01Who we are
Othentic Labs Ltd, trading as Anyray ("Anyray", "we", "us"), is a private company registered in Israel under company number 516743945. We build a self-hosted AI gateway that cuts the cost of LLM traffic. For the personal data described in this policy we are the data controller.
Contact: hi@anyray.ai
Registered office: 2 Kaplan Street, Tel Aviv–Yafo 6473403, Israel
Privacy contact: privacy questions and rights requests go to hi@anyray.ai. We have not appointed a Data Protection Officer; the law does not require one for our processing.
02What this policy covers
This policy applies to:
- anyray.ai and its subpages (together, the "Site"), including the product deck, the LLM cost calculator, and the forms described below;
- the Anyray Portal at app.anyray.ai, where operators sign in, manage their organization, and pay for Anyray (the "Portal"); and
- our marketing communications and our correspondence with you.
It does not apply to:
- Your Anyray deployment. Anyray is self-hosted. The gateway, optimizer, console, and database run in your environment, and prompt and response content never reaches us. For that data, your organization is the controller. For prompt and response content there is no Anyray processing. For the content-free metering rollup, Anyray is your processor. See Data Protection and Subprocessors.
- Third-party websites we link to. They have their own privacy policies.
03The data we collect
Information you give us
| Category | Examples | Where |
|---|---|---|
| Contact data | First and last name, work email address, company name | Waitlist, demo request, Trust Center access form, Portal sign-in |
| Communications data | Emails you send us, messages in a shared Slack Connect channel, notes you type into a form | Email, demo follow-up, forms |
| Scheduling data | Name, email, and time slot when you book a meeting | Cal.com booking widget on the demo page |
| Job-applicant data | Name, email, links (for example GitHub or LinkedIn), a note, and the CV you upload | Careers application form |
| Access records | Name, email, company, the NDA version you accepted, the time you accepted it, and the expiry of the report link | Trust Center report request |
| Account data | Sign-in identity (name, email, identity provider), organization and membership, role | Portal |
| Billing data | Billing contact, invoice history, subscription status. Card details go directly to our payment processor; we never store them. | Portal |
Information collected automatically
- Server and security logs. Our hosting provider (Amazon Web Services / Amazon CloudFront) logs technical data such as your IP address, browser type, and the pages requested. Form endpoints also log the IP address and browser type of the request. We use this to operate, secure, and troubleshoot the Site and the Portal.
- Privacy-friendly analytics. We use Plausible Analytics, which is cookieless and does not collect personal data or track you across sites. It records aggregate metrics such as page views, referrer, country, and device type.
- Google Analytics — only with your consent. Google Analytics sets cookies, so it is off by default and loads only if you accept it. It records pages viewed, time on page, and the path you take through the Site. You can decline, or withdraw consent later, from our Cookie Notice; declining deletes any cookies already set. Plausible continues either way.
- Web fonts and embeds. The Site loads fonts from Google Fonts and, on the demo page, a booking widget from Cal.com. When these load, the provider receives your IP address.
We do not use advertising or marketing cookies, and we do not track you across other websites for advertising. The only cookies we set are Google Analytics measurement cookies, and only if you accept them. See our Cookie Notice for the full list, purposes, and durations.
Data from your Anyray deployment
If your organization runs Anyray, your deployment sends the Portal a content-free usage rollup for metering: request, token, cost, and savings totals, a seat count, and salted seat hashes that we cannot reverse. It never contains prompt or response content and, by default, no user identities. Data Protection describes exactly what crosses.
Sensitive data
Please do not send us special-category data (for example health, religion, political opinions, or biometric data) through the Site, including in a CV or a free-text note. We do not ask for it and do not need it.
04Why we use your data, and our legal basis
Under the GDPR we need a legal basis for each purpose. The table lists them. Where we rely on legitimate interests, we have checked that your interests and rights do not override ours.
| Purpose | Data | Legal basis |
|---|---|---|
| Respond to a waitlist, demo, or contact request and set up a demo | Contact, communications, scheduling | Steps at your request before a contract (Art. 6(1)(b)); otherwise our legitimate interest in answering the people who contact us |
| Provide and bill the Portal | Account, billing, usage rollups | Contract with you or your organization (Art. 6(1)(b)) |
| Grant access to the SOC 2 and penetration-test reports and enforce the NDA | Access records, contact | Contract (the NDA you accept) and our legitimate interest in protecting confidential material |
| Consider you for a role | Job-applicant data | Steps at your request before a contract (Art. 6(1)(b)) and our legitimate interest in hiring |
| Send product news and marketing email | Contact, marketing preferences | Consent where the law requires it; otherwise our legitimate interest in telling existing contacts about Anyray. You can opt out at any time. |
| Operate, secure, and troubleshoot the Site and the Portal | Server logs, device data | Legitimate interest in running a safe, working service |
| Understand how the Site is used | Aggregate analytics (Plausible); Google Analytics data | Legitimate interest for cookieless aggregates; consent for Google Analytics |
| Comply with the law, and establish or defend legal claims | Any of the above, as needed | Legal obligation (Art. 6(1)(c)) or legitimate interest |
Where we rely on consent, you may withdraw it at any time by contacting us or, for cookies, from the Cookie Notice. Withdrawal does not affect processing carried out before it.
We do not make decisions about you by automated means that have legal or similarly significant effects, and we do not profile you.
05Your choices
- Marketing email. Every marketing email has an unsubscribe link. You can also email us. Service messages, such as billing notices or a reply to your request, continue.
