← Back to Home
Privacy Policy
1. Introduction
EQUALA is committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR) for users in the European Economic Area (EEA). This policy explains how we collect, use, and protect your data while ensuring transparency, security, and user control.
2. Data We Collect
We collect only the minimum information necessary to operate the Platform:
- Account Information: Email address, full verified name, and basic profile details (for registration, authentication, and compliance).
- Project Data: Collaboration history, files, messages, and contributions created on the Platform.
- Usage Data: Operational logs for security, performance monitoring, and fraud prevention.
- Metadata for Secret Rooms: Minimal operational logs (e.g., timestamps, user IDs) to ensure platform functionality. Content remains fully client-side encrypted and entirely inaccessible to EQUALA.
We do not collect unnecessary personal data and we never sell your data to third parties.
3. AI Ecosystem & Data Processing
EQUALA operates as a multi-model ecosystem designed for maximum flexibility, privacy, and user control. Data processing occurs through the following channels:
3.1 Integrated Models (Third-Party Cloud Providers)
Data is handled according to the privacy standards of the respective cloud provider’s infrastructure (e.g., enterprise-grade cloud providers). Current Infrastructure operates on enterprise cloud setups, and the privacy standards of the respective provider apply to any data routed through them.
3.2 Proprietary Models (Future Integration)
EQUALA plans to integrate proprietary AI models (e.g., Aegis, Veritas) in future phases. These models will operate within our secure infrastructure for Standard/Public and Semi-Private Projects only.
- No Access to Secret Rooms: Proprietary models will not have access to or process content in Secret Rooms unless explicitly uploaded or interacted with by users.
- Data Security: All data processed by proprietary models remains strictly within EQUALA’s secure cloud environment.
3.3 User-Provided AI (BYOAI / Personal AI)
Users may integrate their own external AI models (Bring Your Own AI / Personal AI) for exclusive use within their projects.
- Scope of Use: Personal AI models may be used in Public, Semi-Private, and Secret Rooms, subject to the same encryption and zero-knowledge policies as other content in those rooms.
- DU-RENA LLC’s Role: DU-RENA LLC acts only as the interface provider and has no access to, visibility over, or responsibility for the data exchanged through user-provided models.
- User Responsibility: Users are solely responsible for the behavior, compliance, and security of their Personal AI models under all applicable laws, including GDPR.
- Security Requirements (Mandatory Malware Scan):
- Mandatory ClamAV Scan: All uploaded models must pass a local ClamAV scan before activation across all project types, including Secret Rooms.
- VirusTotal API Prohibition: The use of the VirusTotal API is strictly prohibited for Secret and Semi-Private projects due to data leakage risks. It remains optional for Public projects only, requiring explicit user consent.
3.4 Third-Party Enterprise Models (Guest AI)
External companies may apply to host specialized models (Guest AI) on the Platform. Such models are clearly labeled and subject to the privacy terms of the providing entity.
4. Zero-Knowledge Protection (Secret Rooms)
Content created in Secret Rooms is encrypted client-side before transmission. DU-RENA LLC does not have access to the content of these communications.
- Encryption Keys & User Responsibility: Users must securely store their encryption keys. EQUALA cannot recover or reset encryption keys under any circumstances. If access is lost, EQUALA cannot assist. Keys are held exclusively by room participants.
- No AI Access: No AI models provided natively by EQUALA (including future proprietary models like Aegis/Veritas) or third-party providers have access to or process content in Secret Rooms.
▲ Note: Due to our zero-knowledge structural design, even in the event of a valid legal request, EQUALA cannot access or provide Secret Room content.
5. Project Types & Access Control
5.1 Public Projects
Visibility: Fully visible to all users on the platform. Any user can join and contribute. Users may share project details outside the platform unless restricted by the Creator.
5.2 Semi-Private Projects
Visibility: Project descriptions and required skills are visible to all. Participation is restricted to users invited or approved by the Creator through the application process. External sharing of project details or screenshots is strictly prohibited without explicit permission.
5.3 Secret Rooms
Visibility: Completely private. Visible only to invited participants. Sharing any project details, screenshots, or information outside the room is strictly prohibited. All content is client-side encrypted.
6. Project Completion & Downloads
- Project Completion Declaration: Only Creators can declare a project as complete to download final files.
- Co-Creator Evidence: Co-creators receive a cryptographically signed record of their contributions as unalterable proof of participation for dispute resolution.
- Multi-Creator Projects: If a project has multiple designated Creators, all Creators' encryption keys are required simultaneously to download final project files, ensuring collective consent.
7. Immutable History
EQUALA maintains an immutable, append-only record of all project activity. This core feature protects creator rights, resolves attribution disputes, and ensures transparency and fairness. Users are informed of this policy upon registration.
8. Private Chat with AI Models
Users may engage in private chats with AI models for advice or brainstorming.
- No Memory: Private chats do not retain memory or context between separate sessions.
- Automatic Deletion: All private chat data is automatically deleted after 30 days and is not stored in the immutable project history ledger.
9. Cookies
We use only essential session cookies and security tokens required for secure authentication. We do not use tracking, analytic, or advertising cookies.
10. Data Retention
- Account Data: Retained for the duration of your active account.
- Project History: Retained permanently as part of our immutable record policy to guarantee collaboration integrity.
- Private Chat Data: Automatically deleted within 30 days of creation.
- Upon Account Deletion: Personal identifiers (PII) are removed from our active systems within 30 days of request, except where retention is mandated by law.
11. Your Rights (GDPR & Global)
Regardless of your location, you hold the following rights regarding your data:
- Right to Access & Portability: Request a copy of your personal data in a structured, machine-readable format (JSON).
- Right to Correct: Update inaccurate or incomplete data.
- Right to Erasure (GDPR Article 17): Request deletion of your personal data. Upon a valid request, all personally identifiable information (PII) will be permanently removed from our systems within 30 days.
Treatment of Ledger Data Upon Erasure: To preserve the chronological integrity of project collaborations and protect other co-creators from injustice, your contributions, messages, and logs will remain entirely intact in the unalterable ledger, but your identity will be irreversibly anonymized and displayed strictly as "Anonymous User" ("Ανώνυμος Χρήστης").
Treatment of Conduct Reports Upon Erasure: Reports filed against an account for abusive or toxic behavior (see Terms of Service §6) are retained strictly for platform security and integrity. All PII associated with these reports will be permanently deleted, and the history will refer strictly to an Anonymous User.
To exercise any of these rights, contact us at [email protected].
12. Security
We implement industry-standard security measures, including Encryption in Transit (TLS), Encryption at Rest, strict internal access protocols, and client-side End-to-End Encryption for Secret Rooms.
13. Legal Basis for Data Processing (GDPR Article 6)
- Contractual Necessity (Article 6(1)(b)): To provide and maintain our core services.
- Legitimate Interest (Article 6(1)(f)): For platform security, abuse prevention, and infrastructure integrity.
- Consent (Article 6(1)(a)): For optional, user-initiated interactions.
14. Data Protection Officer (DPO)
As a Beta-phase B2B platform, EQUALA does not process data on a large scale nor engage in systematic monitoring of special categories of data that would mandate a DPO under GDPR Article 37. For any data protection inquiries, contact us directly at [email protected].
15. Changes to This Policy
Significant changes to this policy will be communicated via email or prominent platform notifications. Continued use of EQUALA after updates constitutes acceptance of the modified policy.
16. Contact
DU-RENA LLC
30 North Gould Street, Sheridan, WY 82801, USA
Email: [email protected]
© 2026 EQUALA. All rights reserved. Operated by DU-RENA LLC.