We collect almost nothing about site visitors. Separately, we process conversations on behalf of client businesses — that part is described in full below.
Green Package Pro LLC · Version 1.1.0 · Effective August 4, 2026
This policy covers two things that are easy to confuse, so we separate them explicitly.
As a website,EyesInAI publishes benchmark data about AI models. If you are reading the site, we collect very little about you, and the sections “What we collect” and “What we don't do” describe all of it.
As a service operator, Green Package Pro LLCruns assistants and model-routing infrastructure for client businesses. In that role we process conversations that pass through those systems on the client's behalf. If you are talking to an assistant operated by one of our clients, the section “Data we process for client businesses” is the one that applies to you — and the client, not EyesInAI, decides what data goes into their assistant.
No accounts required for browsing, no tracking pixels beyond analytics, no selling or sharing of data, no advertising networks. The benchmark data on the site is about AI models — not about you.
We do not use client conversation content to train AI models, and we do not sell it or use it for advertising.
When a client business runs an assistant with us, the questions their users ask and the answers given pass through our systems. For a client whose assistant answers over their own business records, that content can include information about theircustomers — people who never interacted with EyesInAI directly. We treat that content as the client's data, held on their behalf.
Why we keep a copy at all. To choose the most accurate and cost-effective model for each request, we record what was asked, what was answered, which model answered, how long it took, what it cost, and how the answer scored. This is what lets us move work to a cheaper model without losing quality, and identify common requests that can be answered without calling an AI model at all.
That conversation content is automatically deleted after 30 days. What remains afterwards is the measurements — which model, what cost, how long, what score — with the words removed. Those measurements contain no personal data. The full rules, table by table, are in the Data Retention Policy.
Who else sees it. To generate an answer we send the request to AI model providers. They process it to return a result and operate their own retention practices, which are governed by their own agreements and are outside our control. Every one of them is named in the Subprocessors list.
All communication with our systems is encrypted in transit using HTTPS. Client conversation records are stored in databases where access is denied by default and reachable only by our own service credentials; no public route exposes them. Access to client data by our staff is limited to what is needed to operate and support the service.
The site sets a small number of cookies: the ones that keep you signed in, and one analytics cookie that counts visits. Each one is listed individually — what it does and how long it lasts — in the Cookie Policy. In the EEA, the UK, Switzerland and Thailand we ask before setting the analytics cookie, and it is not loaded until you agree. Everywhere else you can opt out at any time, and we honour Global Privacy Control signals wherever you are.
Wherever you live, you can ask us to do the following, and we will not charge you or treat you differently for asking:
| Right | What it means in practice |
|---|---|
| Access | Get a copy of the personal data we hold about you, and be told what we do with it. |
| Correction | Have inaccurate or incomplete information about you fixed. |
| Deletion | Have your data erased, except where we are legally required to keep it. |
| Portability | Receive your data in a machine-readable form, or have it sent to another provider. |
| Object or restrict | Tell us to stop or pause a particular use of your data, including analytics. |
| Withdraw consent | Where we relied on your consent, take it back at any time — without affecting what was lawful before. |
| Human review | Ask a person to review a decision that was made about you automatically, and contest it. |
To exercise any of these, email [email protected]. We respond within 30 days. We may need to verify who you are first, which protects you from someone else requesting your data.
If you talked to an assistant operated by one of our clients, that client controls the data and we process it on their instruction. Send your request to them if you can. If you cannot reach them or do not know who they are, send it to us and we will identify the client, pass it on, and help them fulfil it.
For the site itself we are the controller. We rely on legitimate interests to run and secure the site and to measure traffic, on contract to provide the service to clients and their users, on consent where you have given it, and on legal obligationwhere the law requires us to keep records. For conversations flowing through a client's assistant, the client is the controller and we are their processor under the Data Processing Addendum.
You have the right to complain to your national data protection authority. In the UK that is the Information Commissioner's Office. We would appreciate the chance to put it right first, but you are not required to come to us before going to them.
Thailand's Personal Data Protection Act gives you the rights listed above, and we apply them to everyone rather than only to Thai residents. The lawful bases we rely on map to the same categories: performing a contract, our legitimate interest in operating and securing the service, your consent where given, and compliance with law.
You may lodge a complaint with the Personal Data Protection Committee. Some of our processing takes place outside Thailand — see international transfers below.
Residents of California, Colorado, Connecticut, Virginia and other states with comprehensive privacy laws have the rights listed above, including the right to know what is collected, to delete it, to correct it, and to opt out of sale or sharing.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done so, and there is no money in exchange for data anywhere in this business. We honour Global Privacy Control signals sent by your browser. You may designate an authorised agent to make a request for you.
We do not use or disclose sensitive personal information beyond what is needed to provide the service and keep it secure.
We operate from Thailand and the United States, and our infrastructure and AI model providers are largely United States based. Using the service therefore involves transferring data across borders, including out of the European Economic Area, the United Kingdom, and Thailand.
Where a transfer leaves a jurisdiction that restricts them, we rely on the appropriate safeguards available under that law — most commonly Standard Contractual Clauses or the equivalent. Clients who need those clauses executed as part of their own compliance programme can request them under the Data Processing Addendum. The single strongest protection we apply is not a contract at all: conversation text is deleted after 30 days wherever it sits.
The site and the service are not directed to children and we do not knowingly collect information from them.
If this policy changes materially we will update the effective date at the top and, for changes that affect client data handling, notify client account contacts directly.
Every published version of this document. The full corpus history is at changelog.
| Version | Effective | What changed |
|---|---|---|
| 1.1.0 | August 4, 2026 | Added your rights under EU/UK GDPR, Thailand’s PDPA and US state privacy law, with the legal bases we rely on and how to exercise each right. Added international transfer disclosure and a dedicated privacy contact. Linked the new Cookie Policy. |
| 1.0.0 | July 25, 2026 | Initial publication of the legal corpus. |
Questions about this document? Email [email protected].