Privacy and data use
Policies for the lab website, contact forms and prepaid deployment trial. Customer deployment responsibilities are agreed separately in writing.
On this page
Website provisions last reviewed . The trial policy review date is shown above.
The rule depends on how a request is paid for, and you can choose to change the paid rule for a rebate. The sections below define each case.
Part A. Trial service
How requests, credit and accounts on the prepaid trial are handled.
Purchased credit: no durable capture or training by default
Purchased-credit requests with training off are not written to the durable capture corpus or used for training or evaluation. With capture enabled, accounts marked for promotional use or explicit training consent may have eligible prompts and completions stored on the serving host and archived, encrypted, in Cloudflare R2. Prompt prefixes may remain in engine memory after a response until evicted or the process restarts. The gateway namespaces prefix reuse by account and cache_salt, not by individual API key.
The single exception is the switch below, which is off unless you turn it on yourself.
Optional: consent to prompt training, 5% of your spend back
In your console under Settings → Training on your prompts you can agree that prompts and completions from your account may be retained and used to improve our models. While that is on, 5% of what you spend is credited back to your balance, one whole day at a time, for each day the switch was on from start to finish. The rebate is calculated from metered spend during that period, not from the price of a credit pack.
It is off by default, it is per account, and you can switch it off at any time; from that moment new capture stops. What we cannot do is withdraw data from a training run that has already completed. Either way, we do not sell prompts and do not share them with another customer. Each change is recorded with its timestamp, so the posture that applied to any given request is auditable.
Promotional credit: prompts may be trained on
New accounts receive free credit only while a promotional offer is open; outside an offer, accounts pay per use from the first request. When a request is paid for out of promotional credit, prompts and completions may be retained and used to improve our models and serving quality. That is the condition attached to free credit, stated here and on the offer terms.
Your first completed purchase ends promotional capture; explicit training consent, if enabled, still applies. If the training condition is not acceptable for your data, buy credit before sending it.
Captured training data is subject to a 24-month deletion policy; account closure starts a 30-day purge deadline, whichever comes first. Purging is performed by our deletion process, with overdue closure alerts and a validated deletion receipt; turning consent off stops new capture, not the retention clock for existing data.
What we keep either way
- Billing metadata
- Billing records contain request identifiers, account or tenant identifiers, API key prefixes where available (not full keys), model, route, timestamps, outcome, token counts and cost; they do not contain prompt or completion bodies. Kept up to 12 months because it is the record behind your invoice.
- Operational logs
- Status codes, latency, error classes, IP address of the calling client. No prompt or completion bodies. Kept up to 30 days.
- Account data
- Your email address, key prefixes, credit ledger, and the referral tag from the link you arrived on. Kept while the account exists.
- Sign-up abuse evidence
- Verified login-provider identity, normalized email and domain patterns, sign-up timing, account and key activity, and a keyed digest of the sign-up network. The raw network address is not stored in this account graph. The digest and local-part comparison shape are removed after 30 days. Decisions and case records stay with the account for support, fraud review, and appeals.
- Payment data
- We never see your card. Paddle processes payments and returns a customer reference and the last four digits of the saved method so the console can show you what auto top-up will charge.
Cookies and tracking
Functional cookies keep you signed in, bind a requested sign-in link to its browser, and let Cloudflare's sign-up challenge distinguish automated traffic. Static website pages do not personalize their content from account cookies. None is used for measurement. There are no advertising pixels and no cross-site tracking.
Page measurement is our own, served from this origin. A view records the path, the page or site you arrived from, how long the page was visible and focused, how far down it was read, which buttons and outbound links were clicked, a two-letter country code from the edge, and one of three size buckets from your window width. It sets no cookie and neither reads nor writes anything on your device: no localStorage, no sessionStorage, no fingerprint, no visitor identifier.
No IP addresses and no user-agent strings are recorded, and nothing is joined across visits, across devices, or with your account; a page view cannot be tied to a customer. If your browser sends Global Privacy Control or Do Not Track, the script stops before sending anything. Rows are held in Cloudflare Analytics Engine for three months. Our platform also injects its own cookieless page-view script (static.cloudflareinsights.com); Cloudflare is already a processor here. Everything else, fonts included, is served from this origin.
Who processes what
Cloudflare provides Pages and Workers delivery, D1 databases, R2 archives, Analytics Engine and outbound email. GLM-5.3-Flash was served from Nebius UK (uk-south2) from 2026-09-13 to 2026-09-19; Nebius holds no customer content now; Verda Oy (Finland, FIN-01) is the only GPU-inference sub-processor (DeepSeek-V4.1-Flash). Paddle processes payments. Calendly processes details you submit when booking a call. For LinkedIn-attributed bookings, LinkedIn receives booking time, a hashed email address, a hashed booking identifier, the conversion rule identifier and, when supplied, first and last name. See the subprocessors list for scope and data handling.
- Cloudflare: site delivery, the console application, its database, and outbound email. Cloudflare operates global infrastructure; this policy does not promise EU-only storage.
- Paddle.com Market Ltd (Paddle): payments, tax, invoicing, and the saved payment method. They are the merchant of record.
- Compute providers: the infrastructure the models run on. Trial requests are processed in Europe (Finland).
Your requests (trial data)
Mail support@tiyuvta.ai to get a copy of your account data, correct it, or delete the account. Deletion removes the account, its keys and its email address; the content-free billing records stay for the retention period above because tax law requires a record of a sale. Credit is not refundable, so deleting the account gives up any unused balance. Spend it first if you intend to. Billing terms.
