Meta Model API Data Commitments
Meta’s responsible innovation principles serve as the foundation for all our work. These principles are specifically crafted to protect people’s privacy so they feel empowered to explore, connect and engage with our products.
How Meta uses your data depends on the type of Services you use.
Standard Services: Meta does not use your Content from Standard Services to train Meta Models. Meta may process Content as necessary to detect, prevent, and respond to violations of the Model API AUP or the Terms of Service, and to develop and improve systems that protect the safety and security of Meta's products and services.
Discounted Services: Meta may use your Content, including Inputs and Outputs, to train, develop, evaluate, and improve Meta's AI models, products, and services. Before using Content from Discounted Services to train artificial intelligence models, Meta takes steps designed to disassociate that Content from your Accounts and your Meta Model API key. However, Meta may use Content for evaluation, safety, abuse, quality, and policy review without first applying those disassociation steps. If you do not want Content used for training, you may upgrade to Standard Services.
In all cases, Meta does not use Customer Data (as defined in the Terms) to train its AI models.
- Customer Data includes your account data, roles, and profile fields (as further defined in the as defined in the Supplemental Managed Accounts Terms).
- Content comprises both the inputs you provide to the Services (such as prompts, documents, code, and other data you submit or authorize the Services to access) and the responses generated by the Services based on your inputs (model responses). For clarity, Content is not considered Customer Data.
Your Content and Customer Data will be used:
- To provide the services;
- To improve and maintain the Meta Model API;
- To detect, prevent, and respond to violations of the Model API Acceptable Use Policy;
- To facilitate Meta's service and marketing communications (using account and contact information);
- To comply with applicable laws; and
- To train and improve Meta’s AI models (Discounted Services Content only, as described above).
Meta uses your Content and Customer Data for the purposes described above and as further detailed in the Terms of Service.
Your Content and Customer Data are stored subject to strict access controls and are only associated with your Account for the purposes described above.
Data Retention.
Meta will retain your Content as described in the Terms and Privacy Policy. You can view and delete your Content through your Account. Certain retention may apply as described in the Terms.
Encryption.
All Content and Customer Data transmitted via the Meta Model API is encrypted in transit using industry-standard TLS 1.2 or later protocols.
Payment Data.
Meta processes all payment card data according to the Payment Card Industry Data Security Standard (PCI-DSS). Payment card numbers are securely stored, encrypted at rest, and stored separately from your profile data. The data provided to facilitate payments within the Services is used only to provide billing services.
Meta's Investments in Security.
Meta performs regular security and vulnerability testing to assess whether key controls are properly implemented and effective. Meta has a vulnerability management program that includes definition of roles and responsibilities, dedicated ownership of vulnerability monitoring, vulnerability risk assessment and patch deployment.
Meta’s security team is responsible for the detection, triage and remediation of vulnerabilities in Meta’s hardware and software. Meta leverages various tools to detect security bugs in its code base, as well as in open-source and third-party code, in order to mitigate or fix security bugs before they make it into shipped Meta’s products and impact our customers.
Meta Model API benefits from Meta's commitment to the security of your data which manifests through the monitoring, controls and measures we have in place to pre-empt or respond to security risks.
Managing the Security Lifecycle.
Meta has established and will maintain an Information Security Management System (ISMS) designed to implement industry-standard information security practices. Meta’s ISMS is designed to protect against unauthorized access, disclosure, use, loss or alteration of Customer Data.
Meta has a security incident response plan for monitoring, detecting and handling possible incidents. The plan includes the definition of roles and responsibilities, communication protocols and post mortem reviews, including root cause analysis and remediation plans. Meta monitors the service for any security breaches and malicious activity. The monitoring process and detection techniques are designed to detect security incidents according to relevant threats and ongoing threat intelligence.
Meta Partners With and Serves Respected Businesses Around the World.
Meta is a trusted partner to many organizations around the world. Our customers trust us because they benefit from Meta’s heavy investments in security technology, resilient infrastructure, policies and processes–investments necessary to protect the data of billions of people worldwide using Meta’s products and services.