Skip to content

Privacy

Privacy Policy

Last Price is built to minimize data exposure and protect tenant information by default. This policy explains what we collect, how we use it, and your rights.

Last updated: October 2026

1. What we collect

When you use Last Price we may collect the following categories of information:

  • Account data: email address, name, and workspace settings you provide when you sign up or update your profile.
  • API request metadata: tenant ID, function name, routing strategy, input / output unit counts, compute duration, and the HTTP response status of each inference call. Raw pricing payloads are not persistently stored beyond what is required for billing and audit.
  • Usage and billing data: metered unit totals, credit balance movements, marketplace revenue records, and webhook delivery logs.
  • Log and diagnostic data: server-side request logs, error traces, and performance telemetry used to operate and improve the platform.
  • Access counts: daily counts of API and MCP requests by route or tool, response status, the public prefix of the API key used (never the full key), workspace and agent ID, the MCP client name and version your client reports, the MCP protocol version, a one-way hash of the MCP session ID, the User-Agent, and the country derived from the request. For failed API authentication we also record why it failed. For requests we cannot tie to a workspace we keep less: only the product name at the start of the User-Agent and, for MCP clients, a recognized client name without its version. We never store full API keys, tokens, request bodies, IP addresses, or email addresses in these counts.
  • Analytics: we use Vercel Analytics (privacy-focused, cookie-free by default) to understand aggregate usage patterns. No advertising trackers are used.
  • Product analytics and session replay: we use PostHog, hosted in the EU, to see which pages you open and what you click, and to record how pages look as you use them so we can find where the product is confusing or broken. It sets a first-party cookie and local storage identifier, for visitors and signed-in people alike. When you are signed in, this is linked to your account and email. Everything you type into a form, and API keys or secrets shown on screen, are masked in recordings. We also use it to turn new features on gradually.

2. How we use your data

  • Authenticate and authorize access to your tenant and workspaces.
  • Route, compute, meter, and settle pricing inference requests on your behalf.
  • Calculate and record billing charges and marketplace revenue shares.
  • Send transactional notifications (e.g., invitation emails, billing alerts).
  • Detect and prevent abuse, fraud, and security incidents.
  • Improve platform reliability, latency, and accuracy using aggregated, de-identified signals.

3. Data security

Tenant API keys are encrypted at rest using AES-256-GCM. All data in transit is protected by HTTPS / TLS. Tenant- and workspace-scoped API routes verify the caller and check workspace membership on every request; a small number of intentionally public endpoints (e.g., the health check and the published OpenAPI specification) do not require authentication.

The commerce control-plane is in beta: connector account credentials are currently persisted as JSON without application-layer encryption, and adding envelope encryption for those records is tracked work prior to general availability. Do not connect production commerce credentials until that work lands.

4. Data retention

Billing records and audit logs are retained as long as your account is active and for a reasonable period thereafter to support disputes and regulatory requirements. You may request deletion of your account data by contacting us; certain records may be retained where required by law or to resolve outstanding obligations. Daily access counts are deleted after 180 days.

5. Third-party services

Last Price is hosted on Vercel. We may use third-party infrastructure providers for database, email, and monitoring services. These providers act as data processors and are contractually obligated to protect your data. We do not sell your personal information to third parties.

6. Your rights

Depending on your location you may have rights under laws such as the GDPR or CCPA, including the right to access, correct, or delete your personal data, and to object to certain processing. To exercise these rights, email support@last-price.ai.

7. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will update the date at the top of the page. Continued use of the platform after a change constitutes your acceptance of the updated policy.