SunsetSunsetBETA
XDiscordLinkedin
PricingGet started

SUNSET PRIVACY POLICY

Last Updated: 21 January 2026

This Privacy Policy explains how Zaniti, Inc., a Delaware corporation (doing business as “Sunset,” “we,” “us,” “our”) collects, uses, discloses, and otherwise processes personal information when you access or use sunsetml.com, and any other websites, products, applications, or services that link to this Privacy Policy (collectively, the “Service”).

This Privacy Policy also describes your rights and choices regarding your personal information. Additional notices or terms may apply to specific features, integrations, or offerings, including beta features, team or enterprise functionality, and model-specific experiences.

IMPORTANT: SUNSET ROUTES USER CONTENT TO THIRD PARTY AI MODEL PROVIDERS. WHEN YOU SUBMIT PROMPTS, DOCUMENTS, FILES, OR OTHER CONTENT FOR AI PROCESSING, THAT CONTENT MAY BE TRANSMITTED TO AND PROCESSED BY THIRD PARTY PROVIDERS SELECTED THROUGH THE SERVICE. THOSE PROVIDERS PROCESS INFORMATION UNDER THEIR OWN POLICIES AND PRACTICES, AND WE CANNOT GUARANTEE HOW THEY RETAIN, USE, OR DELETE INFORMATION ONCE TRANSMITTED, EXCEPT AS CONTRACTUALLY LIMITED.

SCOPE AND DEFINITIONS

1.1 Key terms

  • “Personal information” means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an individual, and includes “personal data” as defined under the GDPR and UK GDPR.
  • “User Content” means content you upload, submit, store, generate, or otherwise make available through the Service, including documents, prompts, instructions, files, and AI outputs.
  • “AI Model Providers” means third-party model providers, inference partners, and API providers that process User Content to generate outputs.
  • “Subprocessors” means third parties we engage to process personal information on our behalf, including infrastructure, analytics, support, and security providers.
  • “Controller” and “processor” have the meanings given under GDPR and UK GDPR.

1.2 Relationship to other terms

Your use of the Service is also governed by the Sunset Terms of Service and any additional policies we publish, including a Cookie Policy if provided.

WHO WE ARE AND HOW TO CONTACT US

2.1 Company

Zaniti, Inc.
447 Sutter St Ste 405
San Francisco, CA 94108
United States


2.2 Contact

Support: support@sunsetml.com
Legal and privacy notices: legal@sunsetml.com

PERSONAL INFORMATION WE COLLECT

We collect personal information from you, automatically through your use of the Service, and from certain third parties.

3.1 Information you provide

  • Account and profile data. First name, email address, password, authentication identifiers, profile preferences, and similar account information.
  • OAuth and sign-in data. If you use Google OAuth, we receive identifiers and account information made available by Google based on your settings and permissions. We use this data to authenticate you and operate your account. Our processing of data received from Google APIs will comply with applicable Google API user data requirements.
  • User Content and AI interaction data. Documents, prompts, instructions, text, files, images, and other content you submit to the Service, along with the outputs you receive, associated metadata, document structure information, and editing information generated as part of using the editor and creative tools.
  • Communications and support data. Messages you send to us, including support tickets, email correspondence, Intercom conversations, Discord messages where we provide support, and technical information you provide to troubleshoot issues.
  • Marketing preferences. Your preferences for receiving marketing communications and your engagement with our communications.
  • Payments and transactions. We do not store full payment card details. Stripe processes payment information on our behalf. We may receive limited billing and transaction metadata from Stripe, such as subscription status, plan, renewal dates, country, payment outcome, and invoice identifiers.

3.2 Information we collect automatically

  • Device and technical data. IP address, browser type, device type, operating system, language, time zone, approximate location derived from IP, unique identifiers, and similar technical signals.
  • Usage, telemetry, and logs. Pages viewed, features used, clicks, session data, interactions within the editor, performance metrics, error logs, crash reports, and system diagnostics. This may include event logs related to routing requests to AI Model Providers, as well as usage volumes, request timing, latency, and throughput.
  • Cookies and similar technologies. Our partners and we use cookies, SDKs, local storage, pixels, and similar technologies to support functionality, analytics, advertising, and measurement. See Section 10.

