Privacy Policy
This policy covers two separate things and deliberately keeps them apart: what happens when you visit modelion.ai, and how your traffic is processed when you use the Modelion.AI service. The data flows are not the same.
Last updated:
1. Scope
This policy covers the modelion.ai website and the Modelion.AI service, both operated by Mersel Technology. Data processed through the console (console.modelion.ai) and the gateway (api.modelion.ai) is additionally governed by the data processing terms in your contract; where the two conflict, the contract prevails.
2. What the website collects
This website sets no cookies and runs no advertising trackers. That is why you see no consent banner: there is no cookie here that would require consent.
We use Plausible Analytics for visit statistics. Plausible sets no cookies, does not fingerprint, does not track across devices or sites, and does not sell what it collects; measurements are tied to the page rather than to a person. It tells us which pages were viewed and how often, which source a visitor arrived from, and country-level location — it does not produce a record that identifies you.
We also count two conversion events: a contact form submission and a newsletter sign-up. The only thing sent alongside those events is the topic you picked from the form's dropdown. Your name, your email and the text of your message are never passed to the analytics system.
Beyond that, data reaches us only when you fill in and submit a form yourself:
- Contact form — name, work email, company, role, phone, topic, monthly spend band and your message. Used only to answer your enquiry.
- Newsletter form — your email address and the site language you chose.
- The interactive demos on this site (policy simulator, guardrail scanner, cost calculator) run entirely in your browser. Nothing you type into them is sent to us.
3. What the Modelion.AI service processes
When you use the service, the following is processed for each request that passes through the gateway:
- Request content — the prompt and variables you send with a model call. These are forwarded to the selected provider; where policy raises a redaction obligation, the provider receives the masked version.
- Decision trace — which rule won, which rules matched and lost, the obligations enforced, the model and region selected.
- Usage record — token counts, latency, cost, virtual key id, organization and region.
- Conversation logs — if enabled on your plan, end-to-end conversations are retained within your organization and can be reviewed through a shareable link.
4. Transfers to providers
Modelion is hosted-only: Mersel runs the provider relationships and holds the credentials, and you never supply your own API key. The consequence is that your prompt is forwarded to the provider your policy selects, under Mersel's credential.
Some of those providers are established outside your region. Because policy decides which provider is used, you can enforce residency at the policy level — for example, a rule that forbids a request with detected PII from leaving the region. While such a rule is in force the fallback chain is deliberately disabled: with no candidate left, the gateway returns an error rather than moving the request into another jurisdiction.
5. Regions and residency
Your organization is bound to a home region: tr-west-1 (Turkey), eu-east-1 (Europe) or us-east-1 (Americas). Decision traces, usage records and conversation logs are held in that region.
6. Retention
Decision-trace retention depends on your plan and is set contractually on enterprise plans. Usage records that form the basis of invoicing are retained for as long as the applicable financial legislation requires. Enquiries you submit through a form are deleted a reasonable period after the enquiry is closed.
7. Security
Provider credentials are encrypted with AES-256-GCM, the keys are KMS-wrapped, and they are decrypted only for the duration of the request; they are not held in memory beyond it. Access is role-based and isolated per organization. Even so, we do not claim that any transmission over the internet is unconditionally secure.
8. Your rights
You have rights of access, rectification, erasure and objection in respect of your personal data. If you are in Turkey, see the KVKK Notice for the detail of your rights under Law No. 6698 and how to exercise them.
You can print this document or save it as a PDF.