ExeFast Privacy Policy

Last Updated: July 21, 2026

EXEFAST INC, a Florida benefit corporation ("ExeFast," "we," "us," or "our") explains here how we collect, use, disclose, retain, and protect personal information when you use the ExeFast platform, websites, applications, APIs, AI agents, and related services (the "ExeFast Platform"), and your rights and choices.

This Policy does not apply to information processed independently by third parties (e.g., Stripe, Thunes, Google, Anthropic, OpenAI, OpenRouter, and underlying model providers, WhatsApp, Telegram, or our verification partners), each of which maintains its own privacy policy. For privacy inquiries or to exercise your rights, contact privacy@exefast.ai. Where the ExeFast Platform is offered to users in the EEA or UK, we have appointed representatives under Article 27 of the EU GDPR and the UK GDPR; their contact details are in Section 10 (Contact). Our primary data processing occurs in the United States.

1. Information We Collect

You provide:

Collected automatically: IP address, device and browser type, identifiers, access times, features used, API and inference usage metadata (volume, duration, success/failure), error and performance data, and essential cookies for authentication and security (analytics/performance cookies subject to consent where required). Approximate location is derived from IP for fraud prevention and compliance with our launch list; we do not collect precise geolocation unless you enable it for a feature.

We use cookies and similar technologies as described in our Cookie Policy. Where required (for example, in the EEA and UK), we set non-essential cookies only with your consent, collected through a consent banner, and you can change your choices at any time via the banner or your browser settings. We honor recognized opt-out signals, including Global Privacy Control (GPC), where applicable law requires.

From third parties: verification results and watchlist outcomes from verification partners; transaction and payout status from payment providers; transient inference context routed through OpenRouter to model providers; message content and metadata from messaging providers where you use those channels; and aggregated or pseudonymized analytics from infrastructure providers.

We generally do not collect sensitive personal information except identity/verification data in the payout context, which is used only for verification, fraud prevention, tax, and regulatory purposes and is not sold or used for advertising.

Personal data you process through the Services (our role as processor)

When you use Gig, custom AI agents, or the ExeFast API to process personal data about third parties (for example, your own customers, contacts, or end-users handled by an agent or over a messaging channel), you act as the controller of that data and ExeFast acts as your processor, processing it on your documented instructions to provide the Services. You are responsible for providing any required notices to, and obtaining any required consents from, those individuals, and for having a lawful basis and the authority to process their data through the Services. Where the GDPR, UK GDPR, or similar laws apply, our Data Processing Addendum (DPA) governs this processing, is available at legal@exefast.ai, and prevails over this Policy for such processor processing.

2. How We Use Information

We use personal information to: create, secure, and manage your account; provide and improve AI agents, Gig, the ExeFast API, runtime environments, and related features; process subscriptions and Referral Program rewards (via payment providers); deliver inference results (transient routing to no-retention model providers); perform identity/payout verification, fraud prevention, sanctions screening, tax reporting, and other legal obligations; enforce our Terms and Acceptable Use Policy and investigate abuse; monitor and improve security, reliability, and performance; analyze usage in aggregated or pseudonymized form to improve the ExeFast Platform; and send transactional communications (which you cannot opt out of) and, with opt-out, promotional messages.

Where required (e.g., GDPR), our legal bases are performance of a contract, legitimate interests (security, fraud prevention, improvement), legal obligation, and consent (which you may withdraw).

Inference. When you run Gig, custom AI agents, or use inference, prompts and context are transiently routed via OpenRouter to model providers (e.g., Google, Anthropic, OpenAI) under no-retention, no-training terms; any provider safety/security retention is limited (typically no more than 30 days). We do not retain raw model inputs or outputs beyond the transient session needed to return results, except aggregated analytics or legally required logs.

