Privacy Policy | Ample
Privacy Policy
Effective Date: May 1, 2026
This Privacy Policy describes how Ample Computer, a product of Potluck.AI Corp, ("Ample," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the Ample platform and all related services (the "Services"), as well as our website at ample.computer (the "Site").
By using the Services or the Site, you agree to the collection and use of information as described in this policy. If you do not agree, you should not use the Services.
1. Information We Collect
1.1 Account Information
When you create an Account, we collect information necessary to provide the Services and process payments, including:
- Name and email address
- Billing address
- Payment information (processed and stored by our payment processor, Stripe; we do not store full credit card numbers)
- Company name, if applicable
1.2 Usage Data
We automatically collect information about how you interact with the Services, including:
- API requests: endpoints called, timestamps, request parameters (excluding Content), response status codes, and latency
- Resource usage: CPU, memory, disk, and bandwidth consumption per Server
- Server lifecycle events: creation, destruction, pause, resume, snapshots
- Authentication events: login attempts, token creation and usage, scope information
- Billing events: charges incurred, budget limit triggers, payment transactions
1.3 Technical Data
We collect technical information necessary for the operation of the Services:
- IP addresses used to access the API
- CLI version and operating system
- User-Agent strings from API requests
1.4 Customer Content
Your Content (data, code, applications, and files stored on Servers) resides on our infrastructure. We do not access, monitor, or analyze your Content except as necessary to: (a) provide the Services; (b) prevent or address security incidents or technical issues; (c) respond to support requests you initiate; or (d) comply with applicable law.
1.5 Website Data
When you visit the Site, we may collect standard web analytics data including pages visited, referral sources, browser type, and device information. We use cookies only for essential Site functionality (such as session management during account setup). We do not use advertising cookies or third-party tracking cookies.
2. How We Use Information
We use the information we collect for the following purposes:
- Providing, maintaining, and improving the Services
- Processing payments and managing billing
- Enforcing budget controls, rate limits, and resource quotas
- Detecting and preventing fraud, abuse, and security incidents
- Responding to support requests and communications
- Sending service-related notices (outages, maintenance, security alerts, billing notifications)
- Complying with legal obligations
- Generating aggregated, de-identified analytics about platform usage to improve the Services
We do not use your information for advertising purposes. We do not sell your personal information. We do not use your Content to train machine learning models.
2.1 Aggregated and De-Identified Data
Notwithstanding anything to the contrary in this Privacy Policy, Ample may freely collect, use, and disclose Aggregated De-Identified Data for any lawful business purpose, including without limitation improving, testing, operating, promoting, and marketing our current and future products and services, publishing benchmarks and industry reports, and conducting research. "Aggregated De-Identified Data" means data derived from your use of the Services that has been aggregated with data from other users and de-identified such that it cannot reasonably be used to identify you, your Account, or any individual. Aggregated De-Identified Data expressly excludes your Content.
3. How We Share Information
We do not sell, rent, or trade your personal information. We may share information in the following limited circumstances:
3.1 Service Providers
We share information with third-party service providers who perform services on our behalf, including:
- Payment processing (Stripe)
- Infrastructure providers (currently Hetzner Online GmbH) who provide the bare metal servers on which the Services operate
- Email delivery services for transactional notifications
These providers are contractually obligated to use your information only as necessary to provide their services to us and are required to maintain appropriate security measures.
3.2 Legal Requirements
We may disclose information if required to do so by law, regulation, legal process, or governmental request. We will make commercially reasonable efforts to notify you of such disclosure unless prohibited by law or court order. See Section 7 (Law Enforcement Requests) for details on our process.
3.3 Safety and Enforcement
We may disclose information when we believe in good faith that disclosure is necessary to: (a) protect the safety of any person; (b) address fraud, security, or technical issues; (c) protect the rights or property of Ample; or (d) enforce our Terms of Service or Acceptable Use Policy.
3.4 Business Transfers
In the event of a merger, acquisition, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
3.5 Aggregated Data
We may share aggregated, de-identified data that does not identify any individual without restriction. This may include platform usage statistics, performance benchmarks, and similar data.
4. Data Storage and Security
4.1 Location of Data
The Services currently operate on infrastructure located in United States of America or Germany. Your Content is stored in the region you select when provisioning Servers. Account and billing information may be processed in the United States. As we expand to additional regions, you will have the ability to choose where your Servers and Content are located.
