This Privacy Policy explains how Stellar Apex Tech Limited (“we”, “us”, “our” or the “Company”) collects, uses, shares, retains, and protects personal data when you visit our website, use the MAX developer dashboard, or make calls to our application programming interface (the “Service”), and the rights and choices available to you. It is designed to meet our obligations under the EU and UK General Data Protection Regulations, the California Consumer Privacy Act (as amended by the CPRA), and other applicable privacy laws. Please read it together with our Terms of Service.
1.Introduction and Scope
1.1 What This Policy Covers. It applies to personal data processed through our public website, developer dashboard, online documentation, and the API gateway we operate.
1.2 What It Does Not Cover. It does not cover (a) the applications you build or the data you collect from your own end users, for which you are the controller; or (b) data that a Model Provider collects independently under its own privacy policy when a request reaches its systems. We encourage you to review the Model Providers’ policies.
1.3 Our Two Roles. We act as a data controller for information relating to your account, billing, and use of our website and dashboard. We act as a data processor for the content you send through the API (your prompts, files, and the returned outputs), which we process only on your documented instructions.
2.Data Controller and Contact
2.1 Controller. The data controller is Stellar Apex Tech Limited, registered at UNIT 11, 9/F THE CLOUD NO.111 TUNG CHAU ST TAI KOK TSUI HONG KONG, with company/registration number 81332298.
2.2 Data Protection Officer. Our data protection contact can be reached at privacy@link-io.cloud (or dpo@link-io.cloud). We welcome questions and requests at any time.
3.Personal Data We Collect
3.1 Categories. The table below summarises the categories and examples of personal data we may collect.
| Category | Examples |
|---|---|
| Identity and contact | Name, work email, organisation, job title, country. |
| Account and credentials | Username, hashed password, security settings, account preferences. |
| Verification (KYC/KYB) | Business registration, tax identifiers, and, only where required, identity documents (encrypted and access-restricted). |
| API and technical data | API-key identifiers (prefixes only; secrets are hashed), request timestamps, model called, token counts, status codes, latency, rate-limit data, IP address. |
| API content (Customer Data) | Prompts, inputs, uploaded files and context, and the generated outputs, processed on your behalf as processor. |
| Billing and payment | Billing address, tax information, and payment records; full card details are handled by our payment processor and are not stored by us. |
| Device and online data | IP address, browser and device type, operating system, referring URLs, pages viewed, and website/dashboard analytics. |
| Communications | Support tickets, emails, chat messages, survey responses, and feedback. |
- Category
- Identity and contact
- Examples
- Name, work email, organisation, job title, country.
- Category
- Account and credentials
- Examples
- Username, hashed password, security settings, account preferences.
- Category
- Verification (KYC/KYB)
- Examples
- Business registration, tax identifiers, and, only where required, identity documents (encrypted and access-restricted).
- Category
- API and technical data
- Examples
- API-key identifiers (prefixes only; secrets are hashed), request timestamps, model called, token counts, status codes, latency, rate-limit data, IP address.
- Category
- API content (Customer Data)
- Examples
- Prompts, inputs, uploaded files and context, and the generated outputs, processed on your behalf as processor.
- Category
- Billing and payment
- Examples
- Billing address, tax information, and payment records; full card details are handled by our payment processor and are not stored by us.
- Category
- Device and online data
- Examples
- IP address, browser and device type, operating system, referring URLs, pages viewed, and website/dashboard analytics.
- Category
- Communications
- Examples
- Support tickets, emails, chat messages, survey responses, and feedback.
3.2 Sensitive Data. We do not ask you to provide special categories of personal data (such as health, biometrics, racial or ethnic origin, political opinions, or precise location) or other regulated data. If you choose to submit such data through the API, you do so under Section 10.6 of the Terms and remain responsible for having a lawful basis.
4.How We Collect Personal Data
4.1 Directly From You. When you register, verify your account, add credits, configure routing, contact support, or communicate with us.
4.2 Automatically. When you use our website or dashboard, through server logs and cookies and similar technologies.
4.3 From Third Parties. From payment processors, verification providers, referral partners, and limited metadata returned by Model Providers.