3. How We Share Information

We do not sell personal information or share it for cross-context behavioral advertising. We share only with: identity and verification partners; payment and banking providers (Stripe, Thunes) for transactions and payouts; cloud and inference providers (Google Cloud; OpenRouter and model endpoints on a transient, no-retention basis); analytics, monitoring, and support tools under data-processing agreements; and professional advisers under confidentiality. We also disclose to comply with law or lawful requests, to protect rights, property, or safety, and in a merger or asset sale (with notice and successor obligation to honor this Policy). Messaging and voice providers process the content and metadata necessary to deliver those channels under their own policies. We may use and share aggregated or de-identified data that does not identify you. A current list of the sub-processors we engage to process personal data is available on request at privacy@exefast.ai.

4. Data Residency and Security

Primary storage is in the United States (Google Cloud, us-central1 or equivalent U.S. regions). We do not intentionally store personal information outside the U.S. except for transient inference routing or as needed to provide the service through third-party providers. We apply reasonable technical, administrative, and physical safeguards (encryption in transit and at rest where feasible, access controls, logging, monitoring, vendor due diligence). No system is fully secure; you are responsible for safeguarding your credentials and API key and for reporting suspected incidents. We notify affected users and regulators of confirmed incidents as required by law.

5. Retention

We retain personal information only as long as needed for the purposes collected, to meet legal obligations, resolve disputes, and enforce agreements:

On a deletion request, we delete or de-identify information no longer required, subject to carve-outs for legally required retention, fraud prevention, and de-identified or backup data.

6. Your Rights

Depending on your location, you may have rights to access, correct, delete, and port your information, to opt out of sale/sharing, to limit use of sensitive information, and to non-discrimination - and, under GDPR/UK GDPR, to restriction, objection, withdrawal of consent, and to lodge a complaint with a supervisory authority. To exercise rights, contact privacy@exefast.ai or use in-platform tools; we verify identity and respond within the time your jurisdiction requires (typically 30-45 days). If we decline a request, you may appeal by replying to our decision or emailing privacy@exefast.ai. Rights are subject to legal exceptions (including required retention of verification, tax, and compliance records). You may opt out of promotional messages at any time; transactional messages continue.

Automated decision-making. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. We use automated tools for fraud, abuse, and risk detection (for example, anti-fraud signals and payout holds described elsewhere in this Policy and our Terms); where such a measure significantly affects you, you may request human review by contacting privacy@exefast.ai.

7. International Users, Transfers, and Channels

By using the ExeFast Platform you understand your information is processed in the United States, where laws may differ from your home jurisdiction. For transfers from the EEA, UK, Switzerland, or similar jurisdictions, we rely on appropriate safeguards such as Standard Contractual Clauses (or the UK Addendum), adequacy decisions, or your consent where required. If you use integrated messaging or voice channels (WhatsApp, Telegram, telephony), your messages and metadata are processed by those providers under their own policies and may involve cross-border processing outside our control. Service availability and region-specific measures are governed by our launch list; users in non-approved regions may have restricted functionality.

8. Children

The ExeFast Platform is not directed to children under 18 (or the age of digital consent in your jurisdiction). We do not knowingly collect personal information from children under that age. If we learn we have, we delete it promptly; contact privacy@exefast.ai.

9. Changes

We may update this Policy and will provide notice of material changes (email, in-app notice, or an updated "Last Updated" date). Continued use after the effective date constitutes acceptance.

10. Contact

privacy@exefast.ai EXEFAST INC, 1200 Brickell Ave, Suite 800, Miami, FL 33131, United States

EU GDPR Article 27 Representative: Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria, office@prighter.com. EEA users may contact our EU representative on any matter relating to the processing of their personal data.

UK GDPR Representative: Prighter Ltd, 20 Mortlake High Street, London, SW14 8JN, United Kingdom, office@prighter.com. UK users may contact our UK representative on any matter relating to the processing of their personal data.

Data Protection Officer: For all privacy matters, contact privacy@exefast.ai. Our EU representative under Article 27 is Prighter EU Rep GmbH (details above).