3.3 Information from third parties

  • Analytics and advertising partners. We receive aggregated or event-level data from providers such as Google Analytics and advertising platforms to measure performance and attribute conversions.
  • Service providers. We may receive data from vendors that help operate the Service, such as customer support tools, security providers, and infrastructure partners.
  • Public and business sources. Where permitted, we may obtain business contact information or enrichment data for sales outreach.

HOW WE USE PERSONAL INFORMATION

We use personal information for the purposes described below.

4.1 Provide and operate the Service

We process personal information to provide, operate, and administer the Service, including to create and manage accounts, authenticate users (including via Google OAuth), provide editor and creative features, route user requests to AI Model Providers and return outputs, provide customer support and respond to inquiries, manage subscriptions, billing status, and account administration, and enable security features and fraud prevention measures.

4.2 Improve and develop the Service

We process personal information to maintain and improve the Service, including to debug, test, and monitor performance; maintain reliability; build and refine product features and workflows; conduct analytics and user research; and develop internal insights using aggregated or de-identified data where feasible. Where feasible and appropriate, we design analytics and measurements to minimise collection and to reduce identifiability.

4.3 Safety, integrity, and abuse prevention

We process personal information to protect the Service and users, including to detect and prevent suspicious activity, fraud, and misuse, enforce usage limits, fair use controls, and security policies, and investigate potential violations of our Terms of Service and policies.

4.4 Communications and marketing

We process personal information to communicate with you, including to send service-related communications such as confirmations, alerts, and updates. We may also send marketing communications where permitted and in accordance with your choices, and measure engagement with emails and campaigns.

4.5 Compliance, legal obligations, and protection

We process personal information to comply with applicable laws and regulations, respond to lawful requests, establish, exercise, and defend legal claims, and protect our rights, users, and the public, including for incident response.

4.6 Advertising and measurement

Where applicable and permitted by law, we process personal information to deliver, measure, and optimise advertising, including interest-based advertising. Where required by law, we will do so only with appropriate notice and consent mechanisms in place.

LEGAL BASES FOR PROCESSING

Where GDPR or UK GDPR applies, we rely on the following legal bases:

5.1 Contract

Processing necessary to provide the Service under our Terms of Service, including account creation, routing requests to AI Model Providers, and providing outputs.

5.2 Legitimate interests

Processing necessary for our legitimate interests, including operating and improving the Service, ensuring security, preventing abuse, analytics, and supporting business operations. We consider and balance these interests against your rights and fundamental freedoms, and we implement safeguards designed to reduce privacy impact.

5.3 Consent

Where required, we rely on consent for certain cookies, marketing activities, and optional processing. You may withdraw your consent at any time, but doing so does not affect processing already performed.

5.4 Legal obligation

Processing necessary to comply with applicable laws, tax and accounting obligations, and lawful requests.

AI PROCESSING, MODEL ROUTING, AND THIRD PARTY PROVIDERS

This section is important. It explains how your data is processed when you use AI features.

6.1 Routing and orchestration role

Sunset functions as a routing and orchestration layer that enables you to send User Content to one or more AI Model Providers for processing and to receive outputs back in the Service. We do not operate, own, or control the third-party models that generate outputs, nor do we control their internal behaviour.

6.2 What data is transmitted to AI Model Providers

When you use AI features, we may transmit User Content to the AI Model Provider you choose within the Service, which may include prompts, documents, excerpts, files, instructions, and relevant context necessary to fulfil your request. We may also transmit technical metadata necessary to perform the request, such as request identifiers, timing, or error context.