4.4 Generated by Us. Usage metering, aggregated statistics, and security and reliability telemetry we derive.
5.How We Use Personal Data and Legal Bases
5.1 Purposes and Bases. Where the GDPR or UK GDPR applies, we rely on the following legal bases.
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and manage accounts; authenticate users. | Performance of a contract – Art. 6(1)(b). |
| Operate the API; route requests; return outputs. | Performance of a contract – Art. 6(1)(b). |
| Meter usage; calculate and collect Fees; prevent payment fraud. | Contract and legitimate interests – Art. 6(1)(b), (f). |
| Secure the Service; detect abuse, attacks, and policy violations. | Legitimate interests – Art. 6(1)(f). |
| Provide customer and technical support. | Contract and legitimate interests – Art. 6(1)(b), (f). |
| Comply with KYC/KYB, sanctions, export-control, tax, and other legal obligations; respond to authorities. | Legal obligation and legitimate interests – Art. 6(1)(c), (f). |
| Maintain reliability and capacity using aggregate/metadata (not API content). | Legitimate interests – Art. 6(1)(f). |
| Send marketing or newsletters; set non-essential analytics cookies. | Consent – Art. 6(1)(a); withdrawable at any time. |
| Process API content on your behalf. | As processor under the contract and your documented instructions (DPA). |
- Purpose
- Create and manage accounts; authenticate users.
- Legal basis (GDPR)
- Performance of a contract – Art. 6(1)(b).
- Purpose
- Operate the API; route requests; return outputs.
- Legal basis (GDPR)
- Performance of a contract – Art. 6(1)(b).
- Purpose
- Meter usage; calculate and collect Fees; prevent payment fraud.
- Legal basis (GDPR)
- Contract and legitimate interests – Art. 6(1)(b), (f).
- Purpose
- Secure the Service; detect abuse, attacks, and policy violations.
- Legal basis (GDPR)
- Legitimate interests – Art. 6(1)(f).
- Purpose
- Provide customer and technical support.
- Legal basis (GDPR)
- Contract and legitimate interests – Art. 6(1)(b), (f).
- Purpose
- Comply with KYC/KYB, sanctions, export-control, tax, and other legal obligations; respond to authorities.
- Legal basis (GDPR)
- Legal obligation and legitimate interests – Art. 6(1)(c), (f).
- Purpose
- Maintain reliability and capacity using aggregate/metadata (not API content).
- Legal basis (GDPR)
- Legitimate interests – Art. 6(1)(f).
- Purpose
- Send marketing or newsletters; set non-essential analytics cookies.
- Legal basis (GDPR)
- Consent – Art. 6(1)(a); withdrawable at any time.
- Purpose
- Process API content on your behalf.
- Legal basis (GDPR)
- As processor under the contract and your documented instructions (DPA).
5.2 Special Categories. We do not intentionally process special categories of personal data as a controller. If such data is contained in API content, we process it only on your instructions, and you must ensure a condition under Article 9(2) applies (for example, explicit consent).
6.API and AI Request Data
6.1 How Requests Flow. When you call the API, your request passes through our gateway and is forwarded to the selected Model Provider’s official endpoint; the generated output is returned to you. The Model Provider performs the inference.
6.2 No Training by Default. We do not use API content (prompts, files, or outputs) to train our own models or any third-party model. By default we process content only to route and fulfil the request.
6.3 Temporary Processing and Logging. Content is processed transiently for transmission and reliability. We do not persistently store API content by default. Security and debugging logs generally contain metadata (not full content) and are retained for a short period, typically 30 days or less. Content logging occurs only if you enable it through your settings.
6.4 Model Provider Data Policies. After a request reaches a Model Provider, its handling is governed by that provider’s policy, which may permit retention or, in some cases, training. We use reasonable efforts to display each model’s data policy, including zero-data-retention (“ZDR”) status, on the relevant model page. These indicators are indicative and not a substitute for the provider’s policy.
6.5 Your Controls. Where supported, you can (a) restrict routing to providers that do not retain or train on data (for example, a ZDR or “data_collection: deny” setting), enforced account-wide, per model, or per request; (b) choose specific providers and regions; and (c) disable content logging. We will not route a request to an endpoint that conflicts with an active restriction.
6.6 Processor Terms. For API content we are the processor and you are the controller. We handle, return, and delete that content according to your instructions, the DPA, and applicable law, and we assist with data-subject requests and security incidents.
6.7 Aggregated Telemetry. We may produce aggregated, de-identified statistics (such as total token volume, error rates, or latency distributions) that do not contain API content and cannot identify you, for operations, capacity planning, and reliability.
7.Cookies and Similar Technologies
7.1 Use. Our website and dashboard use cookies and similar technologies to operate, secure, and improve the experience. Core API calls do not rely on advertising cookies.
7.2 Categories. The categories are summarised below.
| Category | Purpose and examples |
|---|---|
| Strictly necessary | Authentication, session and CSRF tokens, and security; required to log in. |
| Functional | Remembering preferences such as language or dashboard settings. |
| Analytics (consent) | Privacy-friendly statistics on how the site is used, set only with consent. |
- Category
- Strictly necessary
- Purpose and examples
- Authentication, session and CSRF tokens, and security; required to log in.
