Privacy policy
Last updated: 4 October 2026. Draft of 4 October 2026.
This policy explains what personal data Pearl Compute collects, why, who we share it with, how long we keep it and what your rights are. It covers the website at ai.pearlsafe.xyz (including the web chat, the developer console and the miner portal), the API at api.ai.pearlsafe.xyz, our mining pool at pool.ai.pearlsafe.xyz and our node service at node.ai.pearlsafe.xyz.
It does not cover the Pearl Safe wallet at pearlsafe.xyz. Pearl Safe has its own privacy policy, at pearlsafe.xyz/privacy.
In short
- We do not log or store the content of your prompts or completions, and we never train on them.
- We keep account data and request metadata (counts, times, costs, no content) for billing and reliability.
- Standard requests also mine PRL, the Pearl network's coin. Read "Mining and your data" below to see what that means.
- GPU nodes may be in any country. By default a request runs on any healthy node. You can limit this with region rules (section 6).
- We set only strictly necessary cookies: a session cookie to keep you signed in and, on staff admin pages, a short-lived passkey sign-in cookie. Our network provider may add a security cookie. No analytics, advertising or tracking cookies.
1. Who we are
Pearl Compute is a service of Extra Watts B.V.
- Legal name and legal form: Extra Watts B.V. (besloten vennootschap)
- Registered in the Netherlands. Chamber of Commerce (KvK) number: 75938650
- VAT number: NL860448769B01
- Address: Herengracht 420, 1017 BZ Amsterdam, Netherlands
- Privacy contact: privacy@pearlsafe.xyz
- Legal notices: legal@pearlsafe.xyz
- General contact: hello@pearlsafe.xyz
- Security contact: security@pearlsafe.xyz
- Data protection officer: we have not appointed one. The law does not require one for our activities. Send privacy questions to privacy@pearlsafe.xyz.
Extra Watts B.V. is the controller of the personal data described in this policy.
If you send other people's personal data through the API. If you are a business and your requests contain personal data about other people (for example your own customers), we process that content only to answer your request and, on the Standard tier, for the mining checks in section 7, on your behalf. In that case you are the controller of that content and we are your processor. We offer business customers a data processing agreement (DPA). Email privacy@pearlsafe.xyz to get it.
2. Data policy
This is the data policy we submitted to OpenRouter. It applies to every request we serve.
No training on prompts or completions, ever. Zero retention: we do not log or store prompt or completion content; we keep only request metadata (such as request ID, account, timestamps, model, token counts, latency, cost and status) for billing and reliability. GPU nodes run our node software and the open-source Pearl miner, configured not to log or store content. Nodes are operated by us or by independent operators worldwide who must run our unmodified software under our terms. For proof-of-work verification, our pool briefly checks a small slice of intermediate model values from mined requests in memory, then discards them. These are numbers, not text, though with the public model they could reveal individual tokens. We keep only a one-way hash of each share; for the rare share that wins a block, a zero-knowledge proof with a one-way fingerprint of those values is published on the Pearl blockchain. Requests on our Private tier are never used for mining and are routed only to vetted nodes.
The rest of this page explains this in more detail.
3. What we collect
Account and sign-in
- Your email address. You sign in with a link we email to you (a "magic link"). There is no password. Your account is created the first time you use a link.
- Account details: an account ID, your role (customer, miner or both), when you signed up and when you last signed in.
- Sign-in link records: the email address the link was sent to, a one-way hash of the link's token, when it expires (15 minutes after it is sent) and when it was used. Each link works once.
- Sign-in rate limiting: when someone asks for a sign-in link, we record a keyed one-way hash of the IP address (not the address itself) and the time. We use it only to limit how many links can be requested.
- Sessions: a one-way hash of your session token, when the session started, when it expires and when it was last used.
Cookies and browser storage
- Our session cookie (
__Host-pc_session), set only when you sign in. It is sent only to ai.pearlsafe.xyz (host-only), only over encrypted connections, and cannot be read by scripts on the page. It expires after 30 days, or when you sign out. It is strictly necessary to keep you signed in, so it does not need your consent. - Our passkey sign-in cookie (staff only). When a member of our staff signs in to our admin pages with a passkey,
we set a short-lived cookie (
__Host-pc_webauthn) that holds a one-time sign-in challenge. It has the same protections as the session cookie and expires after 5 minutes. Other visitors never get it. It is strictly necessary. - Security cookies from our network provider. Our website runs behind a network provider that protects it against attacks. When it checks whether a visitor is a bot, it may set its own strictly necessary security cookies (for example a bot-management cookie that expires after 30 minutes). They are not used for analytics, advertising or tracking.
