Legal

Privacy Policy

Effective date: September 8, 2026 · Yielding Bear LLC · Sheridan, Wyoming, USA

This Privacy Policy explains how Yielding Bear LLC ("Yielding Bear," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit yieldingbear.com, create an account, use the Grizzly / Yielding Bear API gateway, dashboard, billing tools, booking tools, documentation, skills/plugins, or related products and services (collectively, the "Services").

By using the Services, you acknowledge this Policy. If you do not agree, do not use the Services. Capitalized terms not defined here have the meaning in our Terms of Service.

1. Who we are

Controller / business: Yielding Bear LLC, a Wyoming limited liability company. Primary contact for privacy requests: grizzly@yieldingbear.com. Mailing / registered presence: Sheridan, Wyoming, United States.

2. Scope

This Policy applies to personal information we process in connection with:

  • Marketing and product websites (including yieldingbear.com and related pages)
  • Account registration, login, email verification, and session management
  • API keys, OpenAI-compatible chat/completions and related endpoints, model routing (including Grizzly / Grizzly Max / Grizzly 1.0G), usage metering, and developer tools
  • Billing, subscriptions (e.g. Grizzly Max), credit packs, invoices/statements, and payment processing
  • Support, sales, discovery booking, and transactional email
  • Optional integrations, plugins, skills, Catabasis-related product surfaces, and referral programs
  • Cookies, pixels, and similar technologies on our sites

This Policy does not control how third-party model providers, payment processors, or platforms you connect process data under their own policies. Where we act as a processor for enterprise customers under a separate written DPA, that agreement controls for the covered processing.

3. Categories of information we collect

3.1 Account and identity

  • Name, email address, password or authentication credentials (hashed/stored via our auth provider)
  • Profile and plan/tier labels (e.g. free, pay-as-you-go, pro/Grizzly Max, team, enterprise)
  • Organization or workspace identifiers if you use multi-seat or team features
  • Communication preferences and support correspondence

3.2 Billing and commercial data

  • Subscription status, credit balances, usage charges, and statement history
  • Stripe customer and payment method tokens (we do not store full card numbers on our servers; Stripe processes card data)
  • Billing email, tax/business identifiers you provide, and invoice metadata
  • Referral or promo codes and related attribution

3.3 API, product, and content data

  • API keys and key metadata (creation time, labels, last used, rate-limit context)
  • Request metadata: timestamps, model IDs, token/usage counts, latency, routing decisions, error codes, request IDs
  • Prompt, message, completion, embedding, and other content you submit through the API or playground ("Customer Content"), processed to fulfill the request and operate routing, caching, guardrails, and billing
  • Saved routing preferences, default models, and dashboard configuration
  • Logs needed for abuse detection, security, debugging, and service integrity

3.4 Device, network, and usage

  • IP address, user agent, device/browser type, approximate location derived from IP
  • Pages viewed, referrers, session duration, and similar analytics events
  • Cookies, local storage, and similar identifiers (see Cookies)

3.5 Booking and sales

  • Name, email, company, meeting time preferences, and notes you submit for discovery or audit calls
  • Calendar-related details needed to schedule and confirm meetings

3.6 Sensitive data

We do not require special-category data (e.g. health, precise biometrics, government IDs) to use the core API. Do not submit sensitive personal data in prompts unless you have a lawful basis and appropriate safeguards. If you do, you are responsible for compliance with applicable law and provider policies.

4. Sources of information

  • Directly from you (signup, billing, forms, support, booking, API use)
  • Automatically from your devices and browsers when you use the Services
  • From payment processors (e.g. Stripe) and auth/hosting providers as needed to operate accounts
  • From upstream model infrastructure (e.g. routing/proxy providers such as LiteLLM deployments and OpenRouter) in the form of status, usage, and error responses
  • From partners or referral links when you arrive via a tracked campaign or referral code
  • From publicly available sources only if needed for fraud prevention or business contact verification in B2B contexts

5. How we use information

We use personal information to:

  • Provide, operate, maintain, and improve the Services (authentication, API gateway, routing, dashboards, docs)
  • Meter usage, enforce plan limits, rate limits, and entitlements; process payments and prevent fraud
  • Route Customer Content to selected or automatically chosen models and return results
  • Provide optional features such as caching, guardrails, analytics, virtual keys, statements, and agent-oriented tooling
  • Communicate service notices, security alerts, billing receipts, and (with appropriate consent or as permitted) product updates
  • Schedule and run discovery/sales calls; provide customer support
  • Monitor reliability, debug incidents, secure systems, and detect abuse or policy violations
  • Comply with law, respond to lawful requests, and enforce our Terms
  • Analyze aggregate product usage to improve routing quality and capacity planning

Legal bases (where GDPR/UK GDPR or similar laws apply) include: performance of a contract; legitimate interests (security, product improvement, B2B marketing to existing contacts where allowed); consent (where required, e.g. certain cookies or marketing); and legal obligation.

6. AI / model processing of Customer Content

When you call our API or use playground features, Customer Content is transmitted to Yielding Bear infrastructure and may be forwarded to third-party model providers or gateways we use to fulfill the request (including but not limited to infrastructure we operate or contract, and fallback providers such as OpenRouter). Those providers process content to generate outputs under their terms and privacy practices.