Children
The service is for people over 18 acting for themselves or for a business.
Changes to the trial policy
A change that widens what we do with your data is emailed to you before it takes effect. The date at the top moves with every change.
Part B. Lab website and contact forms
How the website, its forms and its measurement handle data.
Who operates this service
Operated under the Tiyuvta trading name. Contact: hello@tiyuvta.ai.
Request content
The prepaid deployment trial processes prompts and model responses to answer your requests. Purchased-credit requests with training off are not written to the durable capture corpus or used for training or evaluation. With capture enabled, accounts marked for promotional use or explicit training consent may have eligible prompts and completions stored on the serving host and archived, encrypted, in Cloudflare R2. Prompt prefixes may remain in engine memory after a response until evicted or the process restarts. The gateway namespaces prefix reuse by account and cache_salt, not by individual API key.
Billing ledger
Billing records contain request identifiers, account or tenant identifiers, API key prefixes where available (not full keys), model, route, timestamps, outcome, token counts and cost; they do not contain prompt or completion bodies.
Operational logs
Separate operational logs may contain request ids, account or tenant ids, model and lane information, and process, accelerator, network, or error diagnostics. They are used for security, abuse prevention, reliability, and debugging, are retained for no more than 30 days, and do not store prompt or completion bodies.
No sale. Training depends on which credit paid for the request.
tiyuvta does not sell API traffic or personal data, in any of the cases below.
Requests paid from purchased credit with training off are not used to train or evaluate models. Requests paid from promotional credit may be; that condition is stated when the credit was granted, and it ends with the account's first purchase. A paid account may also opt in in its settings, in which case 5% of metered spend is credited back; consent applies from the moment it is switched on, is withdrawable at any time, and cannot pull data out of a training run that has already finished.
The full version, including how a partially consented day is treated, is in the trial sections of this privacy and data-use policy.
Processors
The processors and their regions are listed under Part A (Who processes what) and on the sub-processors page.
The request form
If you send a request through the forms at /contact or /services/try, we store what you type: your name, email address, and a description of your workload, plus the optional company, role, current-spend and hardware/budget fields, and any selected service. We also store which page the form was sent from, the language you sent it in, and the country code supplied by our edge network, which is used only to answer you in the right language and time zone.
It is stored in Cloudflare D1 before an owner notification is sent through Cloudflare email. These processors handle the submitted contact details and message so we can reply and continue the conversation. It is not added to a mailing list, sold or used to train a model. The free-text field is yours: put in it only what you want us to have.
Request-form records are retained to handle your enquiry and follow-up; deletion is handled on request. To see what is held or to have it deleted sooner, email hello@tiyuvta.ai from the address you used, and it will be removed.
Capture is off unless the serving host is explicitly configured to store training data. The console sets a per-account trial or consent mark. Explicit consent takes precedence; without consent, promotional capture requires an eligible grant, the promotional training setting and no completed purchase. The gateway captures only successfully completed chat/completions requests on eligible customer accounts, rechecking the mark before writing. Captures can include reasoning, tool calls and the forwarded request body, not just visible answer text.
Captured files are available to the operator through serving-host permissions and archive decryption access, not through customer API keys. Cloudflare handles the encrypted archive. Email notifications also pass through the recipient’s mailbox provider.
Data retention
Billing-ledger records are retained for up to 12 months for billing, reconciliation, abuse and fraud investigation, disputes, and financial records. Operational logs are retained for no more than 30 days.
Captured training data is subject to a 24-month deletion policy; account closure starts a 30-day purge deadline, whichever comes first. Purging is performed by our deletion process, with overdue closure alerts and a validated deletion receipt; turning consent off stops new capture, not the retention clock for existing data.
Request-form submissions follow the enquiry and deletion process described above.
Measurement, and why there is no cookie banner
This site counts its own pages, with a script served from this origin. A page view records the path, the page or site you arrived from, how long the page was visible and focused, how far down it was read, which buttons and outbound links were clicked, a two-letter country code from the edge, and one of three size buckets derived from your window width.
It sets no cookie and neither reads nor writes anything on your device: no localStorage, no sessionStorage, no fingerprint, no visitor identifier of any kind. The consent rule that produces cookie banners is about storing or reading information on your device, and this does neither, which is why you are not being asked to dismiss one. Nothing is joined across visits, across devices, or with the trial console. We cannot tell that two page views were the same person, and that limitation is the deliberate price of not asking.
No IP addresses and no user-agent strings are recorded. If your browser sends Global Privacy Control or Do Not Track, the script stops before sending anything at all. The rows are held in Cloudflare Analytics Engine, which stores them for three months. There are no third-party trackers, advertising pixels, or cross-site cookies on this site's pages; the one server-side exception is described next.
One thing does leave, and only when you have done something first: if you arrive from a LinkedIn ad and then book a call with us, we tell LinkedIn that a booking happened so the ad can be credited. What LinkedIn receives is the time of the booking, a one-way hash of the email address you gave the scheduling page, a hashed booking identifier, the conversion rule identifier and, when supplied, your first and last name, sent from our server. It receives nothing about your visit to this site, and nothing at all for bookings that did not come from a LinkedIn link.
Your requests (website data)
To ask what is held about your account, or to request deletion, email hello@tiyuvta.ai. Include the email address used for access and any request ids that help locate the records. Eligible account and billing-ledger records will be deleted; records needed for billing, security, dispute, or legal purposes may remain within the retention periods above.
Changes to the website policy
Material changes are posted on this page with a new effective date before they apply to new API use.