6.3 Provider independence and limits of control

AI Model Providers process data in accordance with their own privacy policies, security practices, and retention rules. We cannot guarantee that an AI Model Provider will delete, not retain, not log, or not use submitted content for training or improvement unless explicitly stated by that provider and contractually committed to us for the relevant processing mode. Provider practices may vary by model, configuration, geography, and time.

6.4 Roles and responsibility allocation

Depending on the processing flow and jurisdiction, AI Model Providers may act as independent controllers, joint controllers, or subprocessors for the data they receive. We generally act as a controller for accounts, billing status, and platform-level analytics and security operations. For User Content processed on behalf of business customers, we may act as a processor where applicable, and AI Model Providers may act as our subprocessors or independent controllers depending on how they process the content. Once User Content is transmitted to an AI Model Provider, that provider’s processing is governed by its own role and policies, except to the extent that a specific processing mode is contractually limited for that provider and flow.

6.5 International processing and locations

AI Model Providers and other partners may process data in multiple jurisdictions. Your content may be transmitted to providers located in, or operating from, the United States and other countries. See Section 11 on international transfers.

6.6 User responsibility and sensitive information warning

You are responsible for selecting which models you use and what information you submit. You should not submit highly sensitive, regulated, confidential, or special category personal data unless you accept the risk that third parties may process, retain, or use that information under their own policies. Sunset is not responsible for how third-party AI models interpret, store, retain, or further process information once it has been transmitted, except as required by law or as contractually committed to a specific processing mode.

6.7 Outputs and model behaviour

Outputs are generated by third-party models. Sunset does not verify or audit model internals and is not responsible for memorisation, training reuse, hallucinations, inference behaviour, or output characteristics determined by third-party providers.

6.8 Changes to providers

We may add, remove, or replace AI Model Providers and inference partners over time for operational, security, availability, quality, or commercial reasons.

HOW WE SHARE PERSONAL INFORMATION

We share personal information as described below.

7.1 AI Model Providers and inference partners

We share User Content and related information with the AI Model Provider you select in order to deliver AI functionality. Providers may process that information in accordance with their own policies.

7.2 Service providers and subprocessors

We share personal information with vendors that help us operate the Service, including hosting, content delivery, analytics, security monitoring, error tracking, customer support, email delivery, and payment processing.

7.3 Payment processing

Stripe processes payment information. Stripe’s processing is governed by Stripe’s privacy policy and terms. We receive limited subscription and billing status information from Stripe.

7.4 Analytics and advertising partners

We share or make available certain device and usage data with analytics and advertising partners for measurement, attribution, and advertising, subject to applicable law and your choices.

7.5 Affiliates and corporate group

We may share personal information with affiliates and entities under common control for internal operations.

7.6 Legal and safety disclosures

We may disclose personal information to law enforcement, regulators, courts, or other parties when we believe in good faith it is necessary to comply with law, protect rights, investigate fraud or security incidents, or enforce our Terms.

7.7 Business transfers

We may share personal information in connection with a merger, acquisition, financing, restructuring, sale of assets, or similar transaction, including due diligence.

7.8 With your direction

We may share information when you instruct us to do so, such as exporting content or enabling a feature that inherently shares information.

DATA RETENTION

8.1 General approach

We retain personal information for as long as necessary to provide the Service and for legitimate and lawful business purposes, including compliance, security, dispute resolution, and enforcement. Retention periods vary depending on the type of information, the purpose for which it was collected, and legal and operational requirements.

8.2 Account data

We retain account information as long as your account is active. After account closure, we may retain certain information for a limited period to comply with legal obligations, resolve disputes, prevent fraud, and enforce agreements.

8.3 User Content

User Content is stored persistently by default to provide the editor and workspace features. If you delete content, we aim to remove it from active systems within a reasonable period, and it may remain in backups for a limited time before being overwritten, except where retention is required by law or for legitimate security and integrity purposes.

