Privacy Policy
Effective date: July 6, 2026
Who we are
AXIØM is operated by Blendmode (“AXIØM,” “we,” “us”). This policy explains what we collect when you use the AXIØM portal and API, how we use it, and the choices you have. It applies to axiomlens.com and the AXIØM API.
What we collect
When you sign up for AXIØM we collect your email address, a hashed copy of your password, and optional team metadata. When you call the AXIØM API, we record one row per governed call: timestamp, the API key used (by id, not raw value), the model selected, the operator and tier classification, the governance verdict, latency, and token counts. We also log basic request diagnostics (IP address, timestamps) for security and abuse prevention.
Prompt & response content
The hosted decisions ledger is designed to retain governance metadata, not raw prompt or model-response text. The portal strips known content-bearing fields from kernel receipts and stores bounded metadata such as verdict, route, tokens, latency, model, evidence, and next-action signals. CMNDCNTR and other workspace features may separately store business context or evidence that you explicitly submit. Upstream providers receive prompts to produce completions; their data-handling policies apply on their side.
How we use your data
We use the data above to operate the service: authenticate you, meter usage against your plan, render your decisions dashboard, bill you, send transactional email (welcome and quota notices), and prevent abuse. We do not sell your data, and we do not use your prompts or responses to train models.
Sub-processors
We rely on a small set of service providers to run AXIØM: Supabase (database hosting), Vercel (application hosting), Stripe (payments), Resend (transactional email), and the upstream model providers you route to. Each processes data only as needed to provide its service.
Billing data
Stripe processes payment information. AXIØM does not store full credit card numbers; we store a Stripe customer ID and subscription state.
Data retention & deletion
You can delete your account from /dashboard/security. Account deletion deactivates your login and removes your team membership. When a sole owner deletes a team account, its API and staged provider keys are revoked first. Team, billing, activity, and governance records may be retained for security, operational, legal, and billing reconciliation. We do not currently promise an automatic deletion date. To request export or deletion review, contact us below.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. To exercise any of these, contact us and we will respond within the timeframe required by applicable law.
Contact
Questions or data requests: reach us through our contact form.