AI21 Labs – Privacy Policy

Last Updated: August 2, 2026

Introduction and Scope

AI21 Labs Ltd., together with its subsidiaries and affiliates (“AI21,” “we,” “us,” or “our”), respects your privacy and is committed to protecting Personal Data. This Privacy Policy (this “Policy”) describes how we collect, use, disclose, and otherwise process Personal Data in connection with our website at https://www.ai21.com and other websites we operate (each, a “Site”), and our proprietary artificial-intelligence systems, platforms, applications, application programming interfaces (APIs), tools, models and related products and services (collectively, the “AI Systems,” and together with the Site, the “Services”).

“Personal Data” or “Personal Information” means any information that, alone or combined with other information, can identify, relate to, describe, or be reasonably linked to an identified or identifiable natural person. When you (a “User”) access or use the Services, your Personal Data will be processed as described in this Policy.

This Policy applies to Users of our Services, including business customers, the individual developers and other authorized users acting under a business customer’s account, and individual developers who register in their own right. It also applies to visitors to our Site and to individuals who contact us, subscribe to our communications, or interact with us on social media. You are not legally required to provide Personal Data, but some information is necessary for us to provide the Services, for example to create and administer your account or to respond to a support request. By accessing or using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, please do not access or use the Services.

This Policy forms part of, and should be read together with, our Terms of Service and any other agreement that references it. Capitalized terms used but not defined in this Policy have the meaning given to them in our Terms of Service.

It is important to understand the two distinct capacities in which AI21 may process Personal Data, because they are governed by different rules.

AI21 as a Data Controller. For most Personal Data we collect directly in operating our business and Services, such as account-registration data, billing and contact details, communications with us, prompts and inputs, and  technical and      Usage Data ,      AI21 determines the purposes and means of processing and therefore acts as a “data controller” (and as a “business” under U.S. state privacy laws, and as the database owner or holder under Israeli law). This Policy governs      processing by a data controller.

AI21 as a Data Processor. When a  business customer uses the AI Systems, it may submit, upload, transmit, route, or otherwise make available content and data through the Services, including prompts, inputs, files, datasets, configurations, and the resulting outputs (collectively, “Customer Data”). To the extent Customer Data contains Personal Data, AI21 processes that Personal Data on behalf of, and under the instructions of, the business customer, who is the data controller (and the “business” or, where applicable, the “service provider’s” customer) for that data. In that capacity AI21 acts as a “data processor” (or “service provider” or the equivalent term under applicable data protection laws).

This Privacy Policy does not govern Customer Data for which AI21 acts as a Data Processor. Such data is described herein for informational purposes only. Our processing of Customer Data is governed by the agreement between AI21 and the relevant business customer, including any applicable data processing agreement (“DPA”), and by that customer’s own privacy notices and instructions. The      customer is responsible for the legality of the Customer Data, for providing all required notices, and for obtaining all consents and legal bases necessary for AI21 to process the Customer Data, and for honoring data-subject requests relating to it. If you are an individual whose Personal Data appears in Customer Data and you have questions or wish to exercise your rights, please contact the relevant business customer directly; we will reasonably assist that customer as required under our agreement and applicable law. Where you use the Services as an individual developer in your own right (and not on behalf of an organization), we generally act as a controller of your account and usage data, while your own inputs and outputs are handled as described in the “Inputs, Outputs, and AI Processing” section below and in our Terms of Service.

Data Controller and Contact Information

AI21 Labs Ltd. is the data controller for the Personal Data processed under this Policy. Our principal place of business is in Tel Aviv, Israel. For users in the European Economic Area (“EEA”), the United Kingdom (“UK”), or Switzerland, AI21 is the controller responsible for your Personal Data under the EU and UK General Data Protection Regulation (collectively, the “GDPR”). For users in Israel, AI21 is the database owner under the Israeli Privacy Protection Law, 5741-1981.

You may contact us, including our privacy team, at [email protected]. If you are in the EEA or UK and we are required to designate a representative, the contact details of our EU/UK representative are available on request at [email protected]

Categories of Personal Data We Collect

We collect Personal Data in the following categories, depending on how you interact with the Services.

