Legal

Privacy Policy

Effective April 28, 2026 · Last updated April 28, 2026

Kyaralabs ("Kyara Intelligence," "we," "us," or "our") respects your privacy and is committed to protecting it. This Privacy Policy explains how we collect, use, store, and share your personal data when you use our website at lonailabs.com (the "Site") and our API services (together, the "Service").

By using the Service, you consent to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.

1. What We Collect

1.1 Data You Provide

When you create an account or use the Service, we may collect:

  • Your email address
  • Your password (stored in hashed form only, we never have access to your plaintext password)
  • Payment information (processed by our payment provider, we do not store your card details)
  • Any information you voluntarily include in support communications

1.2 Data Collected Automatically

When you visit the Site or use the Service, we may automatically collect:

  • IP address
  • Browser type and version
  • Device type and operating system
  • Pages visited on the Site and time spent
  • Referring URL
  • API usage metadata (model selected, token count, timestamp, response status code)

1.3 What We Do NOT Collect

We do not collect, store, log, or retain the content of your API requests (prompts) or the responses generated by third-party model providers. Requests are proxied in real time and are not written to disk or any persistent storage on our infrastructure. We have no ability to read, review, or reconstruct the content of your API interactions.

API usage metadata (such as which model was called, how many tokens were consumed, and whether the request succeeded) is recorded for billing and service operation purposes. This metadata does not include the content of your prompts or the generated responses.

2. How We Use Your Data

We use the personal data we collect for the following purposes:

  • Providing the Service: managing your account, processing API requests, tracking credit balances, and delivering the features you use.
  • Billing and payments: processing purchases, maintaining transaction records, and preventing fraudulent transactions.
  • Communication: responding to support requests, sending important service notifications (such as changes to these terms), and contacting you about your account.
  • Service improvement: analyzing aggregated, anonymized usage patterns to improve the reliability and performance of the Service.
  • Security: detecting, preventing, and addressing fraud, abuse, security incidents, and technical issues.
  • Legal compliance: meeting our obligations under applicable laws and regulations.

We do not use your personal data for advertising, profiling, or automated decision-making. We do not sell your personal data.

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Performance of a contract: processing necessary to provide you with the Service, including account management, billing, and API access.
  • Legitimate interest: processing necessary for the security of the Service, fraud prevention, and service improvement, where these interests are not overridden by your rights and freedoms.
  • Legal obligation: processing required to comply with applicable laws and regulations.
  • Consent: where you have given explicit consent, such as for receiving optional communications. You may withdraw consent at any time.

4. How We Share Your Data

We do not sell, rent, or trade your personal data. We may share your data only in the following limited circumstances:

4.1 Payment Processors

We use third-party payment processors to handle transactions. When you make a purchase, your payment information is transmitted directly to our payment provider. We do not store your card number or banking details on our systems. Our payment processors are contractually obligated to protect your data.

4.2 Infrastructure Providers

We use third-party hosting and infrastructure services to operate the Service. These providers process data on our behalf and are bound by contractual obligations to use it only for providing services to us.

4.3 AI Model Providers

When you make an API request, your request is forwarded to the third-party model provider you have selected. Each provider has its own privacy policy and data handling practices. Kyara Intelligence does not control how third-party providers process your data once it leaves our systems. We encourage you to review the privacy policies of the providers you use.

We do not share your account information, email address, or any other personal data with model providers. The only data transmitted to them is the API request itself.

4.4 Legal Requirements

We may disclose your personal data if required to do so by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a government request.

4.5 Corporate Transactions

In the event of a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you via email or a prominent notice on the Site of any change in ownership or uses of your personal data.

5. Cookies

We use a minimal set of cookies to operate the Service:

  • Essential cookies: required for authentication and session management. These cannot be disabled without breaking the Service.
  • Analytics cookies (optional): we may use analytics services to understand how the Site is used. These cookies collect anonymized data and can be disabled through your browser settings.

We do not use advertising cookies, tracking pixels, or third-party marketing cookies.

Disabling Cookies

You can configure your browser to refuse cookies or to alert you when cookies are being sent. If you disable essential cookies, some parts of the Service may not function correctly.

6. Data Retention

We retain your personal data for as long as your account is active or as needed to provide you with the Service. Specifically:

  • Account data (email, hashed password): retained until you request account deletion.
  • Transaction records (purchase history, credit changes): retained for a minimum of 10 years to comply with French accounting and tax obligations.
  • API usage metadata (model, token count, timestamp): retained for 90 days for billing and debugging purposes, then automatically deleted.
  • Prompt and response content: never stored. There is nothing to retain or delete.

When you request account deletion, we will delete or anonymize your personal data within 30 days, except for data we are required to retain by law.

7. Data Security

We implement technical and organizational measures to protect your personal data, including:

  • Encryption of data in transit (TLS)
  • Hashed password storage
  • Access controls limiting who can access personal data
  • Regular security reviews of our infrastructure

No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security.

8. International Data Transfers

Kyara Intelligence is operated from France. If you access the Service from outside the European Economic Area, your data may be transferred to and processed in countries within the EEA.

When your API requests are forwarded to third-party model providers, your request data may be transferred to servers outside the EEA, depending on the provider. These transfers are governed by the privacy policies of the respective providers.

9. Your Rights

If you are located in the EEA, the UK, or Switzerland, you have the following rights under the GDPR:

  • Access: you have the right to request a copy of the personal data we hold about you.
  • Rectification: you have the right to request correction of inaccurate personal data.
  • Erasure: you have the right to request deletion of your personal data, subject to legal retention requirements.
  • Restriction: you have the right to request that we restrict processing of your personal data in certain circumstances.
  • Portability: you have the right to receive your personal data in a structured, commonly used, machine-readable format.
  • Objection: you have the right to object to processing of your personal data based on legitimate interests.
  • Withdrawal of consent: where processing is based on consent, you have the right to withdraw it at any time.

To exercise any of these rights, contact us at privacy@lonailabs.com. We will respond to your request within 30 days.

If you believe that we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection authority. In France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL): https://www.cnil.fr.

10. Children's Privacy

The Service is not directed at children under the age of 13. We do not knowingly collect personal data from children under 13. If you are between 13 and 18 years of age, you must have your parent or guardian's permission to use the Service.

If we become aware that we have collected personal data from a child under 13 without parental consent, we will take steps to delete that information promptly. If you believe we have collected information from a child under 13, please contact us at privacy@lonailabs.com.

11. Third-Party Links

The Site may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read the privacy policies of any third-party sites you visit.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on the Site at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes your acceptance of the updated Privacy Policy.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at:

Kyaralabs
Email: privacy@lonailabs.com

Kyara Intelligence is a brand operated by Kyaralabs.