Isotropic LabsBack home

Privacy Policy

Effective date: August 18, 2026

This Privacy Policy explains how Isotropic Labs, Inc. ("Isotropic," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit our websites, communicate with us, create an account, or use our software, APIs, models, and related services (collectively, the "Services").

This Privacy Policy applies to personal information. It does not replace the contractual terms governing confidential business information, manufacturing data, experimental results, process parameters, or other content submitted by an organization to the Services. Those materials are also governed by our Terms of Service and any applicable order form, nondisclosure agreement, data processing agreement, or other written agreement with the organization.

1. Current Scope of the Services

As of the effective date above, the Services consist of our websites, informational and demonstration materials, and authenticated user accounts. The Services do not yet accept uploaded customer files, datasets, or process data.

Provisions below that describe Customer Content apply from the date the corresponding functionality becomes available to you. We will update the effective date and, where a change materially affects how we use personal information, provide notice as described in Section 14.

2. Information We Collect

Information you provide

  • Account and profile information: Your name, business email address, organization, job title, account credentials, and related account details.
  • Communications: Information you provide when you contact us, request a demonstration, join a waitlist, submit a support request, or otherwise communicate with us.
  • Customer Content: Files, datasets, process information, experimental results, parameters, constraints, instructions, and other materials submitted to or generated through the Services, once that functionality is available to you.
  • Feedback: Information you choose to provide in surveys, interviews, product feedback, or other research.

Information collected automatically

  • Usage information: Pages or features viewed, actions taken, dates and times of access, referring pages, and interactions with the Services.
  • Device and network information: IP address, browser type, device type, operating system, approximate location derived from IP address, and diagnostic information.
  • Cookies and similar technologies: Information collected through cookies, local storage, and similar technologies used for authentication, security, session management, and preferences. See Section 6.

Information provided by your organization

If you use the Services through an employer or another organization, that organization may provide account information about you or control your access to the Services.

Information we do not collect

We do not collect payment card information through the Services. If paid Services are offered, payment and billing terms will be stated in an applicable order form or other written agreement, and payment processing will be handled by a third-party payment processor under its own terms.

We do not seek to collect sensitive personal information, including government identifiers, financial account numbers, precise geolocation, health information, biometric data, or information revealing racial or ethnic origin, religious beliefs, political opinions, trade union membership, sex life, or sexual orientation. Please do not submit this information to us. Our Terms of Service prohibit submitting specially regulated information without our prior written agreement.

3. How We Use Information

We may use personal information to:

  • provide, operate, maintain, and support the Services;
  • create and administer accounts and authenticate users;
  • process Customer Content and generate results requested by the customer;
  • respond to inquiries, demonstration requests, and support requests;
  • monitor performance, diagnose problems, and improve the reliability and usability of the Services;
  • protect the Services, our customers, and others from fraud, misuse, security threats, and unlawful activity;
  • communicate about service changes, security matters, and administrative issues;
  • send marketing communications where permitted by law, with the ability to unsubscribe;
  • comply with legal obligations and enforce our agreements; and
  • establish, exercise, or defend legal claims.

We do not make decisions producing legal or similarly significant effects about an individual without human involvement, and we do not engage in profiling for that purpose.

4. Customer Content and Model Training

Customers retain ownership of their Customer Content.

We may process Customer Content to provide the Services to the customer that submitted it. This may include fitting, configuring, or running customer-specific models, generating predictions or recommendations, and performing support or troubleshooting requested by that customer.

We do not use Customer Content to train or improve shared, general-purpose, or cross-customer models. We do not use one customer's Customer Content to provide results to another customer.

We may use usage information and feedback that does not reveal Customer Content to maintain, secure, evaluate, and improve the Services. We may also create aggregated or de-identified information that cannot reasonably be used to identify an individual or reveal a customer's confidential information. We maintain de-identified information in de-identified form and do not attempt to re-identify it, except to test the effectiveness of our de-identification.

5. How We Disclose Information

We may disclose personal information in the following circumstances:

  • Service providers: To vendors that provide hosting, cloud infrastructure, authentication, analytics, communications, security, support, and related services on our behalf. They may process information only for the services they provide to us, only on our documented instructions, and subject to appropriate contractual restrictions.
  • Your organization: To administrators or authorized users of the organization through which you access the Services, including information about your account and use of the Services.
  • Professional advisors: To auditors, accountants, insurers, and legal counsel bound by duties of confidentiality.
  • Legal and safety purposes: When we reasonably believe disclosure is necessary to comply with law, respond to valid legal process, protect rights or safety, investigate fraud or security incidents, or enforce our agreements.
  • Business transactions: In connection with a merger, financing, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality protections.
  • With your direction or consent: When you direct us to disclose information or otherwise consent to the disclosure.

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act and comparable state privacy laws. We have not sold or shared personal information in the preceding twelve months, and we do not sell or share the personal information of minors under 16.

6. Cookies and Analytics

We use strictly necessary technologies for functions such as authentication, security, session management, and account preferences. These are required for the Services to operate and cannot be disabled through our interface. You can block them through your browser, but the Services may not function.

For analytics, we use Vercel Web Analytics, which collects aggregated visit and performance data without using cookies and without building persistent identifiers or cross-site profiles of individual visitors.

We do not use advertising cookies, advertising or conversion pixels, social media tracking technologies, or session-recording tools. Because we use no nonessential cookies, we do not display a cookie consent banner. If this changes, we will update this Privacy Policy, obtain consent where required, and provide an opt-out mechanism.