- No analytics, advertising or tracking cookies, and no third-party analytics or tracking scripts on the site.
- Chat history is kept in your browser's own storage (IndexedDB), not in a cookie, and only if you turn on saving. Your choice to save or not is remembered in the browser's local storage; it holds no chat content. See section 4.
- Payments. When you buy credits you are sent to our payment provider's checkout page. That page is run by the payment provider, which sets its own cookies under its own policy.
- No cookie banner. We use only cookies and browser storage that are strictly necessary for the service you ask for, so we do not need your consent and do not show a cookie banner. If we ever want to use a cookie that is not strictly necessary, we will ask for your consent first.
API keys
- A one-way hash of each key (never the key itself; we show you the key once, when you create it).
- The first few characters of the key, so you can tell keys apart.
- The key's name, its privacy tier, its rate limits, and when it was created, last used and revoked.
Request metadata
For each request we keep metadata only, never the content:
- request ID, account, API key, timestamps;
- model, endpoint, whether it was streamed, privacy tier, which GPU node served it and that node's country;
- token counts, cost, what the GPU operator earned for it;
- status, error code, number of attempts, time to first token and duration;
- a usage receipt signed by the GPU node. The receipt holds the request ID, node, model, token counts and finish time. It contains no content and no hash of the content.
We use this for billing, your usage page, abuse prevention and keeping the service reliable.
Payments
- What we keep: the amount, the status, the time, and our payment provider's reference for the payment. Our credit ledger records each purchase and each charge.
- What our payment provider gets: we pass your account email address and account ID to the provider's checkout page. You enter your payment details (for example your card) on the provider's page. We never see or store your full card number.
- Our payment provider processes payment data to handle your payment. For some purposes, such as preventing fraud and meeting its own legal duties, it acts as an independent controller, under its own privacy policy.
Miners and node operators
If you run a GPU node or mine with our pool, we also collect:
- Node details: the node's name, its public key, its status and its trust tier.
- Node country: the country you declare for the node, and the country that the node's IP address points to. We look up the IP address each time the node connects and store only the resulting country, not the address. (Our server access logs do record IP addresses; see "Technical logs".)
- Heartbeats: about every 10 seconds the node sends GPU model, memory use, utilisation and temperature, the models it serves, active requests, queue depth, tokens per second and miner health (including share counts). We keep the latest heartbeat and a short history.
- Pool records: your mining workers, and for each share a one-way hash plus metadata (time, block height, difficulty, accepted or rejected and why, whether it found a block, the model, whether the weights check passed, and what the node was doing at the time: customer requests, filler or idle). We never store the share itself.
- Test results: we send nodes test requests to check that they serve the model they claim. We keep the results.
- Payout details: your payout addresses (PRL on the Pearl network; USDC on Base), payout amounts and transaction IDs.
- Sanctions screening: before we send a payout, we check the payee against sanctions lists. We keep the result of each check, and any proof of identity or location we ask you for.
Technical logs
- Our web servers keep access logs: the time, the IP address, the path, the status, the response size and timings. We remove request headers (including cookies and API keys) and query strings (sign-in links carry tokens) before anything is logged. Request and response bodies are never logged.
- Our applications log IDs, error codes and counts. They are built never to log content or secrets. In rare error cases, a log line can contain an email address or a payout address.
- We keep an audit log of administrative and security events, such as admin changes, staff passkey sign-ins, node enrolments, payout steps and sign-in link requests. For sign-in link requests it holds only the keyed IP hash and the time (the rate-limiting records above).
When you contact us
If you email us, we keep the email and our reply. Emails to our contact addresses are forwarded to our company mailbox.
4. What we do not collect
- Prompt and completion content. We do not log or store it, and we never train on it. Content exists only in memory on the servers that handle the request, while they handle it. On GPU nodes, recent prompt data may stay in GPU memory for a short time, to speed up repeated prompts, until new requests overwrite it.
