Privacy Notice
Last updated September 26, 2026
This Privacy Notice for Monolyth LLC ("we," "us," or "our") describes how and why we access, collect, store, use, and share ("process") your personal information when you use Qadenza and our other services (the "Services"), including when you:
- visit our website at https://qadenza.ai, or any website of ours that links to this Privacy Notice;
- join the Qadenza beta waitlist or contact us;
- create an account, pair a device, or use the Qadenza dashboard, agent, VS Code extension, or API;
- engage with us in other related ways, including marketing or events.
Questions or concerns? Reading this notice will help you understand your privacy rights and choices. We decide how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you have questions, contact us at privacy@ops.mlyth.org.
Summary of key points
What does Qadenza do with my AI conversations? Qadenza runs AI models on hardware you own. Your prompts, the model's responses, and the files you work with are processed on your own devices. When you reach a device remotely, that traffic passes through our relay servers in transit, and we do not store it.
What personal information do we process? Account details (name, email address, password), the email address you give us to join the waitlist or contact support, information about the devices you pair, Git accounts you choose to connect, and performance data from the Qadenza agent unless you turn it off. Learn more.
Do we process sensitive personal information? Only your account login credentials and the access tokens you give us for Git hosting services. We store these in protected form and use them only to provide the Services.
Do we collect information from third parties? Only when you ask us to: if you connect a GitHub or GitLab account, we receive your username and list of repositories from that service.
Do we sell your information? No. We do not sell or share personal information for targeted advertising.
What are your rights? Depending on your state of residence, you may have rights to access, correct, and delete your personal information. Learn more.
How do you exercise your rights? Email datarequest@ops.mlyth.org. We will act on requests as applicable data protection law requires.
1. What information do we collect?
Information you give us
In short: we collect the information you provide when you join the waitlist, create an account, contact us, or connect other services.
- Waitlist and beta requests. Your name, email address, the operating systems you would use Qadenza on, and whether you would use it alone or with a team. You give us this through the sign-up form on qadenza.ai. We use this to decide who to invite to the beta and to send your invitation.
- Account information. Your first and last name, email address, and password. We store passwords only in hashed form, never in readable form.
- Support messages. Your email address and the contents of any message you send us, along with our replies.
- Connected Git accounts. If you connect GitHub or GitLab to use Workspaces, we store the access token you provide, in encrypted form, and your username on that service. We use the token only to list your repositories and to let your own device clone and push the repositories you choose.
- API access tokens. The names you give tokens for the VS Code extension or other tools, and when they were created. You can revoke a token at any time.
Information about your devices
In short: when you pair a computer with your account, we keep the details needed to show it in your dashboard and connect you to it.
- Paired devices. The device name and hostname, operating system, processor architecture, Qadenza agent version, when it was paired, and when it was last online.
- Hardware for recommendations. When you browse models, the dashboard sends a summary of your hardware (such as graphics card model and memory size) so we can tell you which models will fit. We keep a log of these requests and our responses to improve recommendations. This log is not linked to your account.
Your AI conversations and files
The models you run, your prompts, the responses, the files you attach, and the contents of your Workspaces are processed on your own devices. When you use Qadenza away from the device, requests and responses travel through our relay servers, encrypted in transit. The relay passes them between your browser or tools and your device. We do not store their contents or use them for any other purpose.
Information collected automatically
In short: like most online services, our servers record basic technical information when you use them.
Log and usage data. Our servers record your IP address, browser or client type, the date and time of requests, and error information. We use this to keep the Services secure, prevent abuse, and fix problems.
2. Performance telemetry
In short: unless you turn it off, the Qadenza agent sends us statistics on how fast models run on your hardware. It never sends your prompts, responses, or files.
Qadenza's model recommendations depend on knowing how well different models run on different hardware. To learn this, the agent measures the speed of the models you run and reports the results to us. This is turned on by default. You can turn it off at any time in the dashboard under Organization settings. Turning it off takes effect immediately and deletes any measurements on your device that have not yet been sent.
What is sent.
- Speed measurements, summarized per day: how many tokens per second a model generated and processed, how long it took to start responding, power draw, and the highest graphics card temperature observed. These are sent as grouped ranges, not a record of each individual request.
- What was measured: the inference engine and its version, the compute backend, the model's quantization and file size, and a rough range for how long the prompt was. The model is identified by a one-way hash of its public name, not by the name itself. Models we do not recognize are discarded.
- Benchmark results from the hardware tests the agent runs.
- A hardware profile: operating system and architecture, processor model and core counts, memory size (rounded), graphics card vendor, model, memory (rounded), driver version and connection speed, available compute backends, and hardware warning codes.