- Cookies. Accept, decline, or withdraw analytics cookies from the Cookie Notice.
- Do Not Track. Browsers can send "Do Not Track" or Global Privacy Control signals. Because nothing on the Site sets cookies without your explicit choice, we do not treat these signals as a separate instruction.
- Declining to provide data. Fields marked with an asterisk are required to handle your request. If you leave them empty, we cannot process it.
06Who we share it with
We do not sell your personal data. We share it with service providers ("processors") that act on our instructions under data-processing terms:
| Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services / CloudFront | Website hosting, content delivery, form endpoints, private storage for uploaded CVs and the NDA-gated SOC 2 and penetration-test reports | EU (Frankfurt) origin; CloudFront edge locations worldwide |
| Amazon Web Services (Frankfurt) | Portal and metering backend | EU (Germany) |
| Plausible Analytics | Cookieless, aggregate web analytics | EU |
| Google (Analytics, Fonts) | Usage analytics with your consent; web-font delivery | United States |
| Slack | Internal notifications for form submissions; Slack Connect channels we open with demo customers | United States |
| Cal.com | Meeting scheduling on the demo page | United States |
| WorkOS | Portal sign-in (Google, email code, or your enterprise SSO) | United States |
| Stripe | Payments and invoicing for the Portal. Stripe holds your card details; we do not. | United States |
| Resend | Transactional email from the Portal and from our hiring process | United States |
The current list is always at anyray.ai/subprocessors. We may also share personal data with:
- professional advisors such as lawyers, accountants, and auditors, for the services they provide to us;
- authorities where the law requires it, or to protect our rights, your safety, or the safety of others; and
- a buyer or successor in connection with a merger, acquisition, financing, or sale of assets, under confidentiality terms.
07International transfers
We are based in Israel. The European Commission and the UK both recognize Israel as providing an adequate level of data protection, so data can flow from the EEA and the UK to us without additional safeguards.
Several of our processors are in the United States. For those transfers we rely on the EU-US Data Privacy Framework (and its UK extension) where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses (with the UK Addendum). You can ask us for a copy of the safeguards that apply to your data.
08How long we keep it
We keep personal data only as long as we need it for the purpose we collected it, and then delete or anonymize it. Our standard periods:
| Data | Retention |
|---|---|
| Waitlist and demo contacts | Until you ask us to delete them, or 24 months after our last contact with you, whichever is first |
| Job-applicant data and CVs | The CV download link expires after 30 days. We delete the application 12 months after the process ends unless you ask us to keep it for future roles. |
| Trust Center access records | For the term of the NDA plus the period in which a claim under it could be brought. The report link itself expires after 7 days. |
| Portal account data | For the life of the account; sessions expire and unused invites are pruned. You can export or erase your own account from the Portal. |
| Billing records | As long as tax and accounting law requires, currently 7 years in Israel |
| Server and access logs | 90 days |
| Security audit logs (AWS CloudTrail) | 13 months, so that a full year of activity remains available for security investigation and audit |
| Google Analytics cookies | Up to 2 years, or until you withdraw consent |
| Aggregate analytics | Indefinitely; they contain no personal data |
Where we cannot delete data at once, for example because it sits in a backup, we isolate it from further use until deletion is possible.
09How we protect it
We use technical and organizational measures appropriate to the data, including encryption in transit (HTTPS/TLS), encryption at rest for the Portal, access controls, and audit logging. Anyray holds a SOC 2 Type I attestation for its own program; see Security & Compliance. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your data, we will notify you and the relevant authority as the law requires.
10Your rights
Subject to applicable law, including the GDPR and the UK GDPR for individuals in the EEA and the UK, and the Protection of Privacy Law for individuals in Israel, you may have the right to:
- access the personal data we hold about you and receive a copy;
- correct inaccurate or incomplete data;
- delete your data ("right to be forgotten");
- restrict processing while we check a request;
- object to processing based on legitimate interests, and object at any time to direct marketing;
- withdraw consent at any time; and
- receive your data in a portable, machine-readable format.
How to exercise them. Email hi@anyray.ai. We may ask you to confirm your identity. We respond within one month; for complex requests we may extend this by two months and will tell you if we do. If we refuse a request, we will explain why. Portal users can also export or erase their own account data from the Portal settings.
Complaints. You can lodge a complaint with the supervisory authority where you live or work. For the EEA, the list is at edpb.europa.eu. In the UK it is the Information Commissioner's Office (Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF; +44 303 123 1113). In Israel it is the Privacy Protection Authority. We would appreciate the chance to resolve your concern first.
11Job applicants
When you apply through our Careers page, we receive your name, email, links, note, and CV. The CV is stored in a private bucket and shared with the hiring team through a link that expires after 30 days. We use this data only to assess your application, schedule interviews, and communicate with you. Providing it is voluntary, but we cannot consider an application without it. Retention is set out in section 08.
12Residents of US states
Some US states give residents rights to access, correct, delete, and port personal data, and to opt out of "sales", "sharing", targeted advertising, and profiling. We do not sell personal data, do not share it for targeted advertising, and do not profile. You may exercise the other rights by emailing hi@anyray.ai, and you may appeal a refusal the same way.
13Children
The Site and the Portal are intended for businesses and professionals and are not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
14Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last updated" date above. For material changes we will give notice on the Site or by email where appropriate, and the change takes effect on posting.
15Contact
Email: hi@anyray.ai
Mail: Othentic Labs Ltd, 2 Kaplan Street, Tel Aviv–Yafo 6473403, Israel