Do Not Track and Global Privacy Control. Browsers and extensions may transmit "Do Not Track" (DNT) signals. There is no common industry standard for interpreting DNT, and we do not currently respond to DNT signals. We do honor Global Privacy Control (GPC) signals as valid opt-out requests where required by applicable law. Because we do not sell or share personal information, a GPC signal does not change how we process your information.

7. Data Retention

We retain personal information for as long as reasonably necessary to provide the Services, maintain legitimate business records, comply with legal obligations, resolve disputes, and enforce agreements. Retention periods depend on the type of information, the purpose for which it was collected, contractual commitments, security needs, and legal requirements.

Our current default retention periods are:

InformationRetention period
Account and profile informationFor the life of the account, then up to 24 months after closure
Support and business communicationsUp to 36 months after the last interaction
Marketing contact informationUntil you unsubscribe, then a suppression record is kept indefinitely so we do not re-contact you
Server, security, and diagnostic logsUp to 12 months
Aggregated or de-identified analyticsIndefinitely, in de-identified form
Customer ContentUnder the applicable customer agreement; absent an agreement, deleted within 60 days of account closure
Encrypted backupsUp to 35 days after deletion from active systems

8. Security

We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, and disclosure, including encryption in transit, access controls, and least-privilege administrative access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

You are responsible for protecting your account credentials and promptly notifying us if you believe your account or information has been compromised.

Where required by law or contract, we will notify affected individuals, organizations, and regulators of a security incident within the applicable timeframe.

9. Your Privacy Rights

Depending on where you live, you may have the right to:

  • request access to the personal information we hold about you, and the categories of information, sources, purposes, and recipients;
  • request correction of inaccurate personal information;
  • request deletion of your personal information;
  • obtain a portable copy of certain information;
  • opt out of the sale or sharing of personal information and of targeted advertising (we do not engage in these);
  • opt out of profiling that produces legal or similarly significant effects (we do not engage in this);
  • limit the use of sensitive personal information (we do not seek to collect it);
  • withdraw consent where processing is based on consent; and
  • appeal a denial of a privacy request.

You may unsubscribe from marketing emails using the link included in those messages. You will continue to receive necessary administrative or service communications.

Submitting a request. Contact us at admin@isotropiclabs.org. We will acknowledge and respond within the timeframe required by applicable law, generally 45 days, with one extension where permitted. We may need to verify your identity and authority before completing a request, and we may decline a request where an exception applies, in which case we will explain why.

Appeals. If we deny your request, you may appeal by replying to our decision or writing to the same address with "Privacy Appeal" in the subject line. We will respond to an appeal within 45 days, or 60 days where applicable state law allows. If we deny the appeal, we will provide a method to contact your state attorney general.

Authorized agents. You may use an authorized agent to submit a request. We may require written authorization from you and verification of the agent's identity.

Organization-controlled data. If you use the Services through an organization, we may direct a request concerning that organization's data to the organization, and we will assist the organization in responding.

We will not discriminate against you for exercising an applicable privacy right.

10. Individuals in the European Economic Area, United Kingdom, and Switzerland

This section applies in addition to the rest of this Privacy Policy if you are located in the European Economic Area (EEA), the United Kingdom (UK), or Switzerland.

Our role. For personal information collected through our websites, marketing, and account registration, Isotropic Labs, Inc. is the controller — the party that decides why and how the information is used. For personal information contained in Customer Content submitted by a customer organization, that organization is the controller and Isotropic acts as a processor on its documented instructions, under a data processing agreement.

Legal bases. We process personal information on the following legal bases:

PurposeLegal basis
Providing and supporting the Services under a contract with you or your organizationPerformance of a contract
Account security, fraud prevention, service improvement, and business administrationLegitimate interests
Marketing communications to business contactsLegitimate interests, or consent where required
Nonessential cookies and similar technologiesConsent (we currently use none)
Meeting legal, tax, and regulatory obligationsLegal obligation
Establishing, exercising, or defending legal claimsLegitimate interests

Where we rely on legitimate interests, we have assessed that those interests are not overridden by your rights and freedoms. You may object to that processing as described below.

Your rights. In addition to the rights in Section 9, you have the right to object to processing based on legitimate interests, the right to restrict processing, and the right to lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office. We ask that you contact us first so we can try to resolve the matter.

International transfers. Isotropic is based in the United States, and your information will be transferred to and processed in the United States and in other countries where our service providers operate. Where required, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the Swiss equivalent, together with supplementary measures as appropriate. You may request a copy of the relevant transfer mechanism by contacting us.

Representatives. Our representative in the European Union for the purposes of Article 27 GDPR is Ethan Decker (ethan@isotropiclabs.org). Our representative in the United Kingdom for the purposes of Article 27 UK GDPR is Ethan Decker (ethan@isotropiclabs.org).

11. Children

The Services are designed for businesses and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has provided personal information to us, contact us at admin@isotropiclabs.org and we will delete it.

12. Third-Party Services and Links

The Services may contain links to or integrations with third-party services. Their privacy practices are governed by their own policies, not this Privacy Policy.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version and revise the effective date. If a change materially affects how we use personal information, we will provide additional notice where required by law, and we will obtain consent where consent is required. Prior versions are available on request.

14. Contact Us

Isotropic Labs, Inc. 2601 Pennsylvania Ave Philadelphia PA 19130 United States admin@isotropiclabs.org