Last updated: April 25, 2026
Kyma API is a service of Affitor LLC (Wyoming, USA), doing business as Kyma API. This policy explains what we collect, why, how long we keep it, and your choices.
Account information
Your email address, optional display name, and a securely hashed password when you create an account. If you sign in with Google, we receive your email, name, and Google profile photo URL from Google Sign-In.
API requests
When you call our API, we log the prompt or message content, the model used, token counts, response time, status code, and basic connection metadata (IP address, user agent, source app fingerprint where present). We collect this to monitor service quality, prevent abuse, debug failures, settle billing accurately, and respond to take-down obligations.
Generated assets
For image, video, and audio models, the generated file is stored in private object storage and served back to you via a signed URL. We also keep a cryptographic hash of the file for safety and abuse-investigation purposes for the same 90-day window as request logs.
Dashboard chat
If you use our in-dashboard chat playground, conversations are saved to your account so you can return to them. You can delete any conversation at any time.
Payment information
Payments are processed by Stripe. Stripe holds your card details under its own privacy policy. We never see or store the card number, CVC, or expiry. We do receive a Stripe customer ID, the last four digits, brand, and country of the card (for fraud screening).
Cookies and local storage
We store your session token in localStorage to keep you logged in. We use a small number of first-party cookies for session and preference state. We do not use third-party advertising or cross-site tracking cookies.
Kyma is an aggregator. To actually run a model, your request is forwarded to third-party AI infrastructure operated by the model creator or by an authorized hosting partner. They process your Inputs to produce Outputs and do not retain your data beyond what is needed to serve the request, except where their own terms or law require otherwise.
Some specific routing notes worth flagging:
API request logs (prompts, response content, token counts, request metadata): 90 days, then auto-deleted.
Generated image, video, and audio assets: 24 hours by default. Pass a retain: 30d flag at request time to extend to 30 days. Asset hashes are kept on the same 90-day cycle as request logs.
Dashboard chat conversations: kept until you delete them.
Usage metadata (counts, timing, no content): retained indefinitely for analytics, ranking, and billing reconciliation.
Account data: kept while your account is active and for up to 12 months after deletion to satisfy tax, accounting, and fraud-prevention obligations.
Take-down records: kept for at least one year as required by U.S. and E.U. law.
Kyma is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Image, video, and audio generation models require users to be 18 or older. If you believe a child has provided us with personal information, contact us at privacy@kymaapi.com and we will delete it.
Kyma is operated from the United States. By using the service, you consent to your data being processed in the United States and in any country where our service providers operate. For users in the EEA, UK, or Switzerland, transfers outside your region rely on Standard Contractual Clauses or other lawful transfer mechanisms with our processors.
We use encrypted connections (HTTPS), securely hashed passwords, and host our database on Supabase with enterprise-grade security. Production secrets are stored in Railway and Vercel environment variables and rotated on a regular cadence and after any suspected compromise. We review our practices regularly. No system is perfectly secure — please notify security@kymaapi.com if you discover a vulnerability.
We may update this policy as the service evolves. Material changes are announced by email or in-product banner at least 14 days before they take effect.