Legal Documents
We believe you deserve to know exactly how we operate, what we do with your data, and what standards we hold ourselves to. These documents are written to be readable, not to obscure.
Last Updated: July 1, 2025 · Effective Date: July 1, 2025
PipeFish Labs ("we," "our," or "us") is committed to protecting the privacy of individuals who visit our website, engage our services, or interact with our platforms. This Privacy Policy explains how we collect, use, disclose, and safeguard your information.
We collect information you provide directly to us, including:
We also automatically collect certain technical information when you visit our website:
We use collected information to:
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
We may share your information with:
Client data processed as part of service delivery is subject to a separate Data Processing Agreement (DPA) and is never used for our own marketing or product development.
We retain personal information for as long as necessary to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements. Client project data is retained for 3 years after contract termination unless otherwise agreed. You may request deletion of your data at any time (subject to legal hold requirements).
Depending on your jurisdiction, you may have the right to:
To exercise any of these rights, contact us at pipefish.labs@gmail.com. We respond to all requests within 30 days.
We use strictly necessary cookies for site functionality, and optional analytics cookies (with your consent). We do not use advertising or tracking cookies. You can manage cookie preferences through your browser settings or our cookie consent banner.
We operate from the United States. If you are located in the EU, UK, or other jurisdictions with data transfer restrictions, we rely on Standard Contractual Clauses (SCCs) as our transfer mechanism. We maintain EU-US Data Privacy Framework certification where applicable.
Privacy inquiries: pipefish.labs@gmail.com
Data Protection Officer: pipefish.labs@gmail.com
Last Updated: July 1, 2025 · Effective Date: July 1, 2025
By accessing our website or engaging our services, you agree to these Terms of Service. If you are entering into these terms on behalf of an organization, you represent that you have the authority to bind that organization.
PipeFish Labs provides AI automation, consulting, software development, and related professional services as described in individual Statements of Work (SOW) or Service Agreements. Specific deliverables, timelines, and payment terms are governed by those agreements. These Terms provide the baseline framework.
Upon full payment, you own all custom code, models, documentation, and other deliverables created specifically for your project. We retain ownership of our pre-existing tools, frameworks, libraries, and methodologies ("Background IP") which may be incorporated into your deliverables under a perpetual, non-exclusive license.
You retain ownership of all data, systems, and materials you provide to us. We do not claim any ownership over your proprietary information.
Both parties agree to maintain the confidentiality of each other's Confidential Information. All client engagements are covered by our standard Mutual Non-Disclosure Agreement (MNDA) unless a separate NDA is executed. Confidential Information does not include information that is publicly known, independently developed, or received from a third party without restriction.
Invoices are due within 30 days of issuance unless otherwise specified. Late payments accrue interest at 1.5% per month. We reserve the right to suspend services for accounts more than 45 days past due, with 7 days' written notice. All fees are non-refundable except as explicitly stated in your Service Agreement.
To the maximum extent permitted by law, PipeFish Labs' total liability for any claims arising from our services shall not exceed the total fees paid in the 12 months preceding the claim. We are not liable for indirect, incidental, consequential, or punitive damages. This limitation does not apply to willful misconduct, fraud, or violations of confidentiality obligations.
Services are provided "as is" and "as available." We disclaim all warranties, express or implied, including merchantability and fitness for a particular purpose, except as explicitly stated in your Service Agreement. We warrant that deliverables will substantially conform to agreed specifications for 90 days after delivery.
These Terms are governed by the laws of the State of Florida, USA, without regard to conflict of law principles. Disputes shall first be subject to good-faith negotiation for 30 days, then binding arbitration under JAMS rules. Class actions and jury trials are waived.
We may update these Terms from time to time. Material changes will be communicated 30 days in advance. Continued use of our services after notice constitutes acceptance of revised terms.
Last Updated: July 1, 2025 · Version 2.1
PipeFish Labs is committed to building AI systems that are safe, transparent, fair, and beneficial. This policy codifies our operational standards and the commitments we make to every client.
We design AI systems to be interpretable. Where black-box models are deployed, we implement explainability layers (SHAP, LIME, or custom attribution) that allow stakeholders to understand why decisions are made. We never deploy AI in high-stakes decisions (credit, hiring, medical) without explainable output.
All models we deploy undergo bias auditing before production release. We test for demographic parity, equalized odds, and disparate impact across protected characteristics. Bias audit reports are provided to clients and updated on at least an annual basis.
We maintain a "human in the loop" principle for all consequential decisions. Every autonomous AI system we build includes escalation paths, override mechanisms, and audit trails. Fully automated decisions are only deployed where explicitly agreed and legally permissible.
We collect and process only the data strictly necessary for the task. Privacy considerations are embedded at the design stage, not bolted on after. We apply differential privacy and federated learning techniques where technically appropriate and client-beneficial.
We do not build AI systems designed to deceive, manipulate, surveil, or harm individuals or groups. We decline engagements that would require creating disinformation systems, mass surveillance infrastructure, or tools that circumvent individuals' legal rights.
We operate in accordance with the EU AI Act requirements applicable to high-risk AI systems. Clients in regulated sectors receive conformity assessment support, Annex IV documentation, and ongoing compliance monitoring as standard components of regulated deployments.
We track compute consumption for all AI workloads and provide clients with carbon footprint estimates. We prefer compute-efficient architectures and offset our direct operational emissions annually through verified carbon credits.
Last Updated: July 1, 2025
PipeFish Labs is committed to keeping our systems and client data secure. We welcome responsible disclosure from the security research community and take all reports seriously.
If you believe you've discovered a security vulnerability in our systems or client-deployed infrastructure, please consult our RFC 9116 security disclosure file at /.well-known/security.txt or submit your report directly to pipefish.labs@gmail.com.
You may encrypt your report using our PGP public key (available on request). Please include:
Initial acknowledgment of your report
Preliminary severity assessment and triage
Patch development for confirmed critical issues
Coordinated public disclosure (if applicable)
We will not pursue legal action against researchers who follow responsible disclosure guidelines, avoid accessing or modifying data beyond what is necessary to confirm the vulnerability, do not perform denial-of-service attacks, and report findings in good faith. We appreciate the security community's contributions to keeping our systems safe.