Who this policy covers
This policy applies to personal data processed by Emynor when you use our website, apps, developer API, support, or payment flows. It does not cover third-party websites or services that have their own privacy policies.
Information we collect
We collect account and contact details; authentication and security records; top-up, balance, invoice, and transaction information; prompts, messages, uploaded files, images, and generated outputs; request metadata such as model, time, token count, cost, and API-key identifier; device, browser, IP address, cookies, and diagnostic logs; and support communications. Payment providers process payment credentials directly, and Emynor receives transaction references and status rather than full card or payment-account credentials.
How and why we use information
We use information to create and secure accounts, route requests and return outputs, calculate charges, process top-ups, provide history and support, detect fraud and abuse, troubleshoot and improve reliability, communicate service updates, and meet legal, tax, accounting, and regulatory duties. We process data as needed to provide the service, comply with law, protect legitimate interests, and, where required, with your consent. We do not sell personal data or use your private content for advertising.
Where information comes from
Most information comes directly from you or your use of Emynor. We also receive limited information from payment providers, identity and security services, AI providers, your organisation's account administrator, and public sources when needed to prevent fraud or comply with law.
Data locations and transfers
AI and infrastructure providers may process data in different countries. Where required, we use contractual, technical, and organisational safeguards intended to protect personal data during these transfers. Processing locations can vary by the model or feature you choose.
How long we keep information
We keep conversation content and files until you delete them or your account, subject to backup cycles. Operational request metadata is generally kept for 90 days. Transaction, invoice, tax, security, and fraud-prevention records may be kept longer where law or a legitimate business need requires it. Account-deletion requests are normally completed within 30 days, although limited records may remain in backups or where retention is legally required.
Your rights and choices
Depending on applicable law, you may request access to, correction of, a copy of, restriction of, objection to, or deletion of your personal data, and may withdraw consent where processing relies on it. You can manage or delete conversations and request an export or account deletion from Settings → Privacy. We may need to verify your identity before completing a request. Contact privacy@emynor.com to exercise a right or raise a complaint.
Security
We use administrative, technical, and physical safeguards designed to protect data, including encryption in transit and at rest, access controls, logging, and monitoring. No online service is completely secure, so protect your credentials and notify us promptly if you suspect unauthorised access.
Children
Emynor is not directed to children under 13 and we do not knowingly collect their personal data. Users under 18 must have permission and supervision from a parent or legal guardian. Contact us if you believe a child provided data without appropriate consent.
Changes to this policy
We may update this policy when our practices, providers, or legal duties change. We will update the effective date and provide reasonable notice of material changes when practical.
Contact
Emynor is responsible for the processing described here. For privacy requests or questions, contact privacy@emynor.com. For general support, contact support@emynor.com.