- The Qadenza agent version.
What is never sent: your prompts, model responses, files, or Workspace contents; the names of your models; your device's hostname; or file paths on your device.
How we store it. Uploads are authenticated as coming from a paired device, so we can limit abuse. We do not store your device ID or account ID with the measurements. Instead we store a pseudonymous code derived from them, which lets us count each device and account once without identifying them directly. We publish only aggregate figures that combine measurements from several accounts.
3. How do we process your information?
In short: to provide, secure, and improve Qadenza, and to communicate with you.
- To run the beta. To manage the waitlist, choose who to invite, and send invitations.
- To create and manage accounts, and to let you sign in.
- To provide the Services, including pairing your devices, connecting you to them remotely, and cloning repositories you choose into Workspaces on your devices.
- To respond to inquiries and provide support.
- To send administrative information, such as changes to the Services, this notice, or our terms.
- To recommend models that fit your hardware, and to improve those recommendations using performance telemetry.
- To protect the Services, including preventing fraud and abuse.
- To comply with our legal obligations, respond to legal requests, and establish or defend legal claims.
4. When and with whom do we share your personal information?
In short: only with service providers who help us run Qadenza, services you ask us to connect, and as the law requires.
Service providers. We share information with vendors who perform services for us under written contracts that limit their use of it:
- Website and sign-up form: Netlify hosts qadenza.ai and receives beta sign-up form submissions.
- Email: Google Workspace (Gmail) receives sign-up notifications and support emails, stores our replies, and sends our emails.
- Hosting and infrastructure: providers that host our servers, databases, and relay.
Services you connect. When you connect GitHub or GitLab, we send your access token to that service to list your repositories. Your own device contacts other services directly when you ask it to, such as Hugging Face or Ollama to download models. Those services' own privacy policies apply to that information.
Business transfers. We may share or transfer information in connection with a merger, sale of company assets, financing, or acquisition of all or part of our business.
Legal requirements. We may disclose information when required by law, such as in response to a subpoena or court order.
We do not sell personal information, and we do not share it for targeted advertising.
5. Do we use cookies and similar technologies?
In short: only what is needed to keep you signed in. No advertising cookies.
The Qadenza dashboard stores sign-in information and your preferences in your browser so you stay signed in and the dashboard remembers your settings. Our website stores a note in your browser that you have requested a beta invite, so it does not ask you again. Our website and dashboard do not use advertising, retargeting, or third-party tracking cookies. If we add analytics in the future, we will update this notice first. You can clear stored data in your browser at any time, which will sign you out.
6. How long do we keep your information?
In short: only as long as we need it for the purposes in this notice, unless the law requires longer.
- Waitlist sign-ups: until you are invited and create an account, or until you ask us to remove you. We delete waitlist entries no later than 12 months after the beta ends.
- Account, device, and connected-account information: for as long as you have an account. Unpairing a device removes it, and disconnecting a Git account deletes its token.
- Support conversations: as long as needed to resolve your request and keep a record of it.
- Performance telemetry: pseudonymous measurements are kept for 24 months. Aggregate figures that cannot be linked to any device or account may be kept indefinitely.
When we no longer need personal information, we delete or anonymize it. If that is not immediately possible, for example because it is held in backups, we store it securely and isolate it from further use until it can be deleted.
7. How do we keep your information safe?
In short: we use technical and organizational measures to protect your information.
These measures include encrypting connections to our Services, encrypting stored Git access tokens, storing passwords only as hashes, and limiting who can access our systems. However, no transmission over the internet or storage system is 100% secure. We cannot guarantee that unauthorized third parties will never defeat our security. Use the Services in a secure environment, and keep your devices and credentials secure.
8. Do we collect information from minors?
In short: we do not knowingly collect data from or market to anyone under 18.
By using the Services, you represent that you are at least 18. If we learn that we have collected personal information from someone under 18, we will deactivate the account and promptly delete that information. If you believe we have, contact us at privacy@ops.mlyth.org.
9. What are your privacy rights?
In short: you can review, change, or delete your account and information at any time.
- Account information. To review or change your account information, or to close your account, contact us. When you close your account, we delete your account information from our active databases. We may keep some information as needed to prevent fraud, resolve disputes, or meet legal obligations.
- Waitlist and email. To be removed from the waitlist or stop receiving our emails, reply to any of our emails or contact us.
- Telemetry. Turn it off under Organization settings in the dashboard.
- Connected accounts and devices. Disconnect a Git account or unpair a device from the dashboard at any time.