We process Customer Content to fulfill your requests, apply routing and product features you enable, meter billing, and maintain security and abuse controls. Unless we expressly state otherwise in a written enterprise agreement, we do not use Customer Content to train public foundation models owned by Yielding Bear. Upstream providers may have their own training, retention, and logging policies—you are responsible for reviewing those policies for models you select or that routing may invoke.

Outputs can be inaccurate or inappropriate. Do not rely on the Services as sole authority for legal, medical, financial, or other high-risk decisions without human review.

7. How we share information

We share personal information only as described below:

  • Service providers / processors: hosting (e.g. Vercel), databases/auth (e.g. Supabase), payments (Stripe), email delivery (e.g. Resend), analytics/ads measurement (e.g. Whop pixel or similar), error/performance tooling, and cloud infrastructure
  • Model and inference providers required to fulfill API requests
  • Professional advisors (legal, accounting) under confidentiality
  • Business transfers: merger, acquisition, financing, or sale of assets, subject to appropriate safeguards
  • Legal and safety: to comply with law, lawful process, or to protect rights, safety, and integrity of users and the public
  • With your direction or consent (e.g. integrations you enable)

We do not sellpersonal information for money. We do not knowingly "sell" or "share" personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA, except insofar as limited advertising/measurement technologies on our marketing site may be interpreted as "sharing" under California law—in which case you may exercise opt-out rights described below. We do not use or disclose sensitive personal information for purposes that require a right to limit under CPRA beyond what is necessary to provide the Services.

8. Cookies and similar technologies

We use:

  • Essential cookies/storage for login sessions, security, load balancing, and core site function
  • Preference cookies (e.g. UI settings) where applicable
  • Referral attribution cookies/local storage (e.g. multi-day referral codes) to credit referrals
  • Analytics and advertising/measurement pixels on marketing pages (which may set or read identifiers)

You can control cookies through browser settings. Blocking essential cookies may break login or checkout. Where required by law, we will present consent mechanisms for non-essential cookies.

9. Retention

We retain personal information for as long as your account is active and as needed to provide the Services, then for a limited period thereafter for legitimate business needs (billing disputes, security audits, legal compliance). Retention periods vary by category:

  • Account data: for the life of the account plus a reasonable wind-down period
  • Billing and tax records: typically 7 years or as required by law
  • API usage/metering logs: retained for billing, abuse prevention, and product analytics on a rolling basis appropriate to those purposes
  • Customer Content in transient processing: retained only as needed to complete the request and operate enabled features (e.g. short-lived caches); longer retention only if you enable features that store it or law requires
  • Support and booking records: for the relationship plus a reasonable archive period

When retention ends, we delete or de-identify data except where backup or legal holds temporarily prevent immediate deletion.

10. Security

We implement administrative, technical, and organizational measures designed to protect personal information, including encryption in transit (TLS), access controls, hashed credentials via our auth stack, segmented secrets, and monitoring. No method of transmission or storage is 100% secure. You are responsible for protecting API keys and account credentials and for configuring least-privilege access.

11. International transfers

We are based in the United States. If you access the Services from outside the U.S., your information may be processed in the U.S. and other countries where we or our providers operate. Where required, we use appropriate transfer mechanisms (e.g. standard contractual clauses) with processors.

12. Your rights

12.1 General

Depending on your location, you may have rights to access, correct, delete, export/port, restrict, or object to certain processing, and to withdraw consent where processing is consent-based. Submit requests to grizzly@yieldingbear.com. We may verify your identity before acting. You may have the right to lodge a complaint with a supervisory authority.

12.2 California (CCPA/CPRA) and similar U.S. state laws

California residents may request: (1) categories and specific pieces of personal information collected; (2) deletion; (3) correction; (4) information about sources, purposes, and disclosures; and (5) to opt out of sale/sharing if applicable. We will not discriminate against you for exercising privacy rights. Authorized agents may submit requests with proof of authority. Shine the Light: we do not disclose personal information to third parties for their direct marketing for monetary consideration in the manner regulated by Cal. Civ. Code § 1798.83.

12.3 EEA/UK

Where GDPR applies, you may exercise the rights listed above and object to processing based on legitimate interests. Contact us as above. If we appoint an EU/UK representative, we will update this Policy.

13. Children

The Services are directed to businesses and adults. We do not knowingly collect personal information from children under 16 (or under 13 where COPPA applies). If you believe a child provided personal information, contact us and we will take appropriate steps to delete it.

14. Third-party links and services

The Services may link to third-party sites (docs, model cards, social profiles, payment pages). Their privacy practices are their own. Review those policies before providing data.

15. Changes

We may update this Policy from time to time. We will post the revised version with an updated effective date. Material changes may be communicated by email or in-product notice when appropriate. Continued use after the effective date constitutes acceptance of the updated Policy to the extent permitted by law.

16. Contact

Privacy questions and requests: grizzly@yieldingbear.com
Yielding Bear LLC · Sheridan, WY · USA
Terms: /terms

Last updated: September 8, 2026. This Policy is provided for operational transparency and does not constitute legal advice.