Privacy Policy
Last updated: September 21, 2026
This Privacy Policy explains how S&T Integrated Solutions LLC, doing business as Science & Technology Integrated Solutions ("SciTech," "we," "us," or "our") collects, uses, shares, and protects personal information when you visit www.scitechsolutions.io, email us, create an account, use our APIs, purchase credits, configure BYOK, or otherwise use our services. www.scitechsolutions.io is operated by S&T Integrated Solutions LLC, doing business as Science & Technology Integrated Solutions.
This Privacy Policy applies to personal information we control as a business. When we process customer-provided data on behalf of a customer under a separate agreement, the customer controls that data, and the applicable customer agreement and Data Processing Agreement at https://www.scitechsolutions.io/dpa govern our processing.
Meter-SPW is delivered as a separate hosted service at https://spw.scitechsolutions.ai and publishes its own Privacy Policy, written from that service's database schema. Where this policy and the Meter-SPW Privacy Policy describe the same data differently, the Meter-SPW Privacy Policy governs data held by that service. Nothing on this page weakens a commitment made there.
1. Information We Collect
We may collect information you provide directly, information collected automatically, information generated through product use, and information from third parties. This may include:
- name, email address, company name, job title, and any other business contact details you choose to include when you write to us. This website has no forms — if you contact us, we hold the message you sent and the address you sent it from;
- account information: display name, account type (individual or organization), organization membership, and admin or user role;
- authentication data: your password, stored only as an Argon2 hash that we cannot read and cannot recover — only reset; your two-factor secret; and your recovery codes, stored hashed, which is why they are shown to you exactly once;
- single sign-on identity: if you sign in with Google or GitHub, the provider name and that provider's stable user id for you. We do not store, and never request, a long-lived token for your Google or GitHub account;
- API keys, stored as a short public prefix plus an Argon2 hash. The full key is shown once at creation and is not recoverable afterwards;
- per-tenant webhook secrets, encrypted at rest with AES-256-GCM;
- BYOK provider keys, encrypted at rest with AES-256-GCM and never stored in plaintext. The encryption key is held only in the environment, never in the database or repository. Unlike your SciTech API key, a provider key has to stay usable in order to route your requests, so it is encrypted rather than hashed;
- provider-key metadata, BYOK configuration, model preferences, routing policies, safety policies, account settings, and service preferences;
- a SHA-256 hash of each prompt — never the prompt text itself on the ordinary call path — plus requested and selected models, routing reasons, latency, estimated savings, token counts, and other audit metadata where processed through Meter-SPW. The hash can confirm that two calls were identical; it is not your text and does not contain it. Meter-SPW also caches model answers and, for the small fraction of flagged calls, may temporarily retain prompt and answer text for human review as described in Sections 4 and 8;
- billing records: a credit ledger of purchases, comps and usage deductions; grace-window state; which balance alerts have already been sent; and the queue of transactional emails;
- transaction details, invoices, payment-processor identifiers, taxes, fraud and risk signals, chargeback data, and purchase history. We never see your payment card — checkout is hosted by Stripe and card details are entered on Stripe's systems, not ours;
- IP address, request metadata, and server log data generated when you reach our services, including metadata processed in transit by our CDN and security provider;
- support requests, feedback, and messages you send us;
- information from our hosting, security, payment, and email providers as needed to operate, bill for, and secure the services.
2. What We Do Not Do
This website uses no analytics, advertising, session-recording, or cross-site tracking technology. Meter-SPW uses Cloudflare's lightweight edge analytics script to report aggregate page-load timing. That script does not use cookies to track users between sites. None of our properties uses an advertising pixel, builds an advertising profile, or sells personal information.
We do not build advertising or behavioural profiles. We do not sell personal information and we do not share it with data brokers. We do not use your prompts, outputs, or other customer content to train AI models.
We never see your payment card. Checkout is hosted by Stripe, and card details are entered on Stripe's systems rather than ours.
