Privacy Policy | Ample

Privacy Policy

Effective Date: May 1, 2026

This Privacy Policy describes how Ample Computer, a product of Potluck.AI Corp, ("Ample," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the Ample platform and all related services (the "Services"), as well as our website at ample.computer (the "Site").

By using the Services or the Site, you agree to the collection and use of information as described in this policy. If you do not agree, you should not use the Services.

1. Information We Collect

1.1 Account Information

When you create an Account, we collect information necessary to provide the Services and process payments, including:

1.2 Usage Data

We automatically collect information about how you interact with the Services, including:

1.3 Technical Data

We collect technical information necessary for the operation of the Services:

1.4 Customer Content

Your Content (data, code, applications, and files stored on Servers) resides on our infrastructure. We do not access, monitor, or analyze your Content except as necessary to: (a) provide the Services; (b) prevent or address security incidents or technical issues; (c) respond to support requests you initiate; or (d) comply with applicable law.

1.5 Website Data

When you visit the Site, we may collect standard web analytics data including pages visited, referral sources, browser type, and device information. We use cookies only for essential Site functionality (such as session management during account setup). We do not use advertising cookies or third-party tracking cookies.

2. How We Use Information

We use the information we collect for the following purposes:

We do not use your information for advertising purposes. We do not sell your personal information. We do not use your Content to train machine learning models.

2.1 Aggregated and De-Identified Data

Notwithstanding anything to the contrary in this Privacy Policy, Ample may freely collect, use, and disclose Aggregated De-Identified Data for any lawful business purpose, including without limitation improving, testing, operating, promoting, and marketing our current and future products and services, publishing benchmarks and industry reports, and conducting research. "Aggregated De-Identified Data" means data derived from your use of the Services that has been aggregated with data from other users and de-identified such that it cannot reasonably be used to identify you, your Account, or any individual. Aggregated De-Identified Data expressly excludes your Content.

3. How We Share Information

We do not sell, rent, or trade your personal information. We may share information in the following limited circumstances:

3.1 Service Providers

We share information with third-party service providers who perform services on our behalf, including:

These providers are contractually obligated to use your information only as necessary to provide their services to us and are required to maintain appropriate security measures.

3.2 Legal Requirements

We may disclose information if required to do so by law, regulation, legal process, or governmental request. We will make commercially reasonable efforts to notify you of such disclosure unless prohibited by law or court order. See Section 7 (Law Enforcement Requests) for details on our process.

3.3 Safety and Enforcement

We may disclose information when we believe in good faith that disclosure is necessary to: (a) protect the safety of any person; (b) address fraud, security, or technical issues; (c) protect the rights or property of Ample; or (d) enforce our Terms of Service or Acceptable Use Policy.

3.4 Business Transfers

In the event of a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.

3.5 Aggregated Data

We may share aggregated, de-identified data that does not identify any individual without restriction. This may include platform usage statistics, performance benchmarks, and similar data.

4. Data Storage and Security

4.1 Location of Data

The Services currently operate on infrastructure located in United States of America or Germany. Your Content is stored in the region you select when provisioning Servers. Account and billing information may be processed in the United States. As we expand to additional regions, you will have the ability to choose where your Servers and Content are located.

4.2 Security Measures

We implement commercially reasonable technical and organizational measures to protect your information, including: encryption of data in transit (TLS); isolation of customer workloads using Firecracker microVM technology; access controls and authentication for all API endpoints; logging and monitoring of system access; and regular security reviews of our infrastructure.

4.3 Breach Notification

In the event of a data breach that affects your personal information, we will notify you without undue delay and no later than 72 hours after becoming aware of the breach, in accordance with GDPR requirements. We will also notify the relevant supervisory authority as required by law.

5. Data Retention

We retain information as follows:

6. Your Rights

6.1 General Rights

Regardless of your location, you may: (a) access and download your Content at any time using the CLI or API; (b) update your Account information; (c) delete your Servers and Content; (d) close your Account.

6.2 Rights Under GDPR (EEA Residents)

If you are located in the European Economic Area, you have additional rights under the General Data Protection Regulation, including: the right to access your personal data; the right to rectification of inaccurate data; the right to erasure (right to be forgotten); the right to restrict processing; the right to data portability; the right to object to processing; and the right to lodge a complaint with a supervisory authority. Our lawful basis for processing is performance of a contract (the Terms of Service) and legitimate interests (security, fraud prevention, service improvement).

To exercise these rights, contact privacy@ample.computer. We will respond within 30 days.

6.3 Rights Under CCPA/CPRA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act and the California Privacy Rights Act:

To exercise your California privacy rights, contact privacy@ample.computer. We will verify your identity before processing your request and will respond within 45 days. You may designate an authorized agent to submit requests on your behalf by providing written authorization.

Categories of personal information we collect (as defined by the CCPA): identifiers (name, email, IP address); commercial information (billing records, transaction history); internet or other electronic network activity information (API logs, usage data); and professional or employment-related information (company name, if provided). We collect this information for the business purposes described in Section 2 of this Privacy Policy.

7. Law Enforcement Requests

We may receive legal requests (subpoenas, court orders, search warrants) for customer information. Our policy is to: (a) carefully review every request for legal validity and proper scope; (b) narrow the scope of any disclosure to the minimum required; (c) notify the affected customer before disclosure unless prohibited by law or court order; and (d) provide information about the requesting authority and the legal basis for the request when permitted. We publish a transparency report annually summarizing the number and types of requests received.

8. International Data Transfers

If your data is transferred between jurisdictions (for example, between Germany and the United States), we ensure that appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission or other legally recognized transfer mechanisms. You may request a copy of the applicable data transfer safeguards by contacting privacy@ample.computer.

9. Children's Privacy

The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child under 18 has provided us with personal information, we will delete such information promptly.

10. Do Not Track Signals

The Site does not respond to Do Not Track (DNT) browser signals. However, because we do not use third-party tracking cookies or advertising cookies, and we do not track users across third-party websites, our data collection practices are effectively consistent with a Do Not Track preference.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated with at least 30 days notice via email or through the Services. Your continued use of the Services after the effective date of changes constitutes acceptance of the updated policy.

12. Contact

Privacy questions and data subject requests: privacy@ample.computer

General inquiries: legal@ample.computer

Mailing address: 1844 Market St., San Francisco, CA, 94102

13. Data Processing Agreement

If you process personal data of third parties using the Services, you may need a Data Processing Agreement (DPA) with Ample. A DPA is available upon request by contacting privacy@ample.computer. The DPA covers Ample's obligations as a data processor under GDPR Article 28, including sub-processor disclosures, security measures, data breach notification procedures, and data deletion.