Legal

Privacy Policy.

We treat your data the way we'd want ours treated — collect the minimum, store it only when needed, and let you take it back at any time.

Introduction

Zyloo, LLC (“Zyloo”, “we”, “us”), a Delaware limited liability company with its registered office at 131 Continental Dr, Suite 305, Newark, DE 19713, USA, operates a unified API gateway for third-party AI models. This policy explains what personal data we handle when you sign up, browse our site, or send requests through the API.

If anything below is unclear, write to us at privacy@zyloo.io and we will respond within seven days.

What we collect

We only collect what we need to run the service:

  • Account information — name and email from your Google or GitHub sign-in.
  • Usage metadata — request timestamps, model id, token counts, latency and HTTP status. We do not log prompt or completion content by default.
  • Technical data — IP address, user agent and referrer, used for fraud prevention and rate limiting. The IP address you signed up from is also used to derive an approximate country for regional statistics and regional email targeting, and is retained for fraud prevention for the life of the account.

How we use it

  • Operate, secure and improve the API gateway.
  • Bill you for the tokens you consume and prevent abuse.
  • Notify you about service-critical events such as outages or pricing changes.
  • Send you product updates and new-model announcements by email — only with your consent; every email includes one-click unsubscribe.
  • Comply with legal obligations and respond to lawful requests.

We do not sell, rent or share your personal data with advertisers. We do not use your prompts or completions to train models — ours or anyone else's.

Where the GDPR or a similar law applies, we rely on the following legal bases for processing your personal data:

  • Contract — operating the service you signed up for and billing you for usage.
  • Legitimate interests — fraud prevention, security, and service analytics.
  • Consent — marketing emails such as product updates and new-model announcements.
  • Legal obligation — tax and accounting records we are required to keep.

Data retention

  • Request payloads (prompt + completion) — not stored. Discarded as soon as the response is sent.
  • Request metadata — kept for 30 days for analytics, then aggregated and the raw rows deleted.
  • Account and billing records — kept for the lifetime of the account, plus the period required by tax law.

Enterprise customers can opt into custom data residency and shorter retention windows from the dashboard.

Third-party providers

When you call a model, we forward the request to the upstream provider you selected (OpenAI, Anthropic, Google, xAI, DeepSeek, Moonshot or Zhipu). Each provider has its own privacy policy that governs the request once it leaves our infrastructure. We negotiate zero-retention enterprise terms with every provider where they offer them.

International transfers

Our sub-processors and the model providers you call may be located outside your country, including in the United States (e.g. Stripe, Vercel, and the upstream model providers listed above). Where required, transfers of personal data rely on safeguards such as Standard Contractual Clauses or an applicable adequacy framework.

Sharing

We share personal data only with:

  • Sub-processors that operate the service (cloud hosting, email, error tracking).
  • Legal or regulatory bodies when compelled by a valid legal process.
  • An acquirer in the unlikely event of a merger or acquisition, under equivalent privacy commitments.

Security

Data in transit is protected by TLS 1.3. Data at rest is encrypted with AES-256. Access to production systems is restricted and protected by multi-factor authentication, and we monitor for vulnerabilities. Despite our efforts, no system is invulnerable — if we discover a breach affecting you we will notify you without undue delay.

Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete the personal data we hold about you. You can delete your account directly from the Profile page in your dashboard; for access or export requests, email privacy@zyloo.io.

Cookies

We use a small number of strictly necessary cookies for authentication and load balancing. We do not use third-party advertising cookies. You can disable cookies in your browser, but core features such as signing in will stop working.

Children

Zyloo is not directed to children under 13 (or under 16 in the EU). We do not knowingly collect data from children. If you believe a child has provided personal information, contact us and we will delete it.

Saved payment methods

When you pay by card, your payment method is saved for faster future top-ups. Saved card details are stored and secured entirely by our payment provider, Stripe — they never reach Zyloo's servers; we only keep a display reference (card brand and last four digits). You can remove a saved card yourself at any time from your billing dashboard — no need to contact us. WeChat Pay, UPI and crypto payments are single-use and are never saved.

Refund policy

  • Fully unused credit can be refunded within 14 days of purchase by emailing support@zyloo.io.
  • Partially or fully spent credit is non-refundable.
  • Approved refunds are returned to the original payment method within 5–10 business days.

Changes to this policy

When we make material changes we will post the new policy here and notify active users by email. Your continued use of the service after a change means you accept the updated policy.

Contact

Questions, complaints or data requests? Email privacy@zyloo.io. The data controller is Zyloo, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, USA. You may also escalate to your local data protection authority.

Have a question?

We answer privacy emails within seven days.

privacy@zyloo.io