Privacy Policy

Last updated: June 4, 2026

This Privacy Policy explains how Distill Energy, Inc. ("Distill," "we," "us") collects, uses, and shares personal data for which it is responsible. It applies to our website, our probabilistic energy forecasting products and APIs, and related communications (the "Service").

1. Our Role

Distill acts as a controller of the personal data described in this Policy — that is, it decides how and why that data is used. The personal data we control relates to website visitors, prospects, and the individual users who administer or access customer accounts.

The Service is not intended to receive personal data as part of customer-submitted data ("Customer Data"). Under our Terms of Service, customers agree not to submit personal data to the Service and warrant that the data they provide is aggregated and/or de-identified so that it cannot reasonably be used to identify an individual. Accordingly, Distill does not act as a processor of personal data on a customer's behalf, and this Policy does not describe such processing, unless Distill and a customer separately enter into a written Data Processing Agreement (DPA). If personal data is inadvertently submitted to the Service, we may delete, quarantine, or return it as described in our Terms of Service.

2. Personal Data We Collect

You provide to us:

  • Identity and contact details (name, business email, phone, job title, employer).
  • Account credentials and preferences.
  • Billing and payment information (often handled by our payment processor — see Section 5).
  • Communications you send us (support requests, sales inquiries).

Collected automatically:

  • Device and usage data (IP address, browser type, pages viewed, API call metadata, timestamps).
  • Cookies and similar technologies (see Section 6).

From third parties:

  • Information from analytics, marketing, and enrichment providers, and from your colleagues who invite you to an account.

We do not seek to collect special-category/sensitive personal data through the Service. Please do not submit it unless requested.

3. How and Why We Use Personal Data

We use personal data to:

  • provide, secure, maintain, and improve the Service;
  • create accounts, authenticate users, and provide support;
  • process payments and manage subscriptions;
  • communicate about the Service, including service and security notices;
  • send marketing where permitted (you can opt out at any time);
  • analyze usage to improve features and performance;
  • comply with legal obligations and enforce our terms.

Legal bases (EEA/UK GDPR). Where the EU or UK GDPR applies, we rely on the following legal bases under Article 6(1) for the purposes above:

  • Providing, maintaining, and securing the Service; creating and administering accounts; authenticating users; and providing support — performance of a contract (Art. 6(1)(b)) where you are the individual contracting with us; otherwise our legitimate interests (Art. 6(1)(f)) in delivering and securing the Service we provide to our customers. Securing our systems and preventing fraud also rests on our legitimate interests (Art. 6(1)(f); see Recital 49).
  • Processing payments and managing subscriptions — performance of a contract (Art. 6(1)(b)), and compliance with a legal obligation (Art. 6(1)(c)) for tax, accounting, and record-keeping requirements.
  • Sending service, transactional, and security communications — performance of a contract (Art. 6(1)(b)) or our legitimate interests (Art. 6(1)(f)) in keeping users informed about the Service they use.
  • Sending marketing communications — your consent (Art. 6(1)(a)) where required by law; otherwise our legitimate interests (Art. 6(1)(f)) in promoting our products to business contacts, subject to your right to opt out at any time.
  • Analyzing usage to improve and develop the Service — our legitimate interests (Art. 6(1)(f)) in understanding and improving how the Service is used.
  • Complying with legal obligations and enforcing our terms — compliance with a legal obligation (Art. 6(1)(c)), and our legitimate interests (Art. 6(1)(f)) in establishing, exercising, or defending legal claims and enforcing our agreements.

Where we rely on legitimate interests, we have weighed those interests against your rights and freedoms. Where we rely on consent, you may withdraw it at any time without affecting processing carried out before withdrawal. Separate rules (such as the ePrivacy Directive / PECR) may also govern electronic marketing and the use of cookies — see Section 4.

4. Cookies and Tracking

We may use cookies and similar technologies for essential functionality and analytics. If cookies are in use, you can control non-essential cookies through our cookie banner.

5. How We Share Personal Data

  • Service providers / subprocessors that help us run the Service (hosting, analytics, payments, email, support), under contracts limiting their use of the data.
  • Professional advisors (lawyers, auditors, accountants).
  • Legal and safety disclosures where required by law or to protect rights, safety, or the integrity of the Service.
  • Business transfers in connection with a merger, acquisition, or sale of assets.

We do not sell personal data in the conventional sense.

6. International Data Transfers

We may process personal data in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum for UK data), together with a transfer risk assessment and supplementary measures where appropriate.

7. Data Retention

We keep personal data only as long as needed for the purposes described, to comply with legal obligations, resolve disputes, and enforce agreements, after which we delete or de-identify it.

8. Security

We maintain administrative, technical, and physical safeguards designed to protect personal data. No system is perfectly secure, and we cannot guarantee absolute security.

9. Your Rights

Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal data, and to withdraw consent. To exercise rights, contact us at info@distill.energy. We will respond as required by applicable law and will not discriminate against you for exercising your rights.

  • EEA/UK (GDPR): you may also lodge a complaint with your supervisory authority.
  • California (CCPA/CPRA): you have rights to know, delete, correct, and to opt out of "sale"/"sharing"; we will honor authorized agent and opt-out requests as required.
  • Inadvertently submitted data: if you believe personal data has been submitted to the Service within Customer Data (which our Terms prohibit), contact us at info@distill.energy and we will delete or return it. We do not control or use such data.

10. Children

The Service is intended for businesses and is not directed to children, and we do not knowingly collect personal data from children under 16, per applicable law.

11. Changes to This Policy

We may update this Policy from time to time. We will post the updated version with a new "Last updated" date and, where required, provide additional notice.

12. Contact Us

Distill Energy Inc. — 8 The Green, Ste B, Dover, DE 19901

Privacy inquiries: info@distill.energy

Distill is an interconnected platform. Click a node to explore. Drag to rearrange.