- Your chat history. The web chat keeps your conversations only in your browser, and only if you turn on "Save chats in this browser" (it is off by default). Saved chats are encrypted with a key created in your browser that cannot be read out of it. We do not receive a copy of your history. When you send a message, the conversation so far is sent with it so the model can answer. Like an API request, it is handled in memory and not stored. Turning saving off stops saving new chats; "Delete all history" deletes the chats already saved. If you clear your browser's data, your saved history is gone and we cannot recover it.
- Full card numbers. Our payment provider handles them.
- Tracking. No analytics, advertising cookies or tracking pixels.
We do not sell personal data.
5. Who can see your content while a request runs
Content is never stored, but some systems must handle it to answer you. This is the full list.
| Who | Standard tier | Private tier |
|---|---|---|
| Our API gateway and web servers (rented from a cloud hosting provider in Amsterdam, Netherlands) | In memory, while handling the request | Same |
| Our network provider | Website and web chat traffic only, in transit through its proxy. Not API traffic. | Same |
| The GPU node that serves the request, its operator and the company hosting it. Nodes are operated by us, or by independent operators worldwide whose nodes we approve before they receive any customer request. All must run our unmodified software under our terms (section 6). | In memory, while processing the request | Same, but only on vetted nodes |
| Our mining pool | Small samples of the model's internal numbers (see "Mining and your data") | Nothing. Private requests are never mined. |
| The Pearl blockchain | No content. For the rare block, a fingerprint (see "Mining and your data") | Nothing |
| Anyone on the network between you and us | No. Connections are encrypted. | Same |
The companies that host these servers could technically access their memory. We rely on their contracts and their security. Node operators must run our unmodified software under our terms, and we test nodes, but we cannot technically stop an operator from changing their own machine. We do not offer any tier today in which the GPU node cannot see the content it processes.
6. Privacy tiers
Each API key has a privacy tier. Requests made with that key use that tier.
- Standard. Zero retention, as in the data policy above. The same GPU work also mines PRL. See "Mining and your data".
- Private. Zero retention, never used for mining, and routed only to vetted nodes. Vetted nodes are nodes we run, or nodes of operators we have approved for this tier. Before we approve an operator, we check who they are, where and how the node is hosted, and that they have signed our data processing terms. We offer this tier for a model only once we have measured that model's throughput.
- Confidential. Coming soon. It will run requests inside GPUs with hardware isolation (confidential computing). We will describe it here before we offer it. Nothing in this policy depends on it.
Where your requests run
- GPU nodes may be operated anywhere in the world. Some are ours; others are run by independent operators, whose nodes we approve before they receive any customer request. All must run our unmodified software under our terms. Private-tier requests go only to vetted nodes.
- Every node is tagged with its country. The operator declares it, and we check it against the node's IP address. This check relies on the operator's word and on IP location, which a dishonest operator could fake, for example with a VPN. We remove nodes we catch doing this.
- By default, a request runs on any healthy node, in any country.
- You can set region rules for your whole account or for a single API key, for example "EU only" or "exclude these countries". We then send your requests only to nodes that match. If no matching node is available, the request fails straight away with a clear error. It never runs elsewhere instead.
- The country where each request ran is shown in your usage logs and in the
x-pc-node-countryheader (a two-letter country code) on every API response that a GPU node served, including streamed responses. - "EU only" is not the default. If your requests may contain personal data that must stay in the EU/EEA, set an "EU only" rule.
7. Mining and your data
When a GPU node in our network answers a Standard request, the same work also mines PRL, the Pearl network's coin. Here is what that means for your data.
- Nothing readable goes on the blockchain. When our pool wins a block, the block holds a mathematical proof, a few short codes and a few numbers (such as how many tokens the GPU was processing at that moment). It contains no words from your request or from the answer.
- One of those codes is a fingerprint, not a copy. It can't be turned back into text. Someone who already knew almost all of your text, and could repeat our exact calculation, could use it to check that guess.
- Our mining pool sees small samples. To check the mining work, our pool server receives the model's internal numbers for 2 tokens (a token is a word or part of a word) in each mining result (for some models, also part of a neighbouring token's numbers), about 6 results per minute per GPU, taken from whatever the GPU was processing at that moment. With the public model, those numbers could reveal those 2 tokens and possibly some nearby text. The pool checks them in memory, keeps only a code, and never saves or logs them.
- Private and Confidential requests are never mined. While one is running, its node does no mining, and any mining results from that time are thrown away.
