Privacy Policy
Last updated: July 2026
1. About this service
Napu AI, operated by Temporalis LLC, provides serverless AI inference through an OpenAI-compatible HTTP API. We host open-weight chat and embedding models on dedicated hardware and bill per token. This policy describes what data we collect when you sign up, generate API tokens, and send inference requests.
Registration is open to the public. By creating an account or sending a paid inference request, you agree to this policy.
2. We do not train on your data
We do not use the prompts you send or the completions our models return to train, fine-tune, or evaluate any model. We do not sell, license, or share inference content with third parties. Your inputs and outputs are processed only to fulfil the request you made.
3. Data we collect
The categories of data we hold are:
- Account credentials. Email address and a hashed password (bcrypt). We never store passwords in plain text.
- API tokens. Tokens you generate are stored as SHA-256 hashes. We cannot recover the plain-text value once issued, only verify it.
- Inference usage logs. For each API call we record the model, endpoint, input and output token counts, and the resulting cost. We do not retain the prompt text or the completion text in these logs.
- Credit transactions. Every credit movement (plan credits, grants, debits) is recorded with timestamp, amount, and a short description, as required for billing and accounting.
- Payment data. If you pay with a card, payment details are handled by our payment processor and we never see or store your full card number. If you pay with x402 over USDC on the Base network, the transaction is recorded on the public blockchain by design.
- Operational logs. Standard HTTP logs (IP address, user agent, request path, response status) are kept short-term for security and abuse prevention.
4. Retention
- Inference usage rows are pruned automatically after roughly 24 hours. They exist only to power the in-app billing view.
- Async inference job rows are deleted as soon as a job completes or fails.
- Credit transactions are kept for the lifetime of the account, plus the period required by tax and accounting law (typically up to seven years).
- Account data is kept while your account is active. If you delete your account, account data is removed within 30 days, except where retention is legally required.
- Operational logs are retained for up to 30 days.
5. How we use data
We use the data described above only to:
- Authenticate you and verify your API tokens.
- Route your inference requests to the correct model and bill them accurately.
- Detect abuse, enforce rate limits, and protect the service.
- Send you transactional email about your account (for example, billing notices). We do not send marketing email without explicit opt-in.
6. Subprocessors
We rely on a small number of third-party providers to run the service. Today these include:
- Cloud hosting and managed PostgreSQL (DigitalOcean).
- A card payment processor (Stripe) for monthly subscription payments.
- The x402 facilitator and the Base blockchain network, for crypto micropayments.
- Product analytics (PostHog) to understand how our website and product are used.
We will keep this list current as we add or change subprocessors.
7. Security
All API traffic is served over TLS. Passwords are hashed with bcrypt. API tokens are stored as SHA-256 hashes, so a database leak does not expose usable tokens. Database access is restricted to the application backend on a private network. Beyond the strictly necessary frontend bundle and our product-analytics script (PostHog), we do not run third-party scripts in the browser.
8. Your rights
You can request access to, correction of, or deletion of your personal data at any time. If you are in the EEA, the UK, or California, you also have rights under GDPR or the CCPA, including the right to portability and the right to object to certain processing. To exercise any of these rights, email the address in section 11.
9. International transfers
Our infrastructure is currently located in the United States. If you access the service from outside the United States, your data will be transferred to and processed there. We rely on standard contractual clauses or equivalent mechanisms where required.
10. Children
Napu AI is not directed to children. You must be at least 16 years old to create an account. We do not knowingly collect personal data from anyone under that age.
11. Contact
For privacy questions, data access requests, or deletion requests, email support@napu.ai. We respond to verified requests within 30 days.
12. Changes to this policy
We may update this policy as the service evolves (for example, when we add monitoring features or new subprocessors). Material changes will be posted here with a new "Last updated" date. Continued use after a change constitutes acceptance.