← Back to Kyma

Privacy Policy

Last updated: April 25, 2026

Kyma API is a service of Affitor LLC (Wyoming, USA), doing business as Kyma API. This policy explains what we collect, why, how long we keep it, and your choices.

The short version

  • We log API requests (including message content) for 90 days, then auto-delete.
  • We store image, video, and audio outputs for 24 hours by default, or 30 days if you opt in.
  • We do not train AI models on your data.
  • We do not sell your data.
  • We forward requests to third-party AI infrastructure to actually run the models. They process your input under their own privacy practices.

What we collect

Account information

Your email address, optional display name, and a securely hashed password when you create an account. If you sign in with Google, we receive your email, name, and Google profile photo URL from Google Sign-In.

API requests

When you call our API, we log the prompt or message content, the model used, token counts, response time, status code, and basic connection metadata (IP address, user agent, source app fingerprint where present). We collect this to monitor service quality, prevent abuse, debug failures, settle billing accurately, and respond to take-down obligations.

Generated assets

For image, video, and audio models, the generated file is stored in private object storage and served back to you via a signed URL. We also keep a cryptographic hash of the file for safety and abuse-investigation purposes for the same 90-day window as request logs.

Dashboard chat

If you use our in-dashboard chat playground, conversations are saved to your account so you can return to them. You can delete any conversation at any time.

Payment information

Payments are processed by Stripe. Stripe holds your card details under its own privacy policy. We never see or store the card number, CVC, or expiry. We do receive a Stripe customer ID, the last four digits, brand, and country of the card (for fraud screening).

Cookies and local storage

We store your session token in localStorage to keep you logged in. We use a small number of first-party cookies for session and preference state. We do not use third-party advertising or cross-site tracking cookies.

How we use your data

  • Provide the service — route your requests, return Outputs, store generated assets briefly so you can download them.
  • Bill accurately — track tokens, seconds, characters, and image counts for credit deductions.
  • Keep the service safe — detect abuse, fraud, multi-account farming, and Acceptable Use Policy violations. This includes scanning Inputs and Outputs against safety classifiers (such as Hive's moderation API) for categories like CSAM, NCII, and synthetic media of identifiable real people.
  • Improve reliability — understand error patterns, latency issues, and which models perform best.
  • Comply with law — respond to legitimate legal process, take-down notices, and statutory reporting obligations (for example, mandatory NCMEC reporting for suspected CSAM).

What we don't do

  • We do not train AI models on your Inputs or Outputs.
  • We do not sell your data to third parties.
  • We do not use your content for advertising or share it with ad networks.
  • We do not run third-party trackers on logged-in dashboard pages.

Third-party AI infrastructure

Kyma is an aggregator. To actually run a model, your request is forwarded to third-party AI infrastructure operated by the model creator or by an authorized hosting partner. They process your Inputs to produce Outputs and do not retain your data beyond what is needed to serve the request, except where their own terms or law require otherwise.

Some specific routing notes worth flagging:

  • DeepSeek models routed via DeepSeek Direct are processed on infrastructure operated by DeepSeek in the People's Republic of China. If this matters for your use case, choose an alternative model.
  • Image, video, and speech models are routed through licensed gateway partners (currently fal.ai and Replicate). Their privacy practices apply to the model execution step.
  • Payment processing is by Stripe.
  • Email delivery is by Resend.
  • Database and authentication are by Supabase.
  • Object storage for generated assets is by Vercel Blob.
  • Safety moderation is by Hive AI.

Data retention

API request logs (prompts, response content, token counts, request metadata): 90 days, then auto-deleted.

Generated image, video, and audio assets: 24 hours by default. Pass a retain: 30d flag at request time to extend to 30 days. Asset hashes are kept on the same 90-day cycle as request logs.

Dashboard chat conversations: kept until you delete them.

Usage metadata (counts, timing, no content): retained indefinitely for analytics, ranking, and billing reconciliation.

Account data: kept while your account is active and for up to 12 months after deletion to satisfy tax, accounting, and fraud-prevention obligations.

Take-down records: kept for at least one year as required by U.S. and E.U. law.

Your choices and rights

  • Access and export — request a copy of your account data and request logs.
  • Correct — update your email, display name, billing details from the dashboard.
  • Delete — delete a chat conversation from the dashboard, or request full account deletion via privacy@kymaapi.com.
  • Object / restrict — if you are in the EEA, UK, or Switzerland, you have additional rights under GDPR / UK GDPR including the right to object to certain processing and the right to lodge a complaint with your supervisory authority.
  • California residents — under CCPA / CPRA you have the right to know, delete, correct, and to opt out of any "sale" or "share" of personal information. We do not sell or share for cross-context advertising.

Children

Kyma is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Image, video, and audio generation models require users to be 18 or older. If you believe a child has provided us with personal information, contact us at privacy@kymaapi.com and we will delete it.

International transfers

Kyma is operated from the United States. By using the service, you consent to your data being processed in the United States and in any country where our service providers operate. For users in the EEA, UK, or Switzerland, transfers outside your region rely on Standard Contractual Clauses or other lawful transfer mechanisms with our processors.

Security

We use encrypted connections (HTTPS), securely hashed passwords, and host our database on Supabase with enterprise-grade security. Production secrets are stored in Railway and Vercel environment variables and rotated on a regular cadence and after any suspected compromise. We review our practices regularly. No system is perfectly secure — please notify security@kymaapi.com if you discover a vulnerability.

Changes to this policy

We may update this policy as the service evolves. Material changes are announced by email or in-product banner at least 14 days before they take effect.

Contact