3. How We Use Information
We use information to:
- provide, operate, route, secure, support, troubleshoot, and maintain the website and services;
- create and manage accounts, organizations, API access, BYOK configuration, subscriptions, credits, billing, trials, promotions, promotional benefits, and user permissions;
- process payments, prevent fraud, enforce credit rules, investigate abuse, and manage refunds, chargebacks, taxes, and usage limits;
- route prompts to configured model providers, return outputs, evaluate routing decisions, measure cost and latency, and enforce safety policies;
- provide customer support, respond to inquiries, deliver requested information, and communicate about service matters;
- send transactional email — balance alerts, password resets, receipts, security notices, and account or service messages. We do not send marketing email;
- monitor, detect, investigate, and prevent spam, fraud, abuse, unauthorized access, scraping, red-team abuse, prompt-injection abuse, malware, security incidents, and policy violations;
- comply with legal obligations, enforce agreements, protect rights, and respond to lawful requests;
- monitor reliability, performance, errors, and capacity from our own server-side logs and, for Meter-SPW, aggregate page-load timing reported by Cloudflare's edge analytics;
4. Customer Data and Product Data
Customer content, prompts, outputs, system data, telemetry, logs, configurations, provider-key metadata, routing decisions, model usage data, latency data, cost data, token counts, safety results, and other information processed through Meter-SPW, APIs, BYOK, or related services are subject to the applicable customer agreement.
We use customer data only to provide requested outputs and routing results; maintain contracted audit records; provide, secure, support, troubleshoot, monitor, and maintain the contracted services; comply with law and our agreements; and prevent abuse. We do not use customer-provided data for advertising, marketing, training AI models, developing unrelated products, or improving generalized models or services. We may improve the services using operational metrics only after they have been aggregated or de-identified so they cannot reasonably identify a customer or person or reconstruct customer content.
On Meter-SPW's ordinary call path, the per-call audit record retains a SHA-256 hash of your prompt — never the prompt text itself — together with the requested and selected models, routing reason, token counts, estimated savings, and latency. Meter-SPW caches the model's answer for 24 hours in memory and up to seven (7) days in the shared cache. The cache key includes your account id, so a cached answer is never served to another account. Cached outputs are stored as the model returned them, and an output can carry the substance of the prompt behind it.
Meter-SPW has two prompt-text exceptions. The first: for the small fraction of calls flagged because its checks disagreed, a short-lived human-review buffer may retain the prompt and answer for up to seven (7) days. The row is deleted when review concludes or the seven-day cap expires, whichever occurs first. Deletion from the live database does not remove copies already present in database backups, which expire on their own retention cycle.
The second is a benchmark set you upload yourself under Settings → Routing profile in the Meter-SPW dashboard. Its prompts are stored as text so the service can re-run them for you under a routing profile; they are kept until you delete the set or your account, and used for nothing else. Running a benchmark set relays each prompt to your providers as an ordinary request, billed as one.
Meter-SPW may transmit prompts and related data to third-party model providers in order to route requests and return outputs. In BYOK mode, customer provides provider API keys, customer has the direct provider relationship, customer controls provider account settings, and SciTech routes requests using customer-configured keys. Model providers process data under their own terms, privacy policies, and account settings, which may include their own retention or training practices. We do not control how third-party model providers handle data.
In most cases, Meter-SPW sends your prompt to one LLM model. In the very rare cases where Meter-SPW has to retry, the same prompt is sent to more than one model, and those models may be operated by more than one provider — each under its own terms, as described above.
Where you hold a key for it, the model that answers may also belong to a different provider than the one you named: storing a provider key with Meter-SPW is your consent for it to serve your requests through that provider when it is cheaper. You can switch this off at any time under Settings → Cross-vendor routing in the Meter-SPW dashboard, after which your requests stay with the provider you named.
