send your material to any other third party for their own purposes.
These are the processors involved in running the service: our hosting and database providers, our email provider for confirmation and recovery codes, and the model provider described above. If you need the current list by name, including where each one processes data, write to contact@amlfoundry.com and we will send it to you.
If your material must not be sent to a third-party model provider at all, that is what a private or on-premise deployment is for, where the models run against your own keys and endpoints inside your own network. Talk to us before uploading anything you are not permitted to share.
Why we are allowed to hold it
We process your account details and your app content in order to perform the contract you entered into with us. We process usage records and security logs on the basis of our legitimate interest in operating the service, billing correctly and preventing abuse. We rely on consent only where the law requires it, and you can withdraw it at any time.
How long we keep it
- Your apps and their material stay until you delete them or close your account.
- Sign-in codes expire after 15 minutes and are single use.
- Sessions expire after 30 days, or immediately when you sign out.
- When an account is closed we delete its material within 30 days, except anything we must keep longer by law.
Your rights
Depending on where you live, you have the right to see the personal data we hold about you, to correct it, to have it deleted, to object to some processing, and to receive a copy in a portable form. Write to contact@amlfoundry.com and we will respond within 30 days. You can also complain to your local data protection authority.
Security
Passwords are hashed with scrypt. Session tokens and emailed codes are stored only as SHA-256 hashes, so a copy of our database yields no usable credentials. Access to an app is enforced in the database query rather than in the interface, which means a mistake in a screen cannot expose someone else’s app. Traffic is encrypted in transit.
No system is perfectly secure. If we discover a breach affecting your data, we will tell affected account holders and the relevant authority within the time the law requires.
Children
The service is not intended for children, and accounts are for people aged 18 and over. If you believe a child has given us personal data, write to us and we will delete it.
Changes
When this policy changes we publish the new version here with a new date. If a change materially affects how we handle your data, we will email account holders before it takes effect.
Questions, requests and complaints go to contact@amlfoundry.com.