4.2 Security Measures
We implement commercially reasonable technical and organizational measures to protect your information, including: encryption of data in transit (TLS); isolation of customer workloads using Firecracker microVM technology; access controls and authentication for all API endpoints; logging and monitoring of system access; and regular security reviews of our infrastructure.
4.3 Breach Notification
In the event of a data breach that affects your personal information, we will notify you without undue delay and no later than 72 hours after becoming aware of the breach, in accordance with GDPR requirements. We will also notify the relevant supervisory authority as required by law.
5. Data Retention
We retain information as follows:
- Account information: retained for the duration of your Account and for 30 days following Account closure, unless longer retention is required by law (e.g., for tax purposes)
- Customer Content: deleted within 30 days of Server destruction or Account termination, unless you request earlier deletion
- Usage and billing data: retained for up to 24 months for billing reconciliation and service improvement, then deleted or de-identified
- API and access logs: retained for up to 12 months for security and abuse prevention purposes
- Aggregated, de-identified data: may be retained indefinitely for business purposes as described in Section 2.1
6. Your Rights
6.1 General Rights
Regardless of your location, you may: (a) access and download your Content at any time using the CLI or API; (b) update your Account information; (c) delete your Servers and Content; (d) close your Account.
6.2 Rights Under GDPR (EEA Residents)
If you are located in the European Economic Area, you have additional rights under the General Data Protection Regulation, including: the right to access your personal data; the right to rectification of inaccurate data; the right to erasure (right to be forgotten); the right to restrict processing; the right to data portability; the right to object to processing; and the right to lodge a complaint with a supervisory authority. Our lawful basis for processing is performance of a contract (the Terms of Service) and legitimate interests (security, fraud prevention, service improvement).
To exercise these rights, contact privacy@ample.computer. We will respond within 30 days.
6.3 Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which your personal information was collected, the business purpose for collecting your personal information, and the categories of third parties with whom we share your personal information.
- Right to Delete: You have the right to request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to Correct: You have the right to request correction of inaccurate personal information that we maintain about you.
- Right to Opt-Out of Sale or Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. Therefore, there is no need to opt out.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights.
To exercise your California privacy rights, contact privacy@ample.computer. We will verify your identity before processing your request and will respond within 45 days. You may designate an authorized agent to submit requests on your behalf by providing written authorization.
Categories of personal information we collect (as defined by the CCPA): identifiers (name, email, IP address); commercial information (billing records, transaction history); internet or other electronic network activity information (API logs, usage data); and professional or employment-related information (company name, if provided). We collect this information for the business purposes described in Section 2 of this Privacy Policy.
7. Law Enforcement Requests
We may receive legal requests (subpoenas, court orders, search warrants) for customer information. Our policy is to: (a) carefully review every request for legal validity and proper scope; (b) narrow the scope of any disclosure to the minimum required; (c) notify the affected customer before disclosure unless prohibited by law or court order; and (d) provide information about the requesting authority and the legal basis for the request when permitted. We publish a transparency report annually summarizing the number and types of requests received.
8. International Data Transfers
If your data is transferred between jurisdictions (for example, between Germany and the United States), we ensure that appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission or other legally recognized transfer mechanisms. You may request a copy of the applicable data transfer safeguards by contacting privacy@ample.computer.
9. Children's Privacy
The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child under 18 has provided us with personal information, we will delete such information promptly.
10. Do Not Track Signals
The Site does not respond to Do Not Track (DNT) browser signals. However, because we do not use third-party tracking cookies or advertising cookies, and we do not track users across third-party websites, our data collection practices are effectively consistent with a Do Not Track preference.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated with at least 30 days notice via email or through the Services. Your continued use of the Services after the effective date of changes constitutes acceptance of the updated policy.
12. Contact
Privacy questions and data subject requests: privacy@ample.computer
General inquiries: legal@ample.computer
Mailing address: 1844 Market St., San Francisco, CA, 94102
13. Data Processing Agreement
If you process personal data of third parties using the Services, you may need a Data Processing Agreement (DPA) with Ample. A DPA is available upon request by contacting privacy@ample.computer. The DPA covers Ample's obligations as a data processor under GDPR Article 28, including sub-processor disclosures, security measures, data breach notification procedures, and data deletion.