Protostar AI

Privacy Policy

Effective date: 2026-09-23

Protostar AI, LLC (“Protostar”, “we”, “us”) operates this website at protostarai.com and the Protostar Secure AI Gateway at api.protostarai.com. This policy explains what data we collect, what we do with it, who else is involved, and what choices you have. It is written to describe the systems as they are actually built. Where a practice is a design goal rather than a certified fact, we say so.

Protostar operates in the United States only. Contact: hello@protostarai.com.


1. This website

The website collects nothing except what you send through the contact form. protostarai.com is a static site: no accounts, no cookies, no analytics or advertising trackers, no third-party scripts, and no access logs.

If you use the contact form, your name, email address, and message are sent to us by email and kept only in our mailbox; the site itself stores nothing. A single function hosted on Amazon Web Services relays the message and records only an anonymous request identifier and whether the send succeeded. We use what you send solely to reply to you. If you email us directly, the same applies.

The site is hosted on Amazon Web Services (S3 and CloudFront). AWS may process your IP address transiently to serve the page, as any host does.


2. The Protostar Secure AI Gateway

The gateway is a business service. Our customers (“tenants”) connect their own applications to it so that their users can use AI models without exposing sensitive data. Two kinds of data are involved, and they are treated very differently.

2.1 Content you send for processing

This is the text your application sends to the gateway: prompts, documents, chat messages. It may contain personal information, including protected health information, depending on what your application does.

2.2 Records we keep about your tenant

To run the service, bill it, and prove what it did, we retain:

2.3 How AI is used, and where your content goes

The gateway is an AI service, and this is the disclosure that matters most.

Every request is classified by sensitivity into one of three classes. Your application can declare a class, and a declaration can only make the classification stricter, never looser.

Before content is sent, personal identifiers are detected by a pattern layer and a named-entity recognition layer. Detection is designed to favour recall, but no detection system is perfect; the guarantee that regulated data stays inside the boundary comes from the C1 routing rule, not from detection alone. Customers handling regulated data should declare class C1.

Outbound content may additionally be rewritten by our self-hosted model to reduce stylistic fingerprints before it leaves. This rewriting happens on the anonymized text only.

2.4 Third parties

We use exactly these third parties in the gateway:

We do not sell personal information. We do not share it with advertisers, data brokers, or analytics providers. There are no other processors.

2.5 Retention and deletion

Because audit records are hash-chained, deletion of old records is performed by sealing and removing the expired portion of the chain, which preserves the integrity of what remains.


3. Security

Data in transit is protected with TLS. The database is encrypted at rest. The gateway and the self-hosted model run in private subnets with no internet gateway and no NAT, reaching AWS services only over private endpoints. Secrets are held in AWS Secrets Manager and never in code.

Protostar is designed to HIPAA and SOC 2 controls. We have not been audited or certified against any standard, and we do not claim compliance with one. Before any protected health information is processed for a customer, a separate Business Associate Agreement between that customer and Protostar is required.


4. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or restrict the processing of your personal information. Requests can be sent to hello@protostarai.com. If you are an end user of a customer’s application rather than a customer yourself, the customer controls your data and your request should go to them; we will assist them in fulfilling it.

We do not use automated decision-making that produces legal or similarly significant effects about individuals.


5. Children

Our services are business tools and are not directed to anyone under 18. We do not knowingly collect personal information from children.


6. Changes to this policy

When we change this policy we will update the effective date at the top of this page. Material changes affecting gateway customers will also be sent to the account contact.


7. Contact

Protostar AI, LLC hello@protostarai.com