NewSolo / Entrepreneur access, by invitation.Redeem invite →

Responsible AI & AI Disclosure

Effective Date: July 9, 2026
Last Updated: July 9, 2026

Responsible AI at PrivateStack

PrivateStack is a product of Data Science & Engineering Experts, Inc. ("DSE," "PrivateStack," "we," "us," or "our"). PrivateStack provides infrastructure for teams that need to run AI in private, controlled environments. This statement explains how the platform processes the prompts and outputs that pass through it, the commitments we make about that content, and the controls available to tenant administrators.

This statement is a description of our current practices. It is not a contract, does not create warranties, and does not modify the terms of any agreement between you and DSE. Where this statement and a signed agreement (including a Data Processing Addendum or "DPA") address the same subject, the signed agreement controls.

1. Scope of This Statement

This statement applies to the PrivateStack platform and the AI features it provides, including the processing of tenant prompts, model outputs, and related content, and the third-party AI model and inference providers the platform can route to. It supplements — and does not replace — the PrivateStack Security Overview, Privacy Policy, and Acceptable Use Policy.

Tenant data is customer-controlled. In most configurations, the customer (tenant) is the controller or business with respect to the content it processes through PrivateStack, and DSE acts as a service provider or processor. Tenant administrators control the accounts and data of their own users.

2. How PrivateStack Processes Your Prompts and Outputs

PrivateStack operates a control plane; your workloads run in the data plane. Prompts, model responses, embeddings, and knowledge bases are processed to deliver the inference and workspace features you request. In Bring Your Own Cloud (BYOC) deployments under a signed enterprise agreement, that content lives within your own cloud account, and PrivateStack does not access it without your explicit authorization. For platform-hosted processing, we handle your prompts and outputs solely to operate the service, subject to the Core AI Commitments below.

We do not read your prompts or model outputs to review, monetize, or repurpose their contents, and we do not use them to build advertising or training datasets. Operational and security logging is limited to what is needed to run, secure, and troubleshoot the platform, as described in our Security Overview and Privacy Policy.

3. Model Providers and Routing

PrivateStack can route requests to more than one AI model and inference provider. We disclose these at the category level — AI model and inference providers — rather than by naming individual vendors in this public statement. A current list of the specific model and inference providers available through the platform is provided to customers under our Data Processing Addendum on written request.

We engage all AI model and inference providers under commercial (API) terms that do not permit those providers to train their models on your content. Where you deploy your own models in a BYOC configuration, those models and the content they process remain inside your environment.

4. Human-in-the-Loop and Tenant Admin Controls

AI outputs produced through PrivateStack can be inaccurate or incomplete and are intended to support, not replace, human judgment. We recommend that tenants keep a person in the loop for any use that affects individuals' rights, safety, finances, employment, or access to services, and that final consequential decisions are reviewed by an accountable person before they take effect.

Tenant administrators have controls to govern how their organization uses the platform, including managing users and access, and configuring the features and model routing available to their workspace. Tenants are responsible for setting acceptable-use expectations for their own users, consistent with the PrivateStack Acceptable Use Policy.

5. Our Core AI Commitments

The commitments in this section are shared, without modification, across DSE's Responsible AI statement and the PrivateStack Responsible AI statement. In this section, "you" and "your" refer to our customers and clients, and "content" means the prompts, inputs, files, and outputs that you provide to, or generate through, our AI systems and services.

5.1 Processing of Your Content

We process your content solely to provide, operate, secure, and support our AI systems and services. We do not use your content for advertising, and we do not sell your content.

5.2 No Training on Your Content

We do not use your content to train, fine-tune, or otherwise develop AI models — neither our own models nor those of any third-party provider. We engage AI model and inference providers under commercial (API) terms that do not permit those providers to train their models on your content.

5.3 Opt-in Service-Improvement Analytics

We use aggregated, de-identified usage analytics to improve and operate our services only with your opt-in. These analytics are aggregated and de-identified so that they do not identify you or any individual, and they are used to improve our services — not to train AI models. Where you have not opted in, we do not use your content for service-improvement analytics.

5.4 AI Model and Inference Providers

We rely on third-party AI model and inference providers to deliver certain features. We disclose the categories of providers we engage — including cloud infrastructure and hosting providers, identity and authentication providers, AI model and inference providers, and analytics providers. A current list of the specific providers we engage is available to customers under our Data Processing Addendum on written request. We engage all such providers under terms consistent with the commitments in this statement.

5.5 Human Oversight

A qualified person remains accountable for AI-assisted work. We design our AI uses so that a human can review, correct, or override AI outputs, and we do not rely on AI to make final consequential decisions about individuals without a person in a position to review the outcome.

5.6 Data Retention and Deletion

We honor verified deletion requests as required by applicable law and our agreements. Following termination of an account or conclusion of an engagement, we purge the associated content within 30 days, except that residual copies contained in encrypted backups age out on our standard backup-rotation schedule. We retain records for longer only where required by law, such as for tax, legal-hold, or other legal-retention obligations.

5.7 Security Safeguards

We protect content processed by our AI systems using safeguards including encryption in transit (TLS 1.2 or higher) and at rest (AES-256), least-privilege access controls, multi-factor authentication for administrative access, storage of credentials in managed secret storage rather than in source code, and audit logging. In the event of a security incident affecting your content, we will notify affected parties without undue delay and as required by applicable law.

5.8 Framework Alignment

Our AI governance is designed to align with the NIST AI Risk Management Framework (AI RMF). Alignment describes the framework we apply to our own practices; it is not a certification, accreditation, or attestation by any third party, and no such alignment guarantees any particular result.

5.9 Limitations and No Warranty

AI systems can produce outputs that are inaccurate, incomplete, or unsuitable for a given purpose. You are responsible for reviewing AI-assisted outputs before relying on them. This statement describes our practices and does not create any warranty or contractual commitment; any warranties, disclaimers, and limitations of liability are governed exclusively by the agreement between you and Data Science & Engineering Experts, Inc.

5.10 Changes to This Statement

We may update this statement from time to time. When we do, we will revise the effective date above and post the updated statement. Material changes take effect upon posting unless a later date is stated.

6. Questions and Contact

For questions about this statement or how PrivateStack processes your content, or to make a privacy-related request, contact us at privacy@privatestackhub.com or legal@privatestackhub.com, or use the privacy request form available on this site. Requests may include access, correction, deletion, or opt-out request types where applicable law provides those rights.

PrivateStack, a product of Data Science & Engineering Experts, Inc.

8735 Dunwoody Place #5714, Atlanta, GA 30350

This statement is governed by the laws of the State of Georgia, without regard to its conflict-of-laws principles.