Information you provide directly. When you create an account or register, we collect account and registration data such as your name, email address, username, password, organization name, job title, country, and, for organizational accounts, administrator and authorized-user details (“Account Information”). We collect Personal Data that you provide in the input to our Services, including your prompts and other content you upload, and data from connected services⁠, depending on the features you use (“User Content”). Any text or data you input into the Services that contains Personal Data may be collected by us; where you act on behalf of a business customer, such inputs are Customer Data processed under that customer’s instructions and are addressed in the “When This Policy Does Not Apply” section above, not by this Policy. When you contact us or communicate with us, such as via email, our pages on social media sites, for support, sales, or other inquiries, or when you subscribe to our newsletters or distribution lists, we collect the contents and metadata of those communications, including your name, contact information, work email, telephone number, workplace, and the contents of the messages you send, as well as any other information you choose to provide (“Communication Data”).

Information collected automatically. When you access the Site or the AI Systems, we automatically collect the following categories of information (collectively, “Usage Data”):                              

Log Data: Information that your browser or device automatically transmits when you access the Services, including your Internet Protocol (IP) address, browser type and settings, referring URLs, the date and time of your requests, and how you interact with the Site and AI Systems.

Activity Data: Information about your activity across the Services, including pages and features viewed, time spent, click and interaction patterns, session data, and, for the AI Systems specifically, operational and usage metrics relating to your access, configuration, and consumption of the Services,  for example, request volumes, routing and model-selection metrics, token and resource consumption, latency and performance data, and error logs  which we use to operate, secure, meter, and improve the Services.

Device Information: Information about the device you use to access the Services, such as device name, type and unique identifiers, operating system, and browser version. The specific information collected depends on the type of device and its settings.

Location Information: We derive approximate location (such as country or region) from your IP address for security purposes (for example, detecting unusual login activity), analytics, and geo-compliance (for example, applying geographic access rules required by law). We do not collect precise GPS-based location data unless a specific Service feature requires it and you expressly enable it.

Cookies and Similar Technologies: We use cookies, pixels, SDKs, log files, and similar technologies to operate and administer the Services, maintain your preferences, assist with authentication and support, and improve your experience. For details about the cookies and tracking technologies we use and how to manage your preferences, please see the “Cookies and Tracking Technologies” section below.

Information from third parties. We may receive Personal Data about you from affiliates, business partners, resellers, identity-verification and fraud-prevention providers, marketing and business-intelligence providers, social-media platforms where you interact with our presence, and publicly available sources.

Inputs, Outputs, and AI Processing

The Services use artificial-intelligence technology. As part of providing the Services, Personal Data may be processed, in whole or in part, by AI systems. Where AI21 acts as a controller (for example, for individual-developer accounts or for our own operational data), we process inputs and outputs to deliver and operate the Services, to return the outputs you request, to maintain security and prevent abuse, to provide support, and to maintain, troubleshoot, and improve the Services. Consistent with our Terms of Service, and unless otherwise agreed in writing or required to provide the Services, we do not use your inputs or outputs to train AI21’s foundational or generally available AI models. Because AI output is probabilistic and may be inaccurate or not unique across users, you are responsible for reviewing outputs before relying on them, and AI21 is not responsible for decisions you make based on outputs. Where AI21 processes inputs and outputs as a processor on behalf of a business customer, that processing is governed by our agreement with the customer and not by this Policy.

How We Use Your Personal Data

We use Personal Data for which we are the controller for the following purposes: to create, administer, and secure your account and to provide, maintain, and operate the Services; to authenticate users and administer access for organizational accounts; to process transactions, calculate and collect fees, and meter consumption; to respond to your inquiries and provide customer and technical support; to send service-related and administrative communications, such as security alerts, billing notices, and changes to our policies; to send marketing and promotional communications where permitted, subject to your choices; to operate, analyze, troubleshoot, secure, improve, and develop the Services and our other products, including by analyzing usage patterns and creating statistics, benchmarks, and aggregated insights; to personalize and improve your experience; to detect, prevent, investigate, and respond to fraud, abuse, security incidents, and violations of our terms and policies, including bias and quality audits; to comply with applicable laws, regulations, legal process, and governmental requests, and to establish, exercise, or defend legal claims; and to conduct internal administration, audits, business planning, and corporate transactions.

