This Privacy Notice explains how ExcursionPass Inc., the Delaware corporation that operates Tensor Archive (“ExcursionPass,” “Tensor Archive,” “we,” “us,” or “our”), collects, uses, discloses, and retains personal information when you:
- visit tensorarchive.ai or another Tensor Archive page;
- download or use Tensor Archive Local;
- start a trial, purchase, activate, or use a license;
- use protected planning, updates, public-model downloads, or the Tensor-to-Tensor Transport network;
- submit an early-access or other form; or
- contact us for support, legal, privacy, or business purposes.
This Notice applies to individuals using Tensor Archive personally or on behalf of an organization. An Enterprise agreement, data-processing agreement, or just-in-time notice may supplement this Notice for a specific deployment or feature.
1. Who Is Responsible for Your Information
ExcursionPass Inc. determines the purposes and means of the personal information processing described in this Notice.
ExcursionPass Inc. — Tensor Archive
2035 Sunset Lake Road, Suite B-2
Newark, Delaware 19702
United States
Email: hello@tensorarchive.ai
2. Key Privacy Points
- Tensor Archive is local by default. Model weights, archive contents, and generated outputs normally remain on your Computer unless you direct a network or third-party operation that needs to transfer them.
- Stripe processes complete payment-card details. Tensor Archive does not receive your complete card number or card security code.
- Desktop product analytics are enabled by default, use a random identifier separate from the license, and can be disabled in Settings.
- Desktop analytics do not include model weights, archive contents, model or repository names, file names, local paths, content hashes, email, or license identity. Raw desktop analytics events are retained for no more than 90 days.
- Protected planning processes bounded technical measurements and opaque identifiers, not model weights, model names, repository names, local paths, or model-file hashes.
- T2T infrastructure necessarily processes network addresses and transfer metadata when T2T is used. The application is not intended to publish a user’s personal network information in the user dashboard.
- We do not sell personal information for money.
3. Information We Collect
3.1 Information you provide
We may collect:
- your email address and optional company name when you request early access, product information, an invitation, or other communications;
- your name, email, billing address, tax information, and other checkout information that Stripe makes available to us;
- support messages, attachments, diagnostic files, and other information you choose to send us;
- Enterprise inquiries, organization information, deployment requirements, and license-eligibility information; and
- copyright, legal, security, and privacy requests and the information needed to verify and respond to them.
Do not send model weights, confidential model data, authentication secrets, private keys, or sensitive personal information to support unless we specifically request it through an approved secure channel.
3.2 Website and download information
When you visit the website or download the Software, we and our providers may automatically process:
- IP address and approximate location inferred from it;
- browser, operating system, device type, language, and screen information;
- pages viewed, referring page, timestamps, navigation, and interactions;
- cookie and analytics identifiers;
- UTM campaign, source, and medium values;
- requested file, platform, application version, download source, completion, and related delivery information; and
- request headers, security events, error data, and network logs.
Our public-download service also maintains aggregate daily counts by date, version, platform, and source. Those aggregate metrics do not contain an email, license identifier, installation identifier, IP address, or user agent.
3.3 Early-access and invitation information
If you submit an early-access or invitation form, we may store:
- email and normalized email;
- optional company;
- form source and source path;
- UTM campaign, source, and medium;
- consent version and timestamp;
- pending, invited, accepted, or unsubscribed status;
- invitation-token hash, issue time, expiration, platform, and download count; and
- created, updated, invitation, acceptance, and unsubscribe timestamps.
The application database for these forms is designed not to store the form submitter’s IP address, user agent, or referrer in the lead record. Hosting and security providers may still process ordinary request logs.
3.4 Payment and transaction information
Stripe hosts the payment page and processes payment credentials. Stripe may collect and provide us with:
- customer name, email, billing address, country, and tax information;
- Stripe customer, Checkout Session, and Payment Intent identifiers;
- product, amount, currency, tax, payment, refund, dispute, and fraud status;
- card type and limited payment-method details, such as brand and last four digits, where made available by Stripe;
- acceptance of the Tensor Archive Terms at checkout; and
- purchase, payment, refund, dispute, and acceptance timestamps.
Our checkout service also stores an internal checkout-attempt identifier, a hash of the temporary claim token, a pseudonymous installation hash, checkout status, and expiration timestamps. We do not receive or store the complete payment-card number or card security code.
3.5 License, activation, and trial information
To issue licenses, enforce the named-user and Computer limits, prevent repeated trials, and protect against piracy, we may process:
- random installation identifiers, stored on the server in hashed or otherwise pseudonymous form;
- device public keys, device-key fingerprints, and the general assurance type of the device key;
- license, entitlement, order, and product identifiers;
- product tier, entitlement status, maximum activations, and update-end date;
- activation, reissue, deactivation, trial-start, trial-expiration, refund, dispute, and revocation status and timestamps;
- signed proof nonces and security-verification results; and
- application version, build, platform, and related compatibility information.