5. How We Share Information
We do not sell personal information and we do not share it with data brokers. We share information only as needed to run, secure, and bill for the services:
- Google Cloud — hosting and backups. The services run in the United States (us-south1); backups are stored across us-south1 and us-east1;
- Cloudflare — sits in front of the services for TLS, DDoS protection, and filtering, so it processes request metadata in transit. For Meter-SPW it also provides the Turnstile sign-up/sign-in challenge and a lightweight edge analytics script that reports aggregate page-load timing without using cookies to track users between sites;
- Stripe — payments, as the merchant of record for every purchase of credit. Stripe holds your card details and billing address, issues the receipt, and calculates, collects and remits any tax due; we receive the result and the amount, and hold only the resulting credit-ledger entry;
- Proton Mail — delivers transactional email such as balance alerts, password resets, and receipts;
- Google and GitHub — only if you choose to sign in with them, and only to confirm your email address at that moment;
- third-party model providers, where Meter-SPW routes prompts or related data to those providers on your instruction;
- customer administrators and authorized users within your organization, according to your account settings;
- professional advisors such as attorneys, accountants, auditors, and insurers, under confidentiality obligations;
- government authorities, regulators, courts, law enforcement, or other parties when required by law or necessary to protect rights, safety, and security;
- a successor, affiliate, investor, or counterparty in connection with a merger, financing, acquisition, reorganization, due-diligence process, asset sale, bankruptcy, or similar transaction.
6. Cookies and Local Storage
This website sets no cookies and stores nothing in your browser's local storage.
The Meter-SPW dashboard sets one signed-in session cookie, marked HttpOnly and SameSite=Strict, which expires after 24 hours. Cloudflare's Turnstile challenge sets the data it needs to protect sign-up and sign-in from automated abuse. Cloudflare also injects the Meter-SPW edge analytics script described above; it reports aggregate page-load timing and does not use cookies to track users between sites.
We use no advertising pixels, session-replay tools, or cross-site behavioural tracking on any of these properties. If that changes, we will update this policy and provide any notice or consent mechanism the law requires before the change takes effect.
7. Email and Marketing Choices
We do not send marketing email. The only email we send is transactional: balance alerts, password resets, receipts, security notices, and messages about your account or a service issue. There is no marketing list, so there is nothing to unsubscribe from.
If we ever introduce marketing email it will be opt-in, and every message will carry an unsubscribe link. To ask about email you have received from us, contact privacy@scitechsolutions.ai.
8. Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Privacy Policy, including to provide services, maintain accounts, support customers, maintain business records, comply with legal obligations, prevent fraud and abuse, resolve disputes, enforce agreements, and protect rights and security.
Meter-SPW retains its per-call audit record, including the prompt hash and routing and billing metadata, as evidence behind each charge. Model answers remain in memory for 24 hours and may remain in the shared cache for up to seven (7) days. Prompt and answer text held in the flagged-call review buffer is deleted when review concludes or after no more than seven (7) days, although copies already present in database backups expire on the backup cycle rather than being edited in place.
Two categories are deliberately kept even after an account is deleted, and it is fair that you know why before you sign up. The credit ledger is append-only: a ledger that can be rewritten is not a financial record. The Meter-SPW per-call audit record is kept with it, because it is the evidence behind every charge and behind your right to dispute one. Neither contains your prompt text. Both are retained as evidence and identify an account id rather than you once the account is gone.
Billing, tax, compliance, security, and business records may be retained longer where required or permitted by law. When information is no longer needed and is not part of an append-only record, we delete, destroy, de-identify, or anonymize it as permitted or required by law.
9. Data Security
Traffic is encrypted in transit. Passwords and API keys are stored only as Argon2 hashes — we cannot read them and cannot recover them, only reset or rotate them. Two-factor recovery codes are stored hashed, which is why they are shown to you exactly once. Per-tenant webhook secrets are encrypted at rest with AES-256-GCM. Application credentials are held in Google Secret Manager rather than in files on a server. BYOK provider keys are encrypted at rest with AES-256-GCM and never stored in plaintext; their encryption key is held only in the environment, never in the database or repository.
Our wider program includes access controls, least privilege, MFA, monitoring, logging, vulnerability management, incident response, security review, and third-party security services. Access to production is restricted to SciTech personnel who need it.