8.4 Logs and security records

We retain logs, security events, and audit records for a period appropriate to operate the Service, detect abuse, and satisfy legal obligations. This generally includes retention sufficient to investigate incidents, enforce terms, and maintain the Service's security and integrity.

8.5 Billing and transactional records

We retain billing status and transactional metadata we receive (for example, subscription status, plan, invoice identifiers, and related records) for as long as necessary to administer subscriptions and comply with applicable financial, accounting, and tax obligations.

8.6 Third party provider retentionThird-party

AI Model Providers and other third parties may retain information in accordance with their own policies. Deletion requests to Sunset apply only to data we control and may not delete data that has already been transmitted to third-party AI Model Providers.

SECURITY AND CONFIDENTIALITY

9.1 Safeguards

We maintain administrative, technical, and organisational measures designed to protect personal information, including encryption in transit and at rest, access controls, monitoring, and security testing. We also use error-tracking and monitoring tools (such as Sentry) to detect and remediate issues.

9.2 No absolute security

No method of transmission or storage is completely secure. We cannot guarantee absolute security.

9.3 Incident response and breach notifications

We maintain processes designed to detect, investigate, and respond to security incidents. Where required by applicable law, we will notify relevant authorities and affected individuals of certain breaches involving personal information.

9.4 Shared responsibility

Our security measures apply to systems we control. Third-party AI Model Providers and other vendors maintain their own security practices. We are not responsible for the security of systems we do not control, except as required by law or as agreed in a contract.

9.5 Access limitation and human review

We design the Service to operate primarily through automated processing. Access to personal information and User Content by authorised personnel is limited, role-based, and logged, and is permitted only where reasonably necessary for support, security, abuse prevention, compliance, or to operate and maintain the Service.

COOKIES, ANALYTICS, SESSION REPLAY, AND ADVERTISING

10.1 Cookies and similar technologies

We use cookies and similar technologies for essential functions, analytics, performance, fraud prevention, and advertising.

10.2 Analytics and session replay

We use tools such as Google Analytics, PostHog, and Mixpanel to understand how users interact with the Service, measure performance, and improve the product. PostHog may be used for session replay or similar functionality. Session replay tools may capture interactions with the Service, including user inputs, depending on configuration. Where required by law, we will use session replay and similar technologies only with appropriate notice and consent, and we may implement controls intended to reduce the capture of sensitive fields.

10.3 Advertising and pixels

We may use advertising pixels and SDKs from major advertising platforms to measure campaign performance, retarget audiences, and attribute conversions, subject to applicable law.

10.4 Your choices

You can control cookies through browser settings. Where required by law, we will provide mechanisms to manage consent for non-essential cookies and similar technologies, including certain analytics, advertising, and session replay tools. If you disable certain cookies, parts of the Service may not function properly.

10.5 Do Not Track

Some browsers transmit Do Not Track signals. We do not respond to such signals where not required by law.

INTERNATIONAL DATA TRANSFERS

11.1 Global processing

We are based in the United States and use service providers located in multiple countries. Personal information may be processed and stored in the United States and other jurisdictions that may not offer the same level of protection as your home country.

11.2 Transfer safeguards

Where GDPR or UK GDPR applies, and we transfer personal information outside the UK or EEA, we use appropriate safeguards such as adequacy decisions where available; Standard Contractual Clauses and the UK International Data Transfer Addendum where applicable; and additional technical and organisational measures where appropriate.

11.3 Transfers to AI Model Providers

When you send User Content to AI Model Providers, those providers may process data in other jurisdictions. We cannot guarantee the location of processing at all times, and provider practices may change.

YOUR RIGHTS AND CHOICES

12.1 Account controls

You may access and update certain account information through your account settings.

12.2 Marketing preferences

You can opt out of marketing emails using the unsubscribe link in messages or by contacting us. You may still receive non-marketing service communications.

12.3 GDPR and UK GDPR rights

If you are in the UK or EEA, you may have the right to: access your personal information; correct inaccurate information; request deletion; restrict processing; object to processing based on legitimate interests; data portability; withdraw consent where processing is based on consent; and lodge a complaint with your supervisory authority.

