Security

How we protect your data. Encryption, privacy, and security practices.

Enkriptatzea bidean

Zure arakatzailearen eta Free.airen arteko trafiko guztia HTTPS (TLS 1.2+) bidez enkriptatuta dago. Gure GPUaren inferentzia-zerbitzarirako API eskaerak ere amaieratik amaierara enkriptatuta daude. HSTS indartzen dugu behe-mailako erasoak saihesteko.

Zure datuak ez dira entrenamendurako erabiltzen

Ez ditugu zure sarrerak, irteerak edo igotako fitxategiak AI modeloak entrenatzeko erabiltzen - inoiz ere ez - zuk berariaz aukeratzen ez baduzu. Zure datuak zureak dira.

PCI-rekin bateragarriak diren ordainketak

Ordainketa guztiak Stripe-ek kudeatzen ditu, PCI Level 1 ziurtagiria duen ordainketa-prozesatzaile bat. Ez dugu inoiz zure kreditu-txartelaren zenbakia, CVV edo txartelaren xehetasun osoa gure zerbitzarietan gordetzen.

Kode irekiko eta auditagarriak diren ereduak

Gure AI modeloak kode irekikoak dira, baimendutako lizentziapean (Apache 2.0 eta MIT). Modeloaren pisuak, arkitekturak eta entrenamendu metodologiak publikoki eskuragarri daude eta edozeinek independenteki ikus ditzake.

Daturik ez saltzeko

Ez dugu zure datu pertsonalak saldu, alokatu edo partekatzen hirugarrenekin publizitate edo merkaturatze helburuetarako. Period.

Azpiegituraren segurtasuna

Gure zerbitzariak VPS gogortuetan eta hodeiko GPU azpiegituretan daude ostatatuta, SSH gakoa soilik erabiliz, segurtasun eguneratze automatikoekin eta trafikoa beharrezko atakaetara mugatzen duten sute-horma arauekin. Datu-baseen babeskopiak enkriptatuta daude.

Segurtasun arazoren bat duzu? Kontaktatu.

Ohiko galderak

Yes. All traffic between your browser and Free.ai is encrypted with HTTPS using TLS 1.2+. API requests to our GPU inference server are also encrypted end-to-end. We enforce HSTS to prevent downgrade attacks.

No. We never use your inputs, outputs, or uploaded files to train AI models unless you explicitly opt in. This applies to all users -- free, paid, and enterprise.

All payment processing is handled by Stripe, a PCI Level 1 certified processor. We never store your credit card number, CVV, or full card details on our servers. Stripe handles all sensitive payment data.

Yes. All self-hosted models are open-source under permissive licenses (Apache 2.0, MIT). The model weights, architectures, and training methodologies are publicly available on HuggingFace and GitHub for anyone to audit.

No. We do not sell, rent, or share your personal data with third parties for advertising or marketing purposes. This is a firm policy with no exceptions.

Our servers use SSH key-only access (no password authentication), automatic security updates, firewall rules restricting traffic to necessary ports, and encrypted database backups. We follow security best practices for all infrastructure.

Uploaded files (images, audio, documents) are processed for the requested AI task and are not retained permanently. They are not used for training, shared with other users, or sold to third parties.

We follow GDPR principles including data minimization, purpose limitation, and the right to deletion. Enterprise customers can choose EU data residency through private cloud deployment. Contact us for a Data Processing Agreement (DPA).

Bai. Ezabatu zure kontua edozein unetan. Honek zure datu pertsonalak, berriketa-historia, belaunaldiak eta API gakoak kentzen ditu. Kontuaren ezabapena iraunkorra da eta berehala prozesatuta dago.

We monitor for vulnerabilities continuously and apply security patches promptly. If you discover a security issue, please report it to us through the contact form. We take all reports seriously and respond quickly.

Not directly, not yet — we would rather say so than imply otherwise. If you want a second factor on your Free.ai account today, sign in with Google instead of a password: your Google account's 2FA then protects your Free.ai sign-in too, including any hardware key or authenticator app you already use there. Password accounts are protected by hashed credentials and rate-limited sign-in attempts, but no second factor. Native 2FA and enterprise SSO enforcement are not currently available.

API keys are hashed before storage and transmitted only over HTTPS. You can revoke and regenerate keys at any time from the developer settings. We recommend rotating keys regularly and never sharing them publicly.

Maite duzu Free.ai? Esan lagunei!

Balioetsi orrialde hau