Our SOC 2 program is in progress. Unless expressly stated in writing, we do not claim current SOC 2 certification. No system is immune to compromise. If a breach affects your data, we will notify you at your account email without undue delay. You are responsible for protecting your credentials, API keys, provider keys, devices, networks, systems, applications, users, and data.
10. International Transfers
We process and store information in the United States. The services run in Google Cloud's us-south1 region, and backups are stored across us-south1 and us-east1. Our CDN and security provider may process request metadata in transit from locations closer to you.
If information is transferred from the EEA, United Kingdom, or Switzerland to a country that has not received an adequacy decision, we use appropriate safeguards where required by applicable law, such as Standard Contractual Clauses.
11. Your Rights and Choices
Depending on where you live and applicable law, you may have rights to access, correct, delete, port, restrict, or object to processing of personal information; withdraw consent where processing is based on consent; opt out of certain sale, sharing, targeted advertising, or profiling activities where applicable; appeal a denied request; or lodge a complaint with a data protection authority.
You can export your own audit history and billing ledger from the dashboard at any time. To request deletion of your account, contact privacy@scitechsolutions.ai. Deleting an account removes your profile, single sign-on links, API keys, stored provider keys, and contact details immediately; the credit ledger and the Meter-SPW per-call audit records described in Section 8 are retained as evidence and are no longer linked to a live account.
We do not discriminate against you for exercising privacy rights. To make a request, contact privacy@scitechsolutions.ai. You may use an authorized agent where permitted by law. We may verify your identity and authority before fulfilling a request, and we will respond within the period the applicable law requires.
12. GDPR Legal Bases
If you are located in the EEA, United Kingdom, or Switzerland, we process personal data under one or more of the following legal bases:
- Contract: to provide services, accounts, subscriptions, credits, BYOK configuration, APIs, support, and requested information;
- Legitimate interests: to operate, secure, improve, and protect the website and services, balanced against your rights;
- Consent: where we ask for it. We do not rely on consent for advertising or cross-site tracking, which we do not conduct. This website sets no cookies; Meter-SPW uses a strictly functional session cookie, Cloudflare Turnstile for abuse prevention, and Cloudflare's cookie-free edge analytics for aggregate page-load timing;
- Legal obligation: to comply with applicable law, tax, accounting, legal requests, and regulatory obligations.
For GDPR purposes, S&T Integrated Solutions LLC, doing business as Science & Technology Integrated Solutions, is the controller of personal information collected through the website where we determine the purposes and means of processing. For customer data processed under a customer agreement, our role may be processor or service provider as described in the applicable agreement and DPA.
13. U.S. State Privacy Disclosures
Residents of certain U.S. states, including California, Colorado, Connecticut, Texas, Virginia, and others, may have specific rights. For the categories of personal information described in Section 1, we collect them for the business and commercial purposes described in Section 3 and disclose them to the categories of recipients described in Section 5.
We do not sell personal information, and we do not "share" it for cross-context behavioural advertising, targeted advertising, or profiling as those terms are defined under applicable state law. Meter-SPW's aggregate page-load timing does not track users between sites or support targeted advertising, so we do not conduct an activity that requires an advertising opt-out. We do not use or disclose sensitive personal information for purposes that would require a right to limit.
To exercise state privacy rights or appeal a denied request, contact privacy@scitechsolutions.ai.
14. Children's Privacy
The website and services are intended for business and professional audiences and are not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact privacy@scitechsolutions.ai.
15. Third-Party Links and Services
The website and services may link to, rely on, or integrate with third-party websites, platforms, tools, models, and payment processors. We are not responsible for third-party privacy or security practices. Their policies apply to their services.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted with a revised "Last updated" date. If we make material changes, we will provide additional notice where required by law. Your continued use after an update means the revised policy applies going forward.
17. Contact
For privacy requests, data-subject requests, deletion requests, or complaints, contact privacy@scitechsolutions.ai. For security matters, contact security@scitechsolutions.ai. For billing, credit, or ledger questions, contact billing@scitechsolutions.ai. For general inquiries, contact info@scitechsolutions.ai. For sales, contact sales@scitechsolutions.ai.