Operator: Oasis Vault I LLC
Address: 30 N Gould St Ste N, Sheridan, WY 82801, United States
EIN: 32-0851122
Contact: hello@getmist.ai
1. Introduction
This Privacy Policy explains how Oasis Vault I LLC ("Mist," "we," "us," or "our") collects, uses, and protects information when you visit our website at getmist.ai (the "Site"), use the application at app.getmist.ai (the "Dashboard"), or access our API at api.getmist.ai (together, the "Service").
By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.
2. Who We Are
The Service is operated by Oasis Vault I LLC, a limited liability company formed in the state of Wyoming, United States. Our mailing address is 30 N Gould St Ste N, Sheridan, WY 82801. You can reach us at hello@getmist.ai.
3. Information We Collect
We collect information in the following categories:
3.1 Account and Identity Information
When you create an account or are invited to join a company workspace, we collect:
- Your name and email address
- Your company or organization name
- Your role (e.g., user, company administrator)
3.2 Usage and Billing Metadata
To operate the Service, provide usage dashboards, and administer budgets and billing, we collect metadata about your use of the Service, including:
- API requests and token counts (input, output, and cache categories)
- Model identifiers and provider routing information
- Timestamps and IANA timezone context
- Per-user, per-team (area), per-company, and per-model usage and cost attribution
- Budget limit settings and audit records of budget changes
- Credit ledger, deposit, and billing records
- API key metadata (creation, last use, revocation)
3.3 Inference Content
Mist does not store the content of your prompts or the model responses generated through the Service in our own systems as part of providing inference. To deliver a response, the content you submit is transmitted to the third-party model providers that power the Service, and their own privacy and data-retention practices apply. See Section 5.
Important scope: the statement above covers inference content (prompts and model responses) handled by Mist. It does not extend to the usage, billing, and account metadata described in Section 3.2, which we do retain to operate and bill for the Service.
3.4 Contact and Support Information
When you contact us through the Site's contact form or by email, we collect the information you provide (such as your name, email address, and message). Contact-form submissions are forwarded to a third-party form-processing provider. Do not include confidential prompts, credentials, or sensitive information in contact messages.
3.5 Cookies and Session Data
We use session cookies and similar technologies to keep you signed in and to secure your account. These cookies are necessary for the operation of the Service.
4. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Authenticate users and manage accounts, teams (areas), and access
- Enforce budgets and company-approved model access
- Generate usage, cost, and billing reports for administrators
- Process credits and billing transactions
- Respond to support requests and inquiries
- Detect, prevent, and address security, fraud, and technical issues
- Comply with legal obligations
5. Sharing of Information
We do not sell your personal information.
We share information only in the following circumstances:
- Model providers. To fulfill inference requests, prompt content is transmitted to the third-party model providers (including, without limitation, Venice and OpenRouter) that power the models available through the Service. Their collection and use of that content is governed by their own terms and privacy policies. We instruct our providers that business traffic is not used for training, but we do not control or guarantee each provider's practices.
- Service providers. We engage third-party providers for hosting, infrastructure, form processing, and other operational services. These providers receive only the information necessary to perform their functions.
- Legal compliance. We may disclose information when required by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
- Corporate transactions. If we are involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction.
6. Data Retention
We retain account, usage, billing, and audit metadata for as long as necessary to operate the Service, comply with legal obligations, resolve disputes, and enforce agreements. For example, billing and accounting records are retained to support the credit ledger and tax obligations.
API keys are stored in hashed form; we do not retain plaintext secrets. Passwords are protected using strong, salted hashing.
As described in Section 3.3, Mist does not store inference content (prompts or model responses) in our own systems as part of providing inference.
7. Security
We take reasonable technical and organizational measures to protect your information, including:
- Hashing of API key secrets at rest
- Strong, salted password hashing (Argon2id)
- HTTPS in production
- Session cookies that are HttpOnly, SameSite, and Secure in production
- Origin checks and allowlisting for administrative and forwarding endpoints
- Backend scope checks for company, team, and budget administration
No method of transmission or storage is completely secure. We cannot guarantee the absolute security of your information.
8. International Users
The Service is operated from the United States. If you access the Service from outside the United States, your information may be processed and stored in the United States and in the locations of our service and model providers, and transferred to those locations in accordance with applicable law.
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with data-protection laws, we process your personal data as a "controller" for the purposes described in this Policy, and you may have additional rights described in Section 9.
9. Your Rights and Choices
Depending on your location, you may have the following rights with respect to your personal information:
- Access: request a copy of the personal information we hold about you
- Correction: request that we correct inaccurate information
- Deletion: request that we delete your personal information, subject to legal and operational retention requirements
- Restriction or objection: request that we limit or stop certain processing
- Portability: request your information in a structured, machine-readable format where applicable
- Withdrawal of consent: where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact us at hello@getmist.ai. We will respond in accordance with applicable law. We may need to verify your identity before fulfilling your request.
If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your local data-protection supervisory authority.
10. Children's Privacy
The Service is not directed to children under the age of 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at hello@getmist.ai.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Effective date" above and, where appropriate, notify you by email or through the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy or our privacy practices, contact us at:
Oasis Vault I LLC
30 N Gould St Ste N, Sheridan, WY 82801, United States
Email: hello@getmist.ai