FUEL, Inc. ("FUEL," "we," "us," or "our") is a Delaware corporation. This Privacy Policy explains how FUEL collects, uses, discloses, retains, and protects Personal Information when individuals visit FUEL’s website at www.myfuel.io, use FUEL’s AI-powered platform and related services, communicate with FUEL, or otherwise interact with us.
Customer-controlled data. When FUEL processes Personal Data on behalf of an enterprise customer, the customer generally acts as controller/business and FUEL acts as processor/service provider, as applicable. Those processing obligations are governed by the customer agreement and FUEL’s separate Data Processing Addendum (“DPA”). The DPA is not part of this Privacy Policy.
Contract hierarchy. For contracted customers, the MSA and Order Form govern the Services; the DPA controls Personal Data processing to the extent stated in the MSA; the SLA controls service availability and service credits; and the Terms of Use govern general Website and Service use subject to that hierarchy.
Sensitive information. Customers and users should not submit regulated or sensitive Personal Data unless it is necessary, authorized by the applicable customer, and permitted by the parties’ agreements and applicable law.
Current supported practice. Customer-facing registration and authentication are handled through Clerk. FUEL supports social sign-in through providers such as Google and Apple, and enterprise SSO using standards including SAML and OpenID Connect (OIDC). FUEL maps authenticated requests to an internal account and validates tenant membership and authorization before granting access.
Tenant isolation. FUEL uses tenant-level authorization and separate tenant database schemas. A valid identity token alone does not provide access to another customer’s tenant.
AI processing. Depending on the feature used, FUEL may process prompts, uploaded content, conversation history, voice transcripts or recordings, outputs, feedback, memory/preferences, and related metadata to perform the AI or voice operation requested by the user or customer.
No generalized-model training without authorization. FUEL will not use Customer Data, Customer Confidential Information, or customer-specific prompts, inputs, files, or other content submitted through the Services to train generalized artificial-intelligence or machine-learning models for FUEL or unrelated third parties without the customer’s express authorization.
Current AI/voice providers. FUEL’s current Security & Data Protection Overview identifies Gemini and ElevenLabs as specialized AI and voice providers. FUEL transmits only information necessary to perform the requested AI or voice operation over encrypted connections and does not use those providers as its primary long-term storage for text chat history.
AI outputs. AI outputs may be inaccurate, incomplete, non-unique, or unsuitable for a particular purpose. Users should apply appropriate human review, particularly for consequential decisions. Contractual rights in Customer Data and AI outputs are governed by the MSA.
If FUEL engages in targeted advertising, sale, or sharing as defined by applicable law, FUEL will provide required notices and opt-out mechanisms, including recognized opt-out preference signals where legally required.
AI content encryption. FUEL’s current security documentation states that AI chat messages and derived AI content are encrypted at the application level using AES-256-GCM. User-specific data-encryption keys are protected using AWS Key Management Service (KMS), and infrastructure-level encryption is used for databases, storage, backups, and snapshots.
Access controls. Encrypted AI content is decrypted only by authorized application services after identity, tenant membership, and conversation/session ownership checks. Administrative interfaces do not expose decrypted user chat content by default, and FUEL’s operational logs and monitoring systems are designed not to intentionally contain plaintext AI content, transcripts, summaries, authentication tokens, or similar sensitive content.
Voice recordings. Where a voice recording is created and available, FUEL’s current documentation states that the recording is transferred to private FUEL-managed Amazon S3 storage, encrypted at rest using AWS KMS, protected from public access, and made available to the owning user through a short-lived signed URL.
Security limitation. No security program can guarantee absolute security. FUEL maintains administrative, technical, and organizational safeguards appropriate to the nature of the Services and information processed. Additional security commitments may be described in the MSA, DPA, Security Overview, and applicable Technical and Organizational Measures.
User-controlled deletion. Users can delete AI conversations. After ownership verification, deletion removes the conversation content and directly associated data from active application storage, including chat messages, conversation summaries, session outputs, conversation-specific AI memory, associated voice-session records, and FUEL-managed S3 voice recordings. Users can also explicitly delete stored voice recordings.
Contract termination. For contracted customers, the MSA provides a thirty (30)-day post-termination period to retrieve Customer Data, followed by deletion subject to applicable law and the DPA.
FUEL is based in the United States and may process information in the United States and other locations where FUEL or its subprocessors operate. Where international-transfer laws require safeguards, FUEL will use the transfer mechanism specified in the applicable DPA, such as approved standard contractual clauses or another lawful mechanism.
Depending on where you reside and subject to applicable exceptions, you may have rights to request access to, correction of, deletion of, or a portable copy of Personal Information, and to opt out of certain sales, sharing, targeted advertising, or profiling. You may also have rights concerning sensitive Personal Information and appeals of denied requests.
Customer-managed data. If FUEL processes your Personal Data on behalf of a FUEL customer, you should generally submit your request to that customer. FUEL will assist the customer as required by the DPA and applicable law.
Requests. Submit requests to our privacy contact. FUEL may verify identity and authority before completing a request and will not unlawfully discriminate against an individual for exercising privacy rights.
The Services are primarily designed for organizations and are not marketed directly to children.
If a customer authorizes minors to use the Services, the customer is responsible for providing required notices and obtaining required permissions, subject to FUEL’s independent obligations under applicable law and the DPA.
FUEL may disclose or transfer information in connection with a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or other corporate transaction, subject to applicable law and contractual obligations.
FUEL may disclose information when required by law or where reasonably necessary to protect FUEL, customers, users, or others; investigate fraud, abuse, or security incidents; enforce agreements; or establish, exercise, or defend legal claims. Where legally permitted and contractually required, FUEL will provide appropriate notice of compelled disclosures.
FUEL may update this Privacy Policy to reflect changes in law, technology, products, or practices. Material changes will be communicated by reasonable means appropriate to the nature of the change. A change to this public Privacy Policy does not amend a negotiated MSA or DPA except where that agreement expressly permits incorporation of an updated policy.
FUEL, Inc.
4525 Dean Martin Dr, Suite 2207, Las Vegas, Nevada 89103, USA
Email: legal@fuel.io
Website: www.fuel.io
Main line: 1-844-428-7171