8. Why we use your data (legal bases)
| What we do | Legal basis (GDPR article 6) |
|---|---|
| Create and run your account, sign you in, serve your requests, run the chat, bill you, show your usage | Performance of our contract with you (6(1)(b)) |
| Run the miner program: route requests to your node, credit shares, pay you | Performance of our contract with you (6(1)(b)) |
| Mine PRL with the GPU work that serves Standard requests: our pool checks share samples in memory, and for a winning block a fingerprint is published (section 7) | Performance of our contract with you (6(1)(b)): the Standard tier is offered and priced on this basis. For data about other people in your requests, our legitimate interest in mining income that keeps prices low (6(1)(f)). Use the Private tier to avoid it. |
| Keep payment, ledger and payout records | Legal obligation: Dutch tax and accounting law (6(1)(c)) |
| Rate limits, access logs, audit log, test requests to nodes, checks of node countries, checks that miners' shares are valid, fraud and abuse prevention, security | Our legitimate interest in a secure and reliable service (6(1)(f)) |
| Answer your emails and keep a record of them | Our legitimate interest in answering you and handling any follow-up or claim (6(1)(f)) |
| Screening payouts against sanctions lists | Legal obligation under EU and Dutch sanctions law (6(1)(c)). For other sanctions lists, such as those of the United States, our legitimate interest in not breaching sanctions that bind us or our partners (6(1)(f)). |
We send service emails only: sign-in links, and important notices about your account, your credits, payments or these policies. We do not send marketing emails. If that changes, we will ask for your consent first.
9. Who we share data with
We use these kinds of service providers to run the service. They process data on our behalf, under contract, unless noted.
| Recipient | What for | What data | Where |
|---|---|---|---|
| Cloud hosting providers | Our servers: website, API gateway, database, mining pool; encrypted database backups | All the data in section 3. Content passes through server memory while a request is handled. | EU (Amsterdam, Netherlands) |
| Network providers | DNS for our domains. A protective proxy for the website ai.pearlsafe.xyz: it ends the encrypted connection for the website, including the web chat, and passes traffic to our server. It does not do this for the API. Email forwarding for our contact addresses. | Website traffic, including chat messages in transit, IP addresses; emails sent to our contact addresses, in transit | A global network. Traffic from the EU is normally handled in the EU; the provider may also process data in the United States. |
| GPU node operators | Running the GPU nodes that serve requests and mine. Nodes are operated by us, on GPUs we rent from cloud providers in the US and the EU, or by independent operators worldwide whose nodes we approve before they receive any customer request. All must run our unmodified software under our terms. Private-tier requests go only to vetted nodes. | Content in memory while a request is processed | Multiple countries (see "Where your requests run") |
| Email sending provider | Sending sign-in links and service emails | Your email address and the content of the email | May process data in the United States |
| Email hosting provider | Receiving and keeping the emails you send to our contact addresses (they are forwarded to our company mailbox) | Your email address and what you write | May process data outside the EU, including in the United States |
| Payment provider | Payments (see section 3, "Payments") | Your email address, payment details | EU and United States |
A list of subprocessors is available on request. Email privacy@pearlsafe.xyz.
If our API address is ever moved behind our network provider's proxy as well, the network provider would also handle API traffic in transit. We will update this page before that happens.
We do not send your requests to other AI providers.
Other recipients
- OpenRouter. If you reach our models through OpenRouter, OpenRouter is our customer for that traffic. Its own privacy policy covers what it collects. We apply the same data policy to requests that come through OpenRouter.
- Public blockchains. PRL payouts are transactions on the Pearl blockchain and USDC payouts are transactions on Base. Both are public and permanent. Blocks our pool finds are public too (see "Mining and your data").
- Authorities, when the law requires us to share data.
- A buyer or successor, if Extra Watts B.V. or the service is sold or merged. This policy would continue to apply to your data. We will tell you before your data becomes subject to a different privacy policy.
10. International transfers
Our main servers (website, API gateway, database, mining pool) and our backups are in the EU. Some data leaves the EU/EEA:
- Requests. Unless you set region rules, a request may run on a GPU node in any country, including countries outside the EU/EEA that do not have an EU "adequacy decision". Any personal data in that request then leaves the EU/EEA while it is processed. We treat this as an international transfer.
- Our own GPU nodes run on GPUs we rent from cloud providers in the US and the EU.
- Providers. Some of our service providers (for our network, sending email, our mailbox and payments) are based in the United States or process data there.