12.4 How to exercise rights

To make a request, contact legal@sunsetml.com. We may need to verify your identity. We may refuse requests where permitted by law, such as where compliance would adversely affect the rights of others or where we must retain information for legal reasons.

12.5 Limitations relating to third-party AI Model Providers

Requests to delete, access, or restrict data apply to data we control. We may not be able to access, correct, or delete data retained by AI Model Providers once it has been transmitted.

US STATE PRIVACY DISCLOSURES, INCLUDING CALIFORNIA

This section applies where relevant based on your residency and applicable law.

13.1 Categories of personal information collected

We may collect the following categories: identifiers such as name and email; commercial information such as subscription status and transaction metadata; internet and device activity information such as usage and telemetry; approximate geolocation derived from IP; communications information; user content submitted to the Service and outputs; inferences drawn from usage to improve the Service.

13.2 Purposes and disclosures

We collect and use personal information for the purposes described in Section 4 and share it as described in Section 7.

13.3 Sale and sharing

We may “share” personal information for cross-context behavioural advertising, as defined under California law, by using advertising cookies and pixels. We do not knowingly sell personal information in exchange for money. You may have the right to opt out of sharing for targeted advertising where required. If we provide an opt-out mechanism, it will be described in our cookie or privacy controls.

13.4 Sensitive personal information

We do not intend to collect or process sensitive personal information for the purpose of inferring characteristics about you. You should not submit sensitive personal information in User Content.

13.5 Rights

Depending on your state, you may have rights to access, delete, correct, and opt out of certain processing, and to be free from discrimination for exercising privacy rights. To submit a request, contact legal@sunsetml.com. We will verify your request as required by law.

13.6 Data accuracy and user responsibility

You are responsible for the accuracy and lawfulness of the personal information and User Content you submit to the Service, including any information about other individuals.

CHILDREN

The Service is not intended for individuals under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information, contact legal@sunsetml.com, and we will take appropriate steps in accordance with applicable law.

CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy from time to time. We will update the Last Updated date and may provide notice through the Service or by email, as required by law. Your continued use of the Service after the effective date of an update constitutes your acceptance of the updated policy to the extent permitted by law. We may retain prior versions of this Privacy Policy for recordkeeping, compliance, and audit purposes.

SUBPROCESSORS AND PROVIDER LIST

We maintain and update a list of our key subprocessors and AI Model Providers.

Subprocessor list: [INSERT LINK OR LOCATION]

We may update our subprocessors and providers over time. For business customers, we may provide reasonable advance notice of material changes to subprocessors where commercially practicable and where required by contract.

NOTICE TO UK AND EEA USERS

17.1 Controller and processing roles

For account administration, marketing, analytics, and platform security, Zaniti, Inc. is generally the controller. For certain business customer use cases involving customer content, we may act as a processor where applicable. AI Model Providers may act as independent controllers, joint controllers, or subprocessors depending on the processing flow.

17.2 Supervisory authority complaints

You may lodge a complaint with your local data protection authority. In the UK, this is the Information Commissioner’s Office. In the EEA, you may contact the supervisory authority in your member state of residence or work.

17.3 Data transfers

See Section 11 for transfer safeguards.

17.4 Automated decision-making and profiling

The Service is not intended to make decisions about individuals that produce legal effects or similarly significant effects within the meaning of GDPR or UK GDPR. The Service generates outputs in response to user inputs, and you remain responsible for how you use outputs and any decisions you make.

12.5 Limitations relating to third-party AI Model Providers

Requests to delete, access, or restrict data apply to data we control. We may not be able to access, correct, or delete data retained by AI Model Providers once it has been transmitted.

Address: Zaniti, Inc., 447 Sutter St Ste 405, San Francisco, CA 94108, United States

Sunset ©2026 all rights reserved
Terms of ServiceTOSPrivacy Policy