Device public keys are used to verify that protected requests come from the activated installation. We do not need the corresponding private key, which is designed to remain protected on the device.
3.6 Protected-planning information
Pro creation and compaction use protected remote planning. Depending on the protocol version, the planning service may process:
- license and pseudonymous installation bindings;
- random, opaque session, request, target, relation, candidate, and recipe identifiers;
- selected performance profile;
- target count, candidate count, and recipe count;
- coarse size, element-count, data-type, and tensor-rank buckets;
- bounded dependency and relationship information;
- candidate encoded size, metadata size, dependency depth, and estimated restore work;
- selected recipe or candidate;
- cryptographic digests of planning protocol records;
- request, authorization, challenge, measurement, commitment, expiration, and response timestamps; and
- aggregate request, target, and candidate usage for entitlement and abuse-prevention limits.
The planning request contract is designed to reject extra fields. It is not designed to receive model weights, archive contents, model or repository names, file names, local paths, email addresses, or model-file content hashes.
3.7 Optional desktop analytics
Desktop analytics are initially enabled and may include:
- a random analytics identifier and random session identifier;
- application open and active-time events;
- the general feature used, such as analyze, archive, verify, restore, export, extract, delete, or update;
- whether an operation started, completed, failed, or was cancelled;
- event time and bounded operation duration;
- application version, build, and platform; and
- update check, availability, download, and installation results.
Before storage, the analytics and session identifiers are transformed into cryptographic hashes on the server. The analytics identifier is separate from the installation identifier used for licensing.
The desktop analytics contract rejects unexpected fields and is designed not to accept model weights, archive contents, model, repository or file names, local paths, content hashes, email, or license identity.
You may disable analytics or request deletion of that installation’s raw analytics events in the application’s Settings page. Disabling analytics does not disable operational network, update, licensing, security, or checkout communications.
3.8 T2T network information
When T2T functionality is available and used, we and our infrastructure providers may process:
- IP addresses, ports, connection information, and general network characteristics needed to route and secure transfers;
- pseudonymous installation, device-key, source, destination, session, audience, ticket, settlement, and transfer identifiers;
- device public keys and fingerprints used for authorization;
- public-model repository, revision, manifest, object, range, and transport identifiers;
- source and destination classes, eligibility, availability, and route information;
- authorization scopes, byte quotas, ticket issue and expiration times, and cryptographic signatures;
- bytes requested, transferred, verified, discarded, uploaded, or downloaded;
- timing, throughput, completion, failure, retry, and integrity information;
- contribution events, balance, level, exemptions, declined opportunities, and anti-abuse limits; and
- security, fraud, content-rights, and service-integrity signals.
T2T may technically route, cache, stage, or verify eligible public-model bytes as needed to provide a transfer. Private model data is not authorized for public-network contribution unless you deliberately use a separately supported private feature with the necessary rights and instructions.
3.9 Local application data
The Software maintains a local application directory containing items such as:
- archived content and object data;
- model-family catalogs, manifests, receipts, and verification records;
- generated or reconstructed outputs;
- local job and activity history;
- settings and analytics preference;
- random local identifiers;
- license and update state; and
- T2T cache, staging, transfer, and contribution state.
This local data remains under your control on the Computer unless a feature you select sends specific information to Tensor Archive or a third party. Removing the local application directory may delete local archives and state. Maintain independent backups before deleting it.
4. Sources of Information
We obtain personal information:
- directly from you;
- automatically from your browser, Software, Computer, and network requests;
- from Stripe and other payment, fraud-prevention, and tax providers;
- from model repositories or services you direct the Software to use;
- from an organization that purchases or manages a license for you;
- from hosting, security, analytics, distribution, support, and infrastructure providers; and
- from public authorities, rights holders, security researchers, and other parties reporting legal, security, or abuse concerns.
5. Why We Use Information
We use personal information to:
- operate, deliver, secure, troubleshoot, and improve Tensor Archive;
- provide downloads, T2T transfers, verification, restore, updates, and protected planning;
- create and administer trials, purchases, licenses, activations, update periods, and Enterprise eligibility;
- process payments, taxes, refunds required by law, disputes, chargebacks, and accounting;
- detect, investigate, and prevent fraud, piracy, repeated trials, circumvention, credential abuse, malicious content, and security incidents;
- maintain contribution balances, transfer integrity, network health, and service capacity;
- measure website and product usage and understand feature reliability;
- respond to support, privacy, copyright, legal, and business inquiries;
- send transactional messages and communications you request or consent to receive;
- enforce the Terms of Service, EULA, content rights, and other agreements;
- comply with legal, tax, accounting, sanctions, export, and regulatory obligations; and
- establish, exercise, or defend legal claims and protect users, ExcursionPass, and third parties.
