SingularityAPI

Privacy Policy

We do not store your prompts or the responses returned to you. This policy sets out what we do collect, why, how long we keep it, and the choices you have. Written plainly, because an inference platform that asks for your trust should be legible.

Last updated August 2, 2026

1. Who we are

Singularity (“SingularityAPI”, “we”, “us”) provides an API that routes inference requests to large language models. This policy explains how we handle information when you create an account, use the dashboard, or call the API.

For any privacy question or request, email support@singularityapi.dev. A real person answers.

2. The short version

We do not store the prompts you send or the responses models return. Request content passes through our systems only for as long as it takes to route your request and return the response, and is then discarded. We keep the metadata needed to bill and support you — model served, token counts, cost, latency, timestamps. If you want request history and replay, you can turn on logging for your workspace; it is off unless you enable it. We do not sell your data, and we do not use your prompts or outputs to train models.

3. Information we collect

Account information. Your email address and an authentication credential, handled by our managed authentication provider. We receive a verified email address and an internal user identifier; we never see or store your password in readable form.

API credentials. When you create an API key we store a cryptographic hash of it together with a short prefix and its last four characters, so you can recognise the key in your dashboard. The full key is displayed once at creation and is not recoverable from our systems afterwards.

Request content (prompts and responses). By default we do not store the content of your requests. Message content, system instructions, parameters, and the response returned are held only for as long as it takes to route the request to a model and deliver the response back to you, and are then discarded. Request content is excluded from our application logs, error tracking, and analytics.

Logged content. If you enable request logging for your workspace, we store the content of requests made after you turn it on, so you can review history and replay requests from your dashboard. Logging is off unless you enable it, applies only from the moment you enable it, and can be turned off at any time. Logged content is held in restricted internal storage, separate from the searchable metadata described below.

Request metadata. For each request we record identifiers, the model requested and served, the stable endpoint used where applicable, token counts, computed cost, latency, completion state, and timestamps. This is what powers your request history, receipts, and usage reporting.

Credit and transaction records. Credit grants, reservations, settlements, and adjustments are recorded as an append-only ledger so balances can be reconstructed and audited.

Technical and operational data. Our servers and infrastructure providers generate operational records that may include IP address, user agent, timestamps, and error diagnostics. We also keep short-lived counters used to enforce rate limits; these hold no request content and are routinely discarded.

Payment information. When you purchase credit, our payment processor collects and processes your payment details directly. We receive a record of the transaction — amount, currency, time, and a payment reference — and never receive or store full card numbers.

4. How we use information

  • Operating the service — authenticating you, routing your requests to a model, returning responses, and enforcing rate limits.
  • Metering and billing — reserving and settling credit, producing receipts, and preventing double-charging.
  • Support and debugging — investigating failures you report or that our monitoring detects, using request metadata and, only where you have enabled logging, the stored content of the affected requests.
  • Security and abuse prevention — detecting misuse, credential compromise, and activity that violates our Terms.
  • Service improvement — understanding aggregate reliability, latency, and error patterns to improve routing and infrastructure.
  • Legal compliance — meeting obligations that apply to us and responding to lawful requests.

We do not use your prompts or model outputs to train or fine-tune models, and we do not sell, rent, or trade your personal information.

5. Who processes your information

We rely on a small number of third parties to run the service. They act as our processors, receive only what their function requires, and are bound by contractual confidentiality and security obligations. By category:

  • AI model hosting providers, which receive the request content necessary to generate a response.
  • Cloud infrastructure and hosting providers, which run our compute and networking.
  • Managed database and authentication providers, which store account records, credentials, request metadata, and any content you have chosen to log.
  • Payment processing providers, which handle purchases of credit and receive the payment details you enter with them.
  • Operational tooling for error monitoring and uptime, which receives technical diagnostics but not request content.

Model providers handle content under their own policies. When you call the API, we transmit your prompts to the model provider that serves the request. Model providers process those prompts to generate a response and may, depending on their own terms and data practices, retain and use prompts and responses for their own purposes, including model training and improvement. Those practices differ from provider to provider and are not something we control.

Before you rely on a model, review the data practices of the provider behind it. If you do not want your prompts used for model training, choose a model or provider that commits to not using your data that way. Contact us if you need the retention or training posture of a specific provider and we will tell you what its terms say.

A current list of our named subprocessors is available to customers on request at support@singularityapi.dev.

We may also disclose information where required by law, to enforce our Terms, to protect the rights and safety of users or the public, or in connection with a merger, acquisition, or sale of assets — in which case we will give notice before your information becomes subject to a different policy.

6. International processing

We are a global service. We and our service providers may process and store information in the United States and in other countries where we or they operate. Where information is transferred across borders, we rely on appropriate safeguards, such as standard contractual clauses, to protect it. If you require details of the safeguards applicable to your account, contact us and we will provide them.

7. How long we keep information

Request content. We do not retain it. Prompts and responses are discarded once your response has been delivered, and are never written to durable storage unless you have enabled logging.

Logged content. Where you have enabled request logging, stored content is retained for 30 days from the date of the request and is then permanently deleted. You can turn logging off, or delete logged content ahead of that deadline, at any time from your dashboard.

Account and billing records. Account records, credit ledger entries, and request metadata are retained for as long as your account is active, and afterwards where we need them for legal, accounting, or dispute-resolution purposes.

Operational data. Rate-limit counters expire automatically within minutes. Operational logs are kept for a limited period appropriate to troubleshooting and security, and contain no request content.

Model providers. Content transmitted to a model provider in order to serve your request is subject to that provider’s own retention period, which we do not control and cannot shorten on your behalf.

8. Security

  • All API and dashboard traffic is encrypted in transit with TLS.
  • Data at rest is encrypted by our managed database provider.
  • API keys are stored only as keyed cryptographic hashes; the plaintext key exists only in your possession.
  • Internal services connect to the database as distinct least-privilege roles, so no single component can read everything.
  • Request content is not written to durable storage at all unless you have enabled logging.
  • Access to logged request content requires a separate administrative permission and generates an immutable audit record.
  • Request content is excluded from application logs, traces, analytics, error tracking, and customer-facing APIs.

No system is perfectly secure. If you believe your credentials or data have been compromised, revoke the affected API key from your dashboard and contact us immediately.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing. You can exercise these rights by emailing support@singularityapi.dev; we will verify your request and respond within the period required by applicable law.

You control whether request logging is on. It is off by default, and turning it off stops new content being stored immediately; you can also delete already-logged content from your dashboard.

You can revoke any API key at any time from your dashboard, which immediately stops requests made with it. Deleting your account removes your ability to use the service; we will delete or de-identify associated data except where we are required to retain it.

10. Your responsibilities as an API customer

If you send us personal information belonging to your own users, you are responsible for having a lawful basis to do so and for telling those users how their information is handled.

Two things to weigh before sending regulated information — for example health or financial records. First, although we do not retain request content, serving your request requires transmitting it to a model provider that may retain it under its own terms. Second, enabling request logging is a decision to have that content stored in our systems for the period described above. If you need contractual arrangements covering either, contact us before you send it.

11. Children

The service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

12. Cookies

The dashboard uses strictly necessary cookies to keep you signed in and to protect access to the application. This marketing site does not use advertising cookies or cross-site tracking.

13. Changes to this policy

We will update this policy as the service evolves. When changes are material — particularly changes to what we collect, how long we keep it, or who processes it — we will update the date at the top of this page and notify account holders by email before the change takes effect.