When personal data leaves the EU/EEA for a country without an adequacy decision, we use the EU Standard Contractual Clauses (SCCs) where applicable, in our contracts with service providers and node operators. For a provider in the United States that is certified under the EU-US Data Privacy Framework, we may rely on that framework instead. We assess the risks of each transfer. You can ask us for a copy of the relevant safeguards.
To keep your requests in the EU, set an "EU only" region rule (section 6). For the strongest assurance, combine it with the Private tier, which runs only on vetted nodes.
11. How long we keep data
| Data | How long |
|---|---|
| Account (email address, account ID, role, sign-up and last sign-in dates) | Until you delete your account. Then deleted within 30 days, except records we must keep by law. |
| Sign-in link records | The link expires after 15 minutes. The record is deleted after 30 days. |
| Sign-in rate-limit records (keyed hash of an IP address) | 7 days |
| Sessions | Up to 30 days. Deleted when you sign out. |
| API key records | While your account exists, including revoked keys, so your usage history stays complete. |
| Request metadata | 24 months, then deleted or anonymised. Charges recorded in our ledger are kept as financial records (next row). |
| Payment, ledger and payout records, and sanctions screening results | 7 years, as Dutch tax law requires. |
| Node heartbeat history | 14 days. The latest heartbeat is kept while the node is registered. |
| Node, mining-worker and payout-address settings | While the node or your account exists, then as for your account. Addresses on payout records are kept with those records. |
| Pool share records (hash and metadata), test results | 12 months |
| Audit log | 2 years. Sign-in link request rows: 7 days (as in the rate-limit row above). |
| Server access logs (including IP addresses) | 14 days |
| Application logs | 14 days |
| Database backups | 14 days |
| Support emails | 2 years after our last reply, unless we need them longer for a legal claim. |
| Prompt and completion content | Not stored |
| Chat history | Only in your browser. You decide. |
| Data on public blockchains | Permanent. Neither we nor anyone else can delete it. |
12. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy;
- correct data that is wrong;
- delete your data ("right to be forgotten");
- restrict how we use your data;
- object to uses based on our legitimate interests;
- data portability: get the data you gave us in a machine-readable format.
You can revoke API keys and sign out of all sessions yourself in the console. For anything else, email privacy@pearlsafe.xyz from the address on your account. We answer within one month. We may need to check that the request comes from you.
Some limits apply:
- We cannot give you or delete content we never stored, such as your prompts and completions.
- We cannot read or delete your chat history. It is in your browser.
- We must keep financial records for as long as the law requires, even after you delete your account.
- We cannot change or delete data on public blockchains.
You can also complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority in the EU country where you live or work.
Automated decisions. We do not make decisions about you based only on automated processing that have legal or similarly significant effects. Our systems do automatically limit request rates, and our pool automatically blocks a mining worker for a short time if too many of its shares are invalid. These are temporary safety measures. If you think one was applied to you wrongly, email us and a person will review it.
13. Security
What we do:
- Encrypted connections (TLS) to our website, API, mining pool and node service. GPU nodes connect to us over encrypted connections.
- API keys, session tokens and sign-in tokens are stored only as one-way hashes.
- Sign-in links work once and expire after 15 minutes.
- Our cookies are host-only, sent only over encrypted connections, and not readable by scripts.
- Logs contain no content. Access logs drop headers and query strings.
- Each GPU node proves its identity with its own key when it connects, and signs its usage receipts.
- Our mining pool keeps only a hash of each share.
- Our servers sit behind a firewall that allows only the ports we need, with key-only remote login and rate limits.
- A person approves every payout batch. Our systems never sign USDC payouts on their own.
No system is perfectly secure. If a personal data breach puts you at risk, we will tell you and the regulator as the law requires.
14. Children
Pearl Compute is not meant for children. You must be at least 18 to create an account. We do not knowingly collect data from anyone under 18.
15. Changes to this policy
We will post changes on this page and update the date at the top. If a change is material, we will email account holders at least 30 days before it takes effect, unless the law requires us to make the change sooner.
16. Contact
Extra Watts B.V., Herengracht 420, 1017 BZ Amsterdam, Netherlands. Privacy: privacy@pearlsafe.xyz. Legal: legal@pearlsafe.xyz. General: hello@pearlsafe.xyz. Security: security@pearlsafe.xyz.