Aggregated and De-Identified Information

We may aggregate or de-identify Personal Data so that it no longer identifies you, and may use and disclose such aggregated or de-identified information for any lawful purpose, including to analyze and improve the Services, study usage, develop new features, and produce industry benchmarks and reports. When we use de-identified information, we maintain it as de-identified and do not attempt to re-identify it except as permitted by law.

Legal Bases for Processing (EEA, UK, and Switzerland)

If you are located in the EEA, the UK, or Switzerland, we rely on the following legal bases under the GDPR, depending on the processing purpose. The table below summarizes the principal processing activities, the categories of Personal Data involved, and our lawful basis. Where more than one basis may apply, we identify the primary basis. If you reside in, or use the Services within, a jurisdiction where privacy laws require “consent” as the sole or primary legal basis for processing personal data (whether generally, for specific categories of personal data you choose to process, or due to the nature of such processing), your acceptance of our Terms of Service and this Policy will constitute your consent to the processing of your personal data for all purposes outlined in this Policy, unless applicable law mandates a different form of consent. Where consent is the only relevant legal basis for particular processing activities, and you do not provide your consent, we may be unable to provide the Services, in whole or in part.

Processing purposePrincipal data categoriesLegal basis
Creating and administering your account; providing and operating the Services; authentication and access administrationAccount Information; User Content; Usage DataPerformance of a contract with you, or steps taken at your request before entering into a contract
Processing payments, billing, metering consumption, and record-keepingAccount Information; Usage Data (Activity Data)Performance of a contract; legal obligation for record-keeping; legitimate interests in accurate billing records
Responding to inquiries and providing supportCommunication Data; Account InformationPerformance of a contract; legitimate interests in responding to and assisting you
Securing the Services; fraud and abuse prevention; debugging; enforcing our termsUsage Data (Log Data, Activity Data, Device Information); Account InformationLegitimate interests in protecting our users, the Services, and our business; compliance with a legal obligation
Operating, analyzing, improving, and developing the Services and our productsUsage Data; User Content; Information from third parties; aggregated and de-identified dataLegitimate interests in maintaining and improving our Services
Sending marketing and promotional communicationsCommunication Data; Account InformationYour consent, where required, or legitimate interests in direct marketing subject to your right to object
Non-essential cookies, analytics, and trackingUsage Data (Cookies and Similar Technologies, Log Data, Device Information)Your consent, where required under applicable law
Complying with law; responding to legal process; establishing or defending legal claimsAny relevant categoriesCompliance with a legal obligation; legitimate interests in protecting our legal rights

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal, except where, under applicable law in your jurisdiction, consent is the sole available legal basis for the relevant processing, in which case withdrawal of consent may result in our inability to continue providing the relevant services or carrying out the relevant processing. Where we rely on legitimate interests, you may object as described in the “Your Privacy Rights” section, and we will stop processing unless we demonstrate compelling legitimate grounds that override your rights or the processing is necessary for legal claims.

How We Share Your Personal Data

We may disclose Personal Data to the following categories of recipients: We share with our affiliates and corporate group for the purposes described in this Policy. We engage service providers and subprocessors that perform functions on our behalf, such as cloud hosting and infrastructure, content delivery, analytics, payment processing, customer support and engagement, communications, security and fraud prevention, and marketing, which are contractually bound to use Personal Data only to provide services to us and consistent with this Policy. We may share Personal Data with professional advisors such as lawyers, accountants, auditors, and insurers where necessary for advice, risk management, or legal proceedings. We may disclose Personal Data to regulators, courts, law-enforcement, and other authorities where required to comply with law or legal process, to enforce our terms and policies, to investigate or prevent fraud, security threats, or illegal activity, or to protect the rights, property, or safety of AI21, our users, or others. In connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy, or similar transaction, Personal Data may be transferred to the counterparty or successor, subject to this Policy or a successor policy. We may also share Personal Data with your consent or at your direction.

