1. Information We Collect
We collect information you provide directly to us when you create an account, use our services, or communicate with us. This includes:
β’ Account information: name, email address, password, and company name
β’ Usage data: API requests, model usage, token consumption, and associated metadata
β’ Payment information: billing address and payment method details (processed securely via our payment processor β we never store raw card numbers)
β’ Communications: support tickets, feedback, and any other communications you send us
We also collect certain technical data automatically when you use our services, including IP addresses, browser type, device identifiers, and request logs necessary for service operation and security.
2. How We Use Your Information
We use the information we collect to:
β’ Provide, maintain, and improve our services
β’ Process transactions and send related information
β’ Monitor and analyze usage patterns and trends
β’ Detect, investigate, and prevent security incidents and abuse
β’ Send technical notices, updates, security alerts, and administrative messages
β’ Respond to your comments and questions and provide customer service
β’ Comply with legal obligations
We do not and will never sell your personal information to third parties.
3. Data Retention and Prompt Privacy
By default, we do not log or store the content of your prompts or model completions. Request metadata (model used, token count, latency, timestamps) is retained for up to 90 days for billing, analytics, and abuse prevention.
You may configure extended logging in your account settings for debugging purposes. Any logs you enable are stored in your account only and can be deleted at any time.
4. Data Security
We implement industry-standard security measures including:
β’ TLS 1.3 encryption for all data in transit
β’ AES-256 encryption for data at rest
β’ SOC2 Type II compliance with annual audits
β’ Role-based access controls and audit logging internally
β’ Regular penetration testing by third-party security firms
Despite these measures, no security system is impenetrable. We encourage you to use strong API key practices and contact us immediately if you suspect unauthorized access.
5. Your Rights (GDPR & CCPA)
Depending on your location, you may have rights including:
β’ Access: Request a copy of the personal data we hold about you
β’ Correction: Request correction of inaccurate or incomplete data
β’ Deletion: Request deletion of your personal data ("right to be forgotten")
β’ Portability: Request a machine-readable export of your data
β’ Objection: Object to certain processing activities
β’ Restriction: Request restriction of processing in certain circumstances
To exercise these rights, email privacy@10ai.link. We will respond within 30 days.
6. Cookies
We use essential cookies necessary for service operation (session management, authentication). We do not use advertising or tracking cookies.
You can control cookie preferences in your browser settings. Disabling essential cookies may affect service functionality.
7. Third-Party Services
We use third-party services for payment processing (Stripe), infrastructure (AWS, Cloudflare), and analytics (internal tools only). Each of these is bound by data processing agreements ensuring GDPR compliance.
We do not share your data with AI model providers beyond what is necessary to process your API requests.
8. Contact Us
For privacy-related inquiries, contact our Data Protection Officer at privacy@10ai.link or write to us at: 10ai.link Inc., 548 Market St, San Francisco, CA 94104, USA.