Privacy Policy
Coldcache is operated by Aleksandr Globenko under the trade name Coldcache. This policy explains how information is handled when you visit coldcache.ai, contact Coldcache, schedule a call, or enter into a Coldcache engagement.
This policy should be read together with the Data Handling page and any signed NDA, proposal, statement of work, or data-processing agreement. A signed agreement controls if it conflicts with this public policy.
1. Information collected through the website
- Direct enquiries: your name, email address, company information, and the content of messages you send to hello@coldcache.ai.
- Scheduling information: information you enter when arranging a call through Cal.com, such as name, email, time zone, answers to booking questions, and selected meeting time.
- Basic hosting logs: the website host may process technical request information such as IP address, browser type, referring page, requested URL, and timestamp for security, reliability, and abuse prevention.
The supplied static website does not intentionally use advertising trackers or marketing analytics cookies. Third-party services reached through links, including Cal.com and LinkedIn, apply their own privacy terms.
2. Information collected for an engagement
The information requested depends on the agreed service and audit depth. It may include:
- OpenAI or Anthropic usage and cost exports, including model, token, cost, cache, project/workspace, service-tier, and time fields where available;
- n8n execution IDs, workflow and node labels, timestamps, status, duration, retries, errors, schedules, and other approved telemetry;
- request-level traces, sanitized workflow configuration, and representative test cases where necessary for the agreed scope;
- contracts, invoices, payment status, support correspondence, and delivery records.
Coldcache does not request production credentials for an audit and does not want unnecessary personal data, regulated records, full production databases, unrelated source repositories, raw customer messages, or prompt/response content that is outside the agreed scope.
3. How information is used
- To respond to enquiries, qualify fit, schedule calls, and prepare proposals.
- To perform the agreed audit, implementation, or monitoring work and deliver the resulting report.
- To calculate cost and usage metrics, investigate agreed patterns, design tests, and support follow-up measurement.
- To invoice, maintain accounting and legal records, resolve disputes, and protect the service from misuse.
- To improve internal methodology using lessons that do not identify a client or disclose client information.
4. LLM use and automated analysis
Raw client files are not uploaded to consumer AI chat products. Deterministic local tools are used for aggregation, pricing, anomaly detection, correlation, and report tables where practical.
If LLM assistance is useful, the default input is limited to redacted derived metrics or de-identified summaries through a specifically disclosed commercial/API service or a client-managed environment. Coldcache does not use client data to train or fine-tune a model. Provider retention and training behavior depends on the exact product, account, and settings, so any relevant external processor is disclosed before use.
5. Service providers and disclosures
Coldcache may use limited providers for hosting, scheduling, email, secure file transfer, e-signature, payment processing, or approved LLM analysis. A provider that will receive client confidential information is identified in the engagement documentation with its purpose, account type, relevant retention setting, and applicable terms.
Information may also be disclosed where legally required, to protect legal rights or security, or with your explicit permission. Coldcache does not sell client or website-visitor information.
6. Storage and security
Raw engagement files are stored locally by default in a dedicated per-client folder on a full-disk-encrypted device. Business accounts use unique passwords and multi-factor authentication where available. Coldcache applies least-privilege access, avoids shared accounts for client work, and does not intentionally place raw client folders in personal consumer cloud-sync locations unless the specific service is approved and disclosed.
No system is completely secure. The Data Handling page describes the validation-phase controls and incident procedure in more detail; it is not a security certification.
7. Retention and deletion
- Raw provider exports, n8n logs, traces, and sanitized configuration: deleted from systems under Coldcache’s control within seven calendar days after final delivery, or earlier on written request, unless another period is agreed in writing.
- Final reports and ordinary business records: may be retained for support, invoicing, accounting, tax, legal, or dispute purposes. These records should not contain unnecessary raw logs.
- Case-study information: retained and published only with separate explicit written permission and only in the approved form.
- External-processor information: subject to the disclosed provider’s terms and settings. Coldcache does not promise deletion from an external system unless that behavior has been verified and documented.
8. Case studies and publicity
Coldcache will not identify a client, use a client name or logo, publish engagement details, or create an anonymized case study without separate explicit written approval. Approval may be withheld or limited to specific text, metrics, or channels.
9. Your requests
You may ask what information Coldcache holds about you, request correction or deletion where applicable, request early deletion of raw engagement files, ask which processors are being used, or request deletion confirmation. Some business records may need to be retained for legal, tax, accounting, security, or dispute purposes.
Send requests to hello@coldcache.ai. Identity verification may be required before acting on a request.
10. International and regulated work
Service providers may process information in countries different from yours. Relevant provider and transfer information is addressed during scoping where client data is involved. During validation, Coldcache does not accept regulated or safety-critical engagements. EU engagements involving personal data are deferred until a reusable data-processing agreement and documented workflow are ready.
11. Changes to this policy
This policy may be updated as Coldcache’s entity, tools, processors, and operating controls develop. The date above will be changed when the policy is revised. Material changes affecting an active engagement will be communicated where appropriate.
Want an NDA before sharing anything?
Email hello@coldcache.ai with the subject “NDA request”. You are not required to share logs, exports, workflow files, or other project information before the NDA is signed.