- Category
- Functional
- Purpose and examples
- Remembering preferences such as language or dashboard settings.
- Category
- Analytics (consent)
- Purpose and examples
- Privacy-friendly statistics on how the site is used, set only with consent.
7.3 Your Choices. You can manage non-essential cookies through our consent banner and control or delete cookies via your browser settings. Disabling strictly necessary cookies may prevent login or dashboard use.
8.How We Share Personal Data
8.1 Recipients. We share personal data only as necessary to operate the Service, under appropriate contracts, and with the categories of recipients below. We do not sell personal data.
| Recipient category | Purpose | Typical location |
|---|---|---|
| Model Providers (official endpoints) | Perform inference and return outputs. | Per model (often US; some EU/global). |
| Cloud and hosting providers | Host, compute, and operate the gateway and dashboard. | APAC / US / EU. |
| Payment processors | Process top-ups and recurring payments. | Global. |
| Identity/verification providers | KYC/KYB and fraud checks, where applicable. | Global. |
| Email, support, and CRM providers | Deliver notices and manage support. | Global. |
| Analytics and error-monitoring providers | Reliability, debugging, and site analytics. | Global. |
| Professional advisers | Legal, accounting, audit, and insurance. | Global. |
| Authorities and regulators | Where required by law or legal process. | As required. |
| Transaction counterparties | In a merger, acquisition, financing, or asset sale. | Global. |
- Recipient category
- Model Providers (official endpoints)
- Purpose
- Perform inference and return outputs.
- Typical location
- Per model (often US; some EU/global).
- Recipient category
- Cloud and hosting providers
- Purpose
- Host, compute, and operate the gateway and dashboard.
- Typical location
- APAC / US / EU.
- Recipient category
- Payment processors
- Purpose
- Process top-ups and recurring payments.
- Typical location
- Global.
- Recipient category
- Identity/verification providers
- Purpose
- KYC/KYB and fraud checks, where applicable.
- Typical location
- Global.
- Recipient category
- Email, support, and CRM providers
- Purpose
- Deliver notices and manage support.
- Typical location
- Global.
- Recipient category
- Analytics and error-monitoring providers
- Purpose
- Reliability, debugging, and site analytics.
- Typical location
- Global.
- Recipient category
- Professional advisers
- Purpose
- Legal, accounting, audit, and insurance.
- Typical location
- Global.
- Recipient category
- Authorities and regulators
- Purpose
- Where required by law or legal process.
- Typical location
- As required.
- Recipient category
- Transaction counterparties
- Purpose
- In a merger, acquisition, financing, or asset sale.
- Typical location
- Global.
8.2 Providers’ Roles. For content sent to a Model Provider, that provider’s own terms and privacy policy apply; some act as independent controllers. Our sub-processors are bound by data-processing terms and confidentiality obligations.
8.3 Current List and Notice. We provide notice of material changes and an opportunity to object where the DPA requires.
9.International Data Transfers
9.1 Global Operations. Because the Service is global, personal data may be processed in countries other than your own, including where Model Providers or our infrastructure are located (often the United States).
9.2 Transfer Mechanisms. For transfers out of the EEA or the UK we rely, as appropriate, on: (a) European Commission adequacy decisions (including for recipients certified under the EU–US Data Privacy Framework); (b) the EU Standard Contractual Clauses under Implementing Decision (EU) 2021/914 (with the UK International Data Transfer Addendum where relevant); and (c) other legally permitted safeguards.
9.3 Processor Transfers. Our DPA incorporates the relevant standard-contract-clause modules for processor and sub-processor transfers and requires onward recipients to protect the data.
9.4 Copies. You may request a copy of the applicable transfer safeguards by contacting privacy@link-io.cloud, subject to redaction of commercial terms.
10.Data Retention
10.1 Retention Periods. We keep personal data only as long as necessary for the purposes described or as required by law, generally as follows.
| Data | Retention |
|---|---|
| Account and profile data | While the account is active and for approximately 30 days after closure, subject to legal holds. |
| Billing and tax records | For the period required by tax and accounting law (commonly 7 years). |
| API content | Not persistently stored by us by default; where you enable logging, per that setting; transient caches are cleared within a short period. |
| Security and debug logs | Typically 30–90 days; longer if needed for an incident or legal matter. |
| Marketing and consent records | Until consent is withdrawn, plus records of consent as required. |
| Customer Data (processor) | Per your instructions and the DPA; deletion or return within 30 days, with backup cycles of approximately 90 days. |
- Data
- Account and profile data
- Retention
- While the account is active and for approximately 30 days after closure, subject to legal holds.
- Data
- Billing and tax records
- Retention
- For the period required by tax and accounting law (commonly 7 years).