We may aggregate or de-identify information and use it for analytics, security, research, product planning, and business purposes where the resulting information is not reasonably capable of being linked to an individual.
6. Cookies and Online Analytics
6.1 Google Analytics
The website currently uses Google Analytics. Google Analytics may set or read cookies and collect online identifiers, IP-derived location, browser and device information, referring pages, pages viewed, interaction events, and download events. We use this information for website audience measurement, performance, and product-download analytics.
Google processes information under its own terms and privacy documentation. Your browser settings may allow you to block or delete cookies. Google also offers a browser add-on for opting out of Google Analytics.
We do not send model weights, archive contents, license credentials, local paths, or desktop license identity to Google Analytics through our intentional website event configuration.
6.2 Current browser-signal response
Some browsers send a legacy “Do Not Track” signal. There is no uniform industry standard for that signal, and the website does not currently change its behavior in response to it.
The current website also does not automatically change its analytics behavior in response to Global Privacy Control or another universal opt-out signal. If applicable law requires us to honor such a signal for a particular processing activity, we will implement and honor the required mechanism before conducting that activity.
You can currently limit website analytics by blocking Google Analytics, blocking or deleting cookies, using a content blocker, or using Google’s analytics opt-out tool. These choices do not prevent essential hosting, security, or download-delivery logs.
6.3 Third-party collection
Our hosting, security, analytics, and payment providers may collect information about your interactions with the website and checkout. Their use of information for their own purposes is governed by their privacy notices and our applicable contracts with them.
7. When We Disclose Information
We may disclose the categories described above to:
7.1 Service providers
Providers that help us operate hosting, content delivery, databases, security, payments, fraud prevention, tax, analytics, software distribution, email, support, and professional services. Current material providers include Cloudflare, Stripe, and Google Analytics.
Service providers may process personal information only for the contracted services and other purposes allowed by applicable law and their governing terms.
7.2 Services you direct us to use
If you direct Tensor Archive to access a model repository or other third-party service, the Software may provide that service with the repository, revision, object, request, IP, authentication, and technical information necessary to perform your request. Your relationship with that service is governed by its terms and privacy notice.
7.3 Your organization
If an organization purchases, administers, or pays for your license, we may provide it with purchase, assignment, activation, usage-limit, security, support, and compliance information associated with that organizational license. We do not provide model weights or private model contents merely because an organization pays for the license.
7.4 Legal, safety, and rights protection
We may disclose information where we reasonably believe disclosure is needed to comply with law or legal process; enforce our agreements; respond to copyright, fraud, security, or abuse complaints; protect rights, safety, and property; or establish, exercise, or defend legal claims.
7.5 Corporate transactions
We may disclose information in connection with financing, due diligence, reorganization, merger, acquisition, sale of assets, insolvency, or transfer of all or part of the Tensor Archive business, subject to appropriate confidentiality and legal requirements.
8. Sale, Targeted Advertising, and Profiling
We do not sell personal information for money.
We do not use personal information to make decisions that produce legal or similarly significant effects concerning an individual. Automated security, fraud, trial-eligibility, entitlement, and license-enforcement measures may temporarily block or restrict a request, but users may contact us to contest an error.
We use Google Analytics for audience and product measurement, not to select advertisements on behalf of third-party advertisers. Depending on the configuration, provider activity, and applicable state law, disclosure to an analytics provider may be treated as “sharing” or processing for targeted advertising even where no money changes hands. You may submit an applicable opt-out request using the contact method in Section 12. We will provide and honor any additional opt-out link or browser-signal mechanism required by applicable law.
We do not offer a financial incentive in exchange for personal information. T2T contribution balances are operational network measures, not payment for personal information.
9. Retention
We retain information for no longer than reasonably necessary for the purposes described above, taking into account license duration, product security, technical operation, accounting, tax, legal, dispute, and rights-enforcement requirements.
Current intended periods and criteria include:
- Desktop analytics: raw events for no more than 90 days. Disabling analytics requests deletion of the raw events associated with that installation’s analytics identifier.
- Protected planning: detailed requests and protocol transcripts for up to approximately 24 hours; short-lived proof nonces for approximately 10 minutes. Aggregate entitlement usage may be retained with the entitlement.
- T2T authorization: availability announcements, tickets, and authorization material are generally short-lived, from seconds to minutes. Contribution events may be included in a rolling operational window currently designed around 30 days. Security, dispute, and aggregate records may be retained longer where necessary.
- Trials: expired or revoked pseudonymous installation and device-key fingerprints may be retained during the product’s operation to enforce the one-trial limit and prevent abuse.
- Paid orders, licenses, and activations: for the Commercial Lifetime of the license and afterward as necessary for accounting, tax, disputes, security, ownership records, and legal obligations.
