M Mlandi AI
Acceptable Use Terms of Service Privacy Policy Home
Legal

Privacy Policy

Last updated: September 14, 2026

Data controller: Mlandi AI, operator of www.mlandi.com

This Privacy Policy explains what personal data Mlandi AI collects when you use our API gateway services, why we collect it, how long we keep it, and the rights you have over it. We collect the minimum data necessary to operate and bill the service.
Contents
  1. Data We Collect
  2. How We Use Data
  3. Legal Bases (GDPR)
  4. Sharing With Third Parties
  5. Cookies and Local Storage
  6. Data Retention
  7. Data Security
  8. Your Rights
  9. Children
  10. International Transfers
  11. Changes to This Policy

1. Data We Collect

CategoryExamplesPurpose
Account dataEmail address, username, hashed password, registration date, language preferenceAccount creation and authentication
API usage dataAPI key identifiers, request timestamps, model invoked, token counts, prompt/output lengths, error codesMetering, billing, abuse prevention, service monitoring
Request contentPrompts you submit and outputs returned, relayed to the upstream model provider you selectedDelivering the API service (routed to the provider; retained transiently in logs, see Section 6)
Payment dataOrder ID, amount, payment status, billing emailProcessing purchases and accounting (card details are handled solely by our payment processors)
Technical dataIP address, user agent, access times for console sessionsSecurity, fraud prevention, rate limiting

We do not collect sensitive personal data, and you must not submit such data through prompts beyond what the service inherently requires.

2. How We Use Data

  • Provide, route, and meter the API service;
  • Bill prepaid credits and detect billing abuse;
  • Prevent fraud, enforce the Acceptable Use Policy, and secure the platform;
  • Communicate service notices, security alerts, and account-related emails;
  • Meet legal, accounting, and regulatory record-keeping obligations.

We do not sell personal data. We do not use your request content to train our own models.

3. Legal Bases (GDPR)

Where the EU/UK GDPR applies, we rely on: performance of a contract (delivering the service and billing), legitimate interests (security, fraud and abuse prevention, service improvement), consent where specifically obtained (optional communications), and legal obligation (tax and accounting records).

4. Sharing With Third Parties

  • Upstream AI model providers — your prompts and generation parameters are sent to the provider of the model you call, and are subject to that provider's privacy policy (e.g., OpenAI, Anthropic, Google, Alibaba).
  • Payment processors — checkout is handled by third-party payment processors, which process your payment details under their own privacy policies. We receive only order status and amount.
  • Infrastructure providers — cloud hosting and content delivery vendors used to run the service.
  • Legal requirements — disclosure where required by law, regulation, or valid legal process, or to protect rights and safety.

5. Cookies and Local Storage

We use only strictly necessary cookies/local storage: a session token to keep you logged in, and a language preference key for site display. We do not use advertising or cross-site tracking cookies, so no consent banner is required under the ePrivacy framework.

6. Data Retention

  • Account data — retained while your account is active; deleted or anonymized within 30 days of account deletion, except data we must retain for legal reasons.
  • Usage and billing records — retained for a minimum of 5 years to satisfy accounting and tax obligations (aggregated; prompt content is not retained in these records).
  • Request logs with prompt content — kept for a short operational window for debugging, then deleted or reduced to metadata. Logs may be retained longer where flagged for abuse investigation.
  • Payment records — retained per the payment processor's statutory requirements.

7. Data Security

All traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes. API keys are shown once at creation and stored in encrypted form. Access to production systems is restricted and logged. No system is perfectly secure; if a breach affecting your data occurs, we will notify affected users and regulators as required by law.

8. Your Rights

Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, etc.), you may have rights to: access your personal data, correct it, delete it, export it in a portable format, restrict or object to certain processing, and withdraw consent for optional processing. California residents may also opt out of any "sale" or "sharing" of personal data — we do not sell personal data, so no opt-out applies.

To exercise any right, email privacy@mlandi.com from your account's registered email address. We verify your identity and respond within 30 days.

9. Children

The Services are not directed to children under 18 (or under 13 in jurisdictions where COPPA applies, in which case not under 13). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.

10. International Transfers

We operate globally: your data may be processed in Singapore, mainland China, the United States, and other countries where our infrastructure and upstream model providers operate. Where required, transfers are safeguarded by appropriate mechanisms such as the EU Standard Contractual Clauses.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be published here with an updated "Last updated" date. We encourage you to review this page periodically.

Mlandi AI · www.mlandi.com
Acceptable Use Policy · Terms of Service · Privacy Policy · Privacy: privacy@mlandi.com · Support: support@mlandi.com