We do not “sell” Personal Data for monetary consideration, and we do not “share” Personal Data for cross-context behavioral advertising or process it for targeted advertising in the manner most people would commonly understand those terms; however, certain uses of cookies and similar advertising technologies may constitute a “sale” or “share” under some U.S. state laws, in which case you may exercise the opt-out rights described below.

Cookies, Analytics, and Tracking Technologies

Our Site and Services use cookies, pixels, SDKs, and similar technologies, as well as third-party analytics, business, marketing, and payment-related tools, to operate and improve the Services, distinguish you from other users, remember your preferences, analyze usage, support billing and fraud detection, enable customer engagement and marketing automation, and, where applicable, deliver relevant content and advertising. These technologies and providers may collect device, usage, and identifier information. We use strictly necessary cookies, which are required for the Services to function and cannot be switched off; performance and analytics cookies, which help us measure and improve performance; functional cookies, which enable enhanced features and personalization; and marketing or targeting cookies, where applicable. A full list of the cookies we use is available on the Cookie List page on our Site. Third-party providers process information in accordance with their own privacy policies, which we encourage you to review. You can manage most cookies through your browser settings and, where we provide one, through our cookie-preference tool, including to withdraw consent to non-essential cookies. Disabling certain cookies may affect the functionality of the Services. We do not currently respond to “Do Not Track” browser signals, as there is no consistent industry standard. We may add or remove analytics and related tools from time to time and will update our disclosures and cookie tools accordingly.

International Data Transfers

We operate globally, and your Personal Data may be transferred to, stored in, and processed in countries other than your own, including Israel, the United States, the EEA, the UK, and other locations where we or our service providers operate. These countries may have data-protection laws that differ from those in your jurisdiction. For transfers from the EEA, UK, or Switzerland to countries that are not the subject of an adequacy decision, we implement appropriate safeguards, principally the European Commission’s Standard Contractual Clauses, or we rely on an adequacy decision or another lawful transfer mechanism. Transfers within the AI21 group are covered by an intra-group data processing agreement requiring an adequate and consistent level of protection. You may request further information about our transfer safeguards at [email protected]

Data Retention

We retain Personal Data for as long as necessary to fulfill the purposes described in this Policy, after which we securely delete or anonymize it. Retention periods depend on the nature and sensitivity of the data, the purposes for which we process it, applicable legal, regulatory, tax, and accounting requirements, and our legitimate business needs. We may retain Personal Data for longer where required to comply with law, to maintain accurate records of our dealings with you in the event of complaints or disputes, where we reasonably anticipate litigation, or in aggregated or de-identified form. The Services are not intended to serve as a data-storage or archiving product, and you remain responsible for maintaining your own records and backups of your inputs and outputs.

Information Security

We implement appropriate technical, organizational, and administrative measures designed to protect Personal Data against accidental loss and unauthorized access, alteration, disclosure, or destruction, consistent with applicable industry certifications we maintain. These measures include encryption of data in transit and at rest, access controls limiting access to authorized personnel, security assessments and testing, personnel training, and incident-response procedures. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; the security of your data also depends on the security of the devices, networks, and credentials you use, which you are responsible for protecting. If you believe your interaction with us is no longer secure, please contact us at [email protected]

Your Privacy Rights

Depending on your jurisdiction and the applicable law, you may have some or all of the following rights regarding Personal Data for which we are the controller: the right to access and obtain a copy of your Personal Data; the right to correct inaccurate or incomplete data; the right to delete your data, subject to exceptions; the right to data portability; the right to restrict or object to certain processing, including processing based on our legitimate interests; the right to withdraw consent where processing is based on consent; the right to opt out of marketing communications; and the right to opt out of any “sale” or “sharing” of Personal Data and of certain automated processing, where applicable. You also have the right to lodge a complaint with your local data-protection supervisory authority; we ask that you first contact us so we can try to resolve your concern.

