Loading...
Loading...
Effective August 25, 2026
This policy explains what EnsemblAI LLC (“EnsemblAI,” “we”) collects when you use the EnsemblAI dashboard, API, and related services, why we collect it, and the choices you have. The short version: we collect what’s needed to run an analytics product with accounts and billing — and nothing aimed at advertising. We use no advertising or analytics trackers, and we do not sell or share your personal information for advertising.
The analytics data the product serves (package downloads, rankings, dependency structure) is derived from public software-registry sources and is not personal data about you as a customer. Where those sources include information about package maintainers, see “Public registry data” below.
We use only two kinds of cookies: authentication session cookies (set by Clerk; strictly necessary to keep you signed in) and small preference cookies (for example your selected ecosystem and theme). No advertising cookies, no third-party analytics, no cross-site tracking — which is why there is no cookie banner.
We share personal information only with the service providers below, who process it on our instructions, and where required by law (in which case we’ll notify you unless legally barred). We never sell it.
| Provider | Purpose | Location |
|---|---|---|
| Clerk | Authentication and account management | United States |
| Stripe | Payments, subscriptions, and invoicing | United States |
| Google Cloud Platform | Hosting, databases, storage, and logging (region us-central1) | United States |
| Anthropic | Large-language-model processing for the AI assistant | United States |
Wherever you are, you can ask us to access, export, correct, or delete your personal information by emailing support@ensemblai.com from your account email (that’s how we verify it’s you). We respond within 30 days and don’t discriminate for exercising rights. Residents of California, the EU/UK, and similar jurisdictions may have specific statutory rights (access, portability, correction, deletion, objection); we honor these requests regardless of jurisdiction. We do not sell or share personal information as those terms are defined in the California Consumer Privacy Act.
Traffic is encrypted in transit (TLS) and data is encrypted at rest. API keys are stored only as one-way hashes, never in plaintext. Customer data is isolated per account with database row-level security, and production secrets live in a managed secret store with access controls and rotation. No system is perfectly secure, but if a breach affects your personal information we will notify you as required by law.
The Service is hosted in the United States (Google Cloud, us-central1). If you use it from elsewhere, your information is transferred to and processed in the U.S.
The analytics we serve are built from publicly available software-registry and repository metadata (PyPI, the npm registry, GitHub), which can include information about package maintainers — such as usernames, public profile details, and organization affiliations — as published by those sources. We collect only what is publicly available without authentication or circumvention of access controls. If you are a maintainer and would like your information suppressed from our product, email support@ensemblai.com and we will action it within 30 days. Corrections to the source data itself belong with the registry that publishes it.
The Service is a business analytics tool, not directed to children under 16, and we don’t knowingly collect their data.
We’ll post updates to this policy here with a new effective date and will email account holders about material changes. Questions and requests: support@ensemblai.com.