Privacy Policy
Effective date: September 12, 2026
Operator: TriKro LLC, doing business as Kromatic ("we," "us," "our")
This Privacy Policy describes how TriKro LLC (DBA Kromatic) collects, uses, and shares information in connection with the Fermi API service ("Service") available at fermi.krobar.ai.
1. Information We Collect
1.1 Account Information
When you create an account through our API, we generate and store:
- A unique account identifier (
account_id) - A hashed API key (we do not store your API key in plain text after initial issuance)
- Account creation timestamp
We do not require an email address, password, name, or any other personally identifiable information to create an account.
1.2 API Usage Data
When you use the Service, we collect:
- The natural-language questions you submit
- Estimation parameters you provide (tier, unit, horizon)
- The estimation results returned to you
- Credit transaction records (charges, balances)
- Request timestamps and idempotency keys
1.3 Anonymous Usage Data
For unauthenticated (anonymous) requests, we collect:
- An IP-derived fingerprint used solely for rate limiting
- A daily request count associated with that fingerprint
We do not store raw IP addresses for anonymous users beyond what is necessary for rate-limiting enforcement. The fingerprint is a one-way hash and cannot be reversed to recover the original IP address.
1.4 Web Analytics
The Service's public web pages (the homepage, this Privacy Policy, and the Terms of Service) load Google Analytics 4 through Google Tag Manager. This sets first-party cookies and collects standard GA4 page-view and session data. It is not loaded on the API (/api/v1/*) or MCP (/mcp/*) endpoints, so programmatic and AI-agent usage of the Service is not measured by Google Analytics.
1.5 Information We Do Not Collect
We do not serve advertisements. We do not collect device fingerprints, browser user-agent strings for profiling, or geolocation data beyond what is inherent in an IP address for rate-limiting purposes.
2. How We Use Your Information
We use the information we collect to:
- Provide the Service: Process your estimation requests, manage your account, and track credit balances.
- Improve the Service: Analyze usage patterns in aggregate to improve estimation quality, calibration accuracy, and system reliability.
- Enforce rate limits: Prevent abuse and ensure fair access for all users.
- Monitor errors: Diagnose and fix technical issues via error monitoring.
- Comply with legal obligations: Respond to lawful requests from public authorities.
3. Data Retention
- Account data: Retained for the lifetime of your account. Since accounts have no email or password, deletion requests should be sent to [email protected] with your
account_id. - API usage data: Retained for up to 24 months to support calibration analysis and service improvement, then deleted or anonymized.
- Anonymous rate-limit data: IP-derived fingerprints and daily counts are retained for no more than 30 days.
- Error monitoring data: Error reports sent to Sentry are retained according to Sentry's data retention policies (typically 90 days).
4. Third-Party Services
We share data with the following third-party service providers, solely to operate the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Anthropic (Claude) | LLM provider for generating estimates | Question text, estimation parameters |
| OpenAI | Alternative LLM provider | Question text, estimation parameters |
| Fly.io | Hosting infrastructure | All data transits Fly.io servers |
| Sentry | Error monitoring | Error context, request metadata (no question content by default) |
| Google (Google Analytics / Google Tag Manager) | Web analytics | Page-view and session data from the public web pages (not the API or MCP endpoints) |
We do not sell, rent, or trade your information to any third party. We do not use advertising services.
5. Data Security
We implement reasonable administrative, technical, and physical safeguards to protect your information, including:
- API keys are stored using one-way cryptographic hashes
- All data in transit is encrypted via TLS
- Access to production systems is restricted to authorized personnel
No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
6. Your Rights Under California Law (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act:
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you.
- Right to Delete: You may request that we delete personal information we have collected from you, subject to certain exceptions.
- Right to Correct: You may request that we correct inaccurate personal information we maintain about you.
- Right to Opt Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. There is nothing to opt out of.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
To exercise any of these rights, contact us at [email protected] with your account_id. We will respond within 45 days as required by law.
Because we collect minimal personal information (no email, no name, no password), the scope of identifiable data we can locate is limited to your account_id and associated usage records.
7. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. Because we do not require age verification or collect identifying information at signup, we cannot determine the age of our users. If you believe a child under 13 has provided us with personal information, please contact us at [email protected] and we will take steps to delete such information.
8. International Users
The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States. By using the Service, you consent to this transfer and processing.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Effective date" at the top of this page. We encourage you to review this page periodically. Continued use of the Service after changes constitutes acceptance of the updated policy.
10. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
TriKro LLC (DBA Kromatic)
Email: [email protected]
This document was generated with AI assistance on April 16, 2026.