Privacy Policy

Effective Date: February 27, 2025

1. Introduction

At Kriora.com ("we", "our", or "us"), your privacy is important to us. This Privacy Policy describes how we collect, use, retain, and protect your personal data when you use our AI API services (the "Service"). By using the Service, you agree to the terms of this Policy.

2. Information We Collect

We collect only the minimal necessary information to operate and secure the Service:

  • Email address — for account creation, support, and communications
  • API usage data — such as request timestamps, IP addresses, usage volume, and error logs

We do NOT collect, store, or log the following:

  • Prompts sent to our API
  • Responses generated by the API
  • User-submitted text, files, or media
  • Passwords (if using external authentication)

Your input and output content are processed in-memory only and are never written to persistent storage.

3. Zero-Retention Policy for Prompts and Responses

We operate under a strict zero-retention policy for all user content:

  • We do not log, store, or retain user prompts, responses, or generated content.
  • All such data is discarded immediately after real-time processing is completed.

This ensures that no user content is accessible, viewable, or retrievable after a session ends.

4. No Use of Data for Model Training

We respect your data confidentiality:

  • We do not use any customer data—prompt inputs, completions, or usage content—for model training, fine-tuning, optimization, or dataset enrichment.
  • We also do not aggregate prompt data for analytics or pattern recognition.

All AI model improvements are performed independently of user data.

5. How We Use Your Information

We use your email and usage data to:

  • Authenticate and manage accounts
  • Monitor API usage and performance
  • Detect abuse, prevent fraud, and ensure availability
  • Process payments and maintain billing records
  • Respond to support requests

We do not use your information for advertising or profiling.

6. User Responsibility for Generated Content

You are solely responsible for any content submitted to or generated through the API.

Kriora.com does not monitor, moderate, or censor any prompts or outputs. You agree not to use the Service to generate illegal, harmful, misleading, or offensive content. You are fully responsible for ensuring that your use complies with all applicable laws and ethical guidelines.

We are not liable for misuse or consequences of content generated by you or your users.

7. Legal Basis for Processing (for EU/EEA users)

If you are located in the EU/EEA or similar jurisdictions, we process your data on the following legal bases:

  • Your explicit consent
  • Our legitimate interests (e.g., fraud prevention, security)
  • Fulfillment of contractual obligations
  • Legal compliance when required

8. Data Retention and Deletion

We retain only email and usage metadata necessary to:

  • Provide the Service
  • Support billing and compliance
  • Fulfill legal obligations

You may request deletion of your account and associated personal data at any time by contacting us at [email protected]. We will respond promptly and either delete or anonymize your data unless legally required to retain it.

9. Security Measures

We apply industry-standard security practices to protect your data:

  • Encryption in transit (TLS) and at rest
  • Strict access controls and internal audit logs
  • Segregated environments for processing and infrastructure
  • Routine monitoring for unauthorized access and abuse

However, no system is completely secure, and we cannot guarantee absolute protection from all threats.

10. Sharing and Disclosure

We do not sell or rent your personal data.

We may share your information only with:

  • Third-party processors (e.g., Stripe for billing), bound by confidentiality and data protection agreements
  • Legal authorities in response to subpoenas, court orders, or applicable legal obligations
  • Successors in the event of a merger, acquisition, or business transfer

11. Cookies and Tracking Technologies

We may use minimal cookies or tracking technologies to:

  • Authenticate sessions
  • Detect suspicious activity
  • Analyze usage trends (non-identifying)

You may disable cookies via your browser, but doing so may limit some Service functionality. We do not use cookies for advertising or marketing purposes.

12. International Data Transfers

Our infrastructure may process data in countries outside your jurisdiction. By using the Service, you consent to such transfers. We take reasonable legal and technical measures (such as standard contractual clauses) to protect your data in these transfers.

13. Limitation of Liability for User Content

Kriora.com shall not be liable for any content generated, accessed, or distributed by users through our API. This includes but is not limited to content that is inaccurate, offensive, misleading, harmful, or unlawful.

We disclaim all liability for damages arising from user-generated content, including those caused by misuse of the Service.

14. Your Rights (Where Applicable)

Depending on your location, you may have the right to:

  • Access personal data we hold about you
  • Correct inaccurate data
  • Request data deletion or restriction
  • Object to data processing
  • File a complaint with a data protection authority

To exercise any of the above, please contact [email protected].

15. Children's Privacy

This Service is not intended for individuals under the age of 13, or the minimum age required by applicable law. We do not knowingly collect personal data from children. If you believe a child has submitted data to us, please contact us immediately for removal.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be announced on our website or via email. Continued use of the Service after such updates constitutes acceptance of the revised terms.

17. Contact Us

If you have questions or requests regarding this Privacy Policy or your data, contact us at: 📧 [email protected].