- Early-access and communication records: until the request is fulfilled, you unsubscribe or request deletion, the information is no longer useful, or a longer period is required for legal or security purposes.
- Support and legal correspondence: for as long as reasonably needed to resolve the matter, maintain business records, and establish or defend legal claims.
- Website analytics and infrastructure logs: according to our configured analytics and security periods and provider settings, limited to what is reasonably necessary for measurement, delivery, and protection.
Deletion from active systems may not immediately remove information from encrypted backups, immutable security records, or records that must be retained by law. Such information remains protected and is removed or rendered unavailable under the applicable retention cycle.
10. Security
We use administrative, technical, and organizational measures designed to protect personal information. Depending on the system, these measures include:
- HTTPS and encrypted network transport;
- hashing or pseudonymization of installation, analytics, session, claim-token, and invitation identifiers;
- signed licenses, updates, authorizations, manifests, and receipts;
- device-bound public-key proof and protected private-key storage;
- access controls, rate limits, short-lived authorization, and replay protection;
- data minimization and rejection of unexpected telemetry and planning fields;
- separation of analytics identifiers from license identity; and
- monitoring, backup, integrity, and incident-response controls.
No security measure or transmission is completely secure. You are responsible for protecting your Computer, activation code, license materials, credentials, private keys, local models, and backups.
11. Your Privacy Choices
11.1 Desktop analytics
Use the application’s Settings page to disable desktop analytics or request deletion of that installation’s raw analytics history.
11.2 Website analytics
You may block or delete cookies, use a content blocker, or use Google’s analytics opt-out browser tool. Blocking analytics does not block essential security or delivery processing.
11.3 Communications
You may unsubscribe using the instructions in a message or contact us. We may still send non-promotional messages about a purchase, license, security issue, support request, or legal notice.
11.4 T2T controls
Use the controls available in your version of the Software to manage eligible T2T participation. Some network processing is necessary to perform a transfer you request. Disabling contribution may affect contribution balances, source eligibility, or network performance as described in the Software and Terms.
12. U.S. State Privacy Rights
Depending on where you live and whether the applicable law covers ExcursionPass, you may have the right to:
- confirm whether we process your personal information and access it;
- correct inaccurate personal information;
- request deletion;
- obtain a portable copy of information you provided;
- opt out of sale, targeted advertising, or qualifying profiling;
- limit certain uses of sensitive personal information;
- use an authorized agent; and
- appeal a decision concerning your request.
To submit a request or appeal, email hello@tensorarchive.ai with the subject “Privacy Request” and identify the state in which you live and the right you wish to exercise.
Because Tensor Archive does not require a general user account, we may need to verify your request using the email, transaction, license, installation, or other information associated with the relevant record. Do not send a complete payment-card number, device private key, or password. We may deny or limit a request where we cannot verify it or where an exception applies, and we will explain and provide an appeal route where required.
We will not unlawfully discriminate against you for exercising an applicable privacy right.
Delaware residents may contact the Delaware Department of Justice at privacy@delaware.gov if they have a complaint about a covered controller’s handling of a request.
13. California Online Privacy Disclosures
During the preceding 12 months, we may have collected the categories described in Section 3 from the sources in Section 4, used them for the purposes in Section 5, and disclosed them to the categories of recipients in Section 7. These categories may include:
- identifiers and contact information;
- payment, transaction, and commercial information;
- Internet, network, application, and device activity;
- approximate location inferred from IP address;
- professional or organizational information you provide;
- inferences limited to product, fraud, security, and eligibility status; and
- communications and content you choose to provide to support.
We do not knowingly collect legally protected classifications, precise geolocation, biometric identity templates, health information, or other sensitive personal information through ordinary product operation. Do not submit such information unless a specific authorized feature and notice requires it.
Our response to Do Not Track and third-party online collection is described in Section 6. We do not share personal information with third parties for their own direct marketing as contemplated by California’s “Shine the Light” law.
14. Children
Tensor Archive is not directed to children under 18, and a person must be at least 18 to purchase or accept the Terms. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can investigate and delete it where appropriate.
15. International Access and Processing
Tensor Archive is operated by a United States company. Information may be processed in the United States and in other jurisdictions where our service providers operate. Those jurisdictions may have different privacy laws from your location.
If you access Tensor Archive from outside the United States, you are responsible for determining whether your use is permitted in your location. Mandatory privacy rights that applicable law does not allow the parties to waive remain unaffected.
16. Changes to This Notice
We may update this Notice to reflect changes in the product, processing, providers, or law. We will post the revised Notice with a new effective date and provide additional notice where required.
17. Contact
Questions, requests, and appeals concerning privacy may be sent to:
ExcursionPass Inc. — Tensor Archive Privacy
2035 Sunset Lake Road, Suite B-2
Newark, Delaware 19702
United States
hello@tensorarchive.ai