- Withdrawing consent. Where we rely on your consent, you can withdraw it at any time by contacting us. This does not affect processing that took place before you withdrew it.
10. Controls for Do-Not-Track features
Some browsers offer a Do-Not-Track ("DNT") setting. No uniform standard for recognizing DNT signals has been finalized, so we do not currently respond to them. We do not track you across other websites in any case. California law requires us to tell you how we respond to DNT signals: because there is no accepted standard, we do not respond to them at this time.
11. Do United States residents have specific privacy rights?
In short: if you live in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to access, correct, get a copy of, or delete your personal information, and to withdraw your consent. Applicable law may limit these rights in some cases.
Categories of personal information we collect
The table below shows the categories of personal information we have collected in the past twelve months.
| Category | Examples | Collected |
|---|---|---|
| A. Identifiers | Name, email address, account name, IP address, device name and hostname, and online identifiers such as pseudonymous telemetry codes | YES |
| B. Personal information under the California Customer Records statute | Name and contact information | YES |
| C. Protected classification characteristics | Gender, age, date of birth, race and ethnicity, national origin, marital status | NO |
| D. Commercial information | Transaction information, purchase history, payment information | NO |
| E. Biometric information | Fingerprints and voiceprints | NO |
| F. Internet or other electronic network activity | Server logs of your use of the Services, and device performance telemetry | YES |
| G. Geolocation data | Precise device location | NO |
| H. Audio, electronic, sensory, or similar information | Images and audio, video, or call recordings | NO |
| I. Professional or employment-related information | Job title, work history | NO |
| J. Education information | Student records | NO |
| K. Inferences drawn from personal information | Profiles of your preferences or characteristics | NO |
| L. Sensitive personal information | Account login credentials, and access tokens for connected Git accounts | YES |
We use sensitive personal information only to provide the Services: to sign you in and to access the repositories you choose. We do not use it to infer characteristics about you.
We keep Category A, B, and L information for as long as you have an account or are on the waitlist, and Category F information as described in section 6.
Sources, use, and disclosure
We collect personal information from you, from your devices through the Qadenza agent, and from GitHub or GitLab when you connect them. See section 1 for details and section 3 for how we use it.
In the past twelve months we have disclosed Category A, B, and F information to service providers for business purposes, as described in section 4. We have not sold personal information or shared it for targeted advertising in the past twelve months.
Your rights
Under certain US state privacy laws, you have the following rights. They are not absolute, and in some cases we may decline a request as the law permits.
- Right to know whether we are processing your personal data
- Right to access your personal data
- Right to correct inaccuracies in your personal data
- Right to request deletion of your personal data
- Right to obtain a copy of the personal data you previously shared with us
- Right to non-discrimination for exercising your rights
- Right to opt out of the sale of personal data, targeted advertising, or profiling that produces legal or similarly significant effects. We do not do any of these.
Depending on your state, you may also have the right to:
- access the categories of personal data being processed (for example, under Minnesota law);
- obtain a list of the categories of third parties to which we have disclosed personal data (for example, under California, Delaware, and Maryland law);
- obtain a list of the specific third parties to which we have disclosed personal data (for example, under Minnesota and Oregon law);
- limit the use and disclosure of sensitive personal data (for example, under California law).
How to exercise your rights
Email datarequest@ops.mlyth.org or privacy@ops.mlyth.org, or write to the address in section 13. You may designate an authorized agent to make a request for you. We may deny a request from an agent who cannot show they are authorized to act on your behalf.
Request verification. We will need to confirm you are the person the information is about. We use the information in your request only to verify your identity. If we cannot verify it from information we already hold, we may ask for more. If an authorized agent submits a request, we may need to verify your identity, and the agent must provide your written, signed permission.
Appeals. If we decline to act on your request, you may appeal by emailing appeal@ops.mlyth.org. We will tell you in writing what action we took and why. If your appeal is denied, you may submit a complaint to your state attorney general.
12. Do we make updates to this notice?
In short: yes, as needed to reflect changes to Qadenza and to stay compliant with the law.
We will show the date of the latest version at the top of this notice. If we make material changes, such as collecting a new kind of information, we will notify you by posting a prominent notice or by emailing you.
13. How can you contact us about this notice?
Email privacy@ops.mlyth.org, or write to:
Monolyth LLC418 Broadway, Ste N
Albany, NY 12207
United States
14. How can you review, update, or delete the data we collect from you?
Depending on your state of residence, you may have the right to access the personal information we hold about you, learn how we have processed it, correct inaccuracies, or delete it. To make a request, email datarequest@ops.mlyth.org.