Privacy Policy
Effective date: June 17, 2026
Controller: Daaeonyx AI (operated by Sthiven R.), United States ("Daaeonyx AI", "we").
1. Who we are
Daaeonyx AI provides an LLM inference API by subscription. This policy explains what personal data we process and your rights.
2. Data we collect
- Account data: name, email, phone, password (stored hashed).
- Subscription/billing metadata: plan, status, period, and a reference to your payment — handled by our Merchant of Record. We never receive or store your card number (PCI handled by the MoR/processor).
- Usage metadata (never the content of your prompts): API request metadata such as timestamps, model, token counts, and rate-limit state, plus billing/security audit records needed to operate and secure the Service.
3. Your API content (prompts and outputs) — Zero Data Retention
We operate zero data retention on your API content. The prompts you send and the outputs we return are processed only to generate your response and are not stored afterward. We do not retain the content of your prompts or outputs, we do not use them to train or fine-tune any model, and we do not build profiles from them. Do not send personal data of third parties to the API without a lawful basis (AUP §5.5).
4. Legal bases (GDPR)
- Performance of a contract — to provide the Service and manage your subscription.
- Legitimate interests — security, fraud prevention, and improving reliability (not training on your content).
- Consent — only where required (e.g. optional marketing emails); withdrawable anytime.
- Legal obligation — tax/accounting (largely discharged by the MoR).
5. How we use data
Provide and maintain the Service; authenticate you; enforce limits and the AUP; bill via the MoR; provide support; secure the platform; comply with law.
6. Sharing — subprocessors
We share the minimum necessary with vetted providers, each under data-processing terms. We engage them in the following categories:
| Category | Purpose |
|---|---|
| Payments / Merchant of Record | Billing, tax, receipts, and card processing |
| Cloud infrastructure & hosting | Database and subscription state |
| Transactional email | Activation and receipt emails |
| Edge & security | CDN, DNS, DDoS/WAF protection |
We do not sell personal data. A Data Processing Agreement and the current list of subprocessors are available to business customers on request.
7. International transfers
We operate from the US; data may be processed in the US and by the providers above. For EU/UK personal data, transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses) where required.
8. Retention
- Prompt/output content: not retained — zero data retention (§3).
- Account data (name, email, phone, hashed password): kept while your account is active and for a limited period after cancellation, to handle disputes and legal/tax obligations, then deleted or anonymized.
- Operational metadata (timestamps, token counts, rate-limit state, and billing/security audit records — never prompt content): retained only as needed to operate, secure, and bill the Service and to meet legal obligations.
- You may request deletion of your account data (§9).
9. Your rights
Subject to law (GDPR/CCPA), you may access, rectify, delete, restrict, object, and request portability of your personal data, and withdraw consent. To exercise, contact privacy@daaeonyxai.com; we respond within the legal timeframe. You may also complain to your local data-protection authority.
10. Security
Industry-standard encryption in transit and at rest; least-privilege access controls; no secrets in logs.
11. Cookies
The dashboard uses strictly necessary cookies (session/auth). We do not use advertising cookies. See our Cookie Policy.
12. Children
Not directed to anyone under 18; we do not knowingly collect their data.
13. Changes
Updates posted at daaeonyxai.com/privacy with a new effective date.
14. Contact
Privacy requests: privacy@daaeonyxai.com. Daaeonyx AI, United States.