To exercise your rights, contact us at [email protected].  You may use an authorized agent to submit a request on your behalf where permitted, with proof of authorization. To protect your privacy, we may take steps to verify your identity before responding, and we may decline or limit a request where permitted by law or where it would adversely affect the rights of others. We will respond within the timeframe required by applicable law. We will not discriminate against you for exercising your rights. If you are an individual whose Personal Data appears in Customer Data processed by AI21 as a processor on behalf of a business customer, please direct your request to that customer, as explained in the “When This Policy Does Not Apply” section.

Email and Marketing Communications

We may send you service-related communications, such as account notifications, security alerts, and transaction confirmations, that are necessary to operate the Services and that you cannot opt out of while using the Services. With your consent, or otherwise as permitted by law, we may also send marketing communications, from which you can opt out at any time by using the “unsubscribe” link in our emails or by contacting us at [email protected].  Opt-out requests may take a reasonable time to process. We comply with applicable anti-spam laws, including the U.S. CAN-SPAM Act.

Third-Party Services and Links

The Services may enable you to access, integrate with, or interact with third-party websites, products, models, or services that we do not own or control (“Third-Party Services”). This Policy does not apply to Third-Party Services, and we are not responsible for their privacy practices or content. Third-Party Services may collect Personal Data directly from you and process it under their own policies, which we encourage you to review.

Children’s Privacy

The Services are intended for business, professional, and developer use and are not directed to children. We do not knowingly collect Personal Data from individuals under the age of eighteen (18). If you believe a child has provided us Personal Data, please contact us at [email protected],  and we will take steps to delete it as required by applicable law.

Notice for California Residents

This section supplements the rest of this Policy and applies to California residents, to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the “CCPA”), applies. It does not apply to Personal Data we process as a service provider on behalf of a business customer.

We collect the categories of personal information described in the “Categories of Personal Data We Collect” section, which may include identifiers; categories listed in California Civil Code section 1798.80(e); protected-classification characteristics; commercial information; internet and electronic network activity; geolocation data; professional or employment-related information; and inferences. We collect this information from the sources described above, including directly from you, automatically from your devices, from affiliates and service providers, from business partners, and from publicly available sources. We use and disclose personal information for the business and commercial purposes described in this Policy. We do not “sell” or “share” personal information in the manner most people would understand those terms, and we do not knowingly sell or share the personal information of consumers under sixteen (16) years of age; however, certain uses of advertising cookies may be treated as a “sale” or “share” under the CCPA, and you may opt out as described above.

California residents have the right to know and access the personal information we collect, use, and disclose; the right to delete personal information, subject to exceptions; the right to correct inaccurate personal information; the right to opt out of the sale or sharing of personal information; the right to limit the use and disclosure of sensitive personal information, where applicable; and the right to non-discrimination for exercising these rights. To submit a request, contact us at [email protected]. We will verify your identity before responding and will respond within the time required by the CCPA. We do not offer financial incentives for the collection of personal information. Where we use automated decision-making technology to make a decision that produces legal or similarly significant effects, we will provide any notices and opt-out rights required by applicable California law. Under California’s “Shine the Light” law, California residents may request information about disclosures of personal information to third parties for their direct-marketing purposes by contacting [email protected]

Other U.S. State Privacy Rights

If you are a resident of a U.S. state with a comprehensive privacy law – including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, or another such state      you may have rights similar to those described above, including the rights to access, correct, delete, and port your personal data, and to opt out of targeted advertising, the sale of personal data, and certain profiling. To exercise these rights, or to appeal a decision on a request, contact us at [email protected]

Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, technologies, or legal requirements. We will post the updated Policy with a new “Last Updated” date and, for material changes, provide additional notice by reasonable means, such as email or an in-product or Site notice. Where required by law, we will obtain your consent before implementing material changes. Your continued use of the Services after the effective date constitutes acceptance of the updated Policy. We may also provide “just-in-time” notices that supplement this Policy or offer additional choices at the point of collection.

Contact Us

If you have questions, concerns, or complaints about this Policy or our privacy practices, or wish to exercise your rights, please contact us first at:

AI21 Labs Ltd. – Attn: Privacy Team / Data Protection Officer – Tel Aviv, Israel – Email: [email protected]