- Data
- API content
- Retention
- Not persistently stored by us by default; where you enable logging, per that setting; transient caches are cleared within a short period.
- Data
- Security and debug logs
- Retention
- Typically 30–90 days; longer if needed for an incident or legal matter.
- Data
- Marketing and consent records
- Retention
- Until consent is withdrawn, plus records of consent as required.
- Data
- Customer Data (processor)
- Retention
- Per your instructions and the DPA; deletion or return within 30 days, with backup cycles of approximately 90 days.
10.2 Legal Obligations. We may retain data for longer where needed to comply with law, legal process, or regulatory requests, or to establish, exercise, or defend legal claims, in which case we limit use to those purposes.
11.Data Security
11.1 Technical and Organisational Measures. We protect the Service using measures that may include encryption of data in transit (TLS) and at rest, secure key management, role-based least-privilege access, network isolation and segmentation, multi-region deployment, logging and monitoring, vulnerability scanning and penetration testing, personnel training, and a documented incident-response process.
11.2 API Keys. Secrets are stored using cryptographic protection; only key prefixes are displayed in the dashboard, and full keys are shown once at creation.
11.3 Breach Response. We investigate suspected incidents promptly. Where a breach is likely to result in a risk to rights and freedoms, we notify the competent supervisory authority within the time required by law (under the GDPR, generally within 72 hours) and, when required, notify affected persons. When processing for you, we notify you without undue delay after becoming aware of a breach affecting your data.
11.4 No Absolute Guarantee. No method of transmission or storage is completely secure; while we work to protect personal data, we cannot guarantee absolute security.
12.Your Privacy Rights
12.1 EU and UK Rights. Where the GDPR or UK GDPR applies, you may: access your personal data; obtain rectification of inaccurate data; request erasure (“right to be forgotten”); restrict or object to processing; request data portability; withdraw consent at any time; and not be evaluated solely on automated processing producing legal or similarly significant effects, except as permitted.
12.2 How to Exercise Them. Email privacy@link-io.cloud with sufficient information to verify your identity. We generally respond within one month and do not charge a fee for manifestly unfounded or excessive requests except as allowed by law.
12.3 California (CCPA/CPRA). California residents have the right to know the categories and specific pieces of personal data collected, to delete, to correct inaccurate data, to opt out of any sale or sharing for cross-context behavioural advertising, to limit the use of sensitive personal information, and not to receive discriminatory treatment for exercising these rights. We do not sell or share personal data for cross-context behavioural advertising. Requests may be made through an authorised agent who is properly authorised.
12.4 Other Regions. Users in other jurisdictions (for example under Singapore’s PDPA, Australia’s Privacy Act, or Canada’s PIPEDA) may have equivalent rights to access, correct, or withdraw consent; we provide the same level of protection and will honour rights to the extent required.
12.5 Requests About API Content. Because we process API content as a processor on your behalf, requests from your end users should generally be directed to you; we will promptly assist you in responding as described in the DPA.
12.6 Supervisory Authorities. You have the right to lodge a complaint with a data-protection authority, for example in your EEA member state of residence or, in the UK, the Information Commissioner’s Office.
13.Children’s Privacy
13.1 No Directed Use. The Service is a business-to-business developer platform and is not directed to children. We do not knowingly collect personal data from persons under the applicable age (generally 16 for account-related data, or as local law requires).
13.2 If You Become Aware. If a child’s data has been submitted without a lawful basis, contact privacy@link-io.cloud and we will delete it. You must not process children’s data through the API except in compliance with applicable law.
14.Sensitive Data and Do-Not-Track
14.1 Sensitive Personal Information. We limit our use and processing of sensitive personal information to what is necessary to provide the Service and do not use it to infer characteristics about you. See Sections 3.2 and 10.6 of the Terms.
14.2 Do-Not-Track Signals. Some browsers transmit Do-Not-Track signals. We do not engage in cross-site tracking or cross-context behavioural advertising of our own, and we do not change our core data practices in response to such signals.
15.Changes to This Policy
15.1 Updates. We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. We will post the updated version on this page, revise the “Last Updated” date, and, for material changes, provide notice through the Service or by email. Continued use after the effective date constitutes acceptance where permitted.
16.Contact and Complaints
16.1 Contact. For privacy questions or to exercise rights, contact Stellar Apex Tech Limited at UNIT 11, 9/F THE CLOUD NO.111 TUNG CHAU ST TAI KOK TSUI HONG KONG, or email privacy@link-io.cloud. General support: support@link-io.cloud.
16.2 Complaints. If you are not satisfied with our response, you may complain to your local supervisory authority or seek a remedy under applicable law, as described in Section 12.6.