Privacy Policy
What Kaista Cloud collects, why it is used, when it is shared, and the choices available to account holders.
1. Scope and accountability
This Privacy Policy applies to Kaista Cloud websites, accounts, dashboards, APIs, support communications, and related services. Kaista Cloud is responsible for the personal information under its control and may use service providers to process information on its behalf.
2. Information we collect
We collect information you provide, information produced by your use of the service, and limited technical information needed to operate and secure the platform.
- Account data, such as email address, display name, role, and authentication records.
- Billing data, such as purchased credit, transaction status, currency, tax or receipt information, and Stripe identifiers. Kaista Cloud does not store full card numbers.
- API and usage metadata, such as API key prefix and hash, model ID, token counts, cost, status, request ID, timestamps, and diagnostic events.
- Device and security data, such as IP address, browser or client information, rate-limit events, and suspected abuse signals.
- Support communications and any information you choose to include in them.
3. Prompt and response content
Kaista Cloud’s usage ledger is designed not to store prompt or response bodies. Request content must nevertheless pass through Kaista Cloud and the infrastructure provider serving the selected model so that inference can be performed.
Do not submit secrets, payment-card data, government identifiers, health records, or other sensitive personal information unless you have confirmed that the selected model and your use case are appropriate and lawful.
4. How information is used
We use information to provide and secure accounts and APIs; route and settle requests; prevent fraud and abuse; process payments; deliver account email; provide support; troubleshoot incidents; comply with law; and improve reliability and user experience.
5. Service providers and disclosures
Information may be processed by hosting and deployment providers, Supabase for authentication and database services, Stripe for payment processing, Resend for transactional email, and infrastructure providers serving selected models. These providers process information under their own terms and privacy practices.
We may also disclose information when required by law; to protect rights, safety, users, or the platform; in connection with a corporate transaction; or with your direction or consent. We do not sell personal information.
6. Cookies and local storage
We currently use authentication and security cookies needed to maintain signed-in sessions, plus a functional cookie that remembers a language selected by the user. We do not currently use advertising cookies, behavioural profiling, or third-party analytics cookies. Details and current durations are published in the Cookie Policy.
7. Retention
Account and operational information is retained while an account is active and for a reasonable period afterward for security, dispute handling, and legal obligations. Billing and tax records may be retained for up to seven years. Support records and routine security logs are generally retained for up to two years unless a longer period is reasonably required.
Because the service is in Private Beta, retention controls will continue to be refined. When information is no longer needed, it is deleted, anonymized, or access-restricted where practical and legally permitted.
8. International processing
Kaista Cloud operates from British Columbia, but providers and model infrastructure may process information in Canada, the United States, or other countries. Information may therefore be subject to the laws of those jurisdictions.
9. Security
We use access controls, server-side secrets, hashed customer API keys, encrypted network transport, row-level database controls, request limits, and audit records. No system is completely secure, and you are responsible for protecting your credentials and endpoint environment.
10. Your choices and rights
You may request access to or correction of personal information, update account information, revoke API keys, or request account closure by contacting us. Requests may be limited where retention is required for security, billing, legal claims, or compliance.
11. Contact
Privacy questions and requests should be sent to team@moncepts.com with “Privacy” in the subject line. We may need to verify your identity before responding to an access or deletion request.