Privacy Policy

Last updated: July 2026

1. About this service

Napu AI, operated by Temporalis LLC, provides serverless AI inference through an OpenAI-compatible HTTP API. We host open-weight chat and embedding models on dedicated hardware and bill per token. This policy describes what data we collect when you sign up, generate API tokens, and send inference requests.

Registration is open to the public. By creating an account or sending a paid inference request, you agree to this policy.

2. We do not train on your data

We do not use the prompts you send or the completions our models return to train, fine-tune, or evaluate any model. We do not sell, license, or share inference content with third parties. Your inputs and outputs are processed only to fulfil the request you made.

3. Data we collect

The categories of data we hold are:

  • Account credentials. Email address and a hashed password (bcrypt). We never store passwords in plain text.
  • API tokens. Tokens you generate are stored as SHA-256 hashes. We cannot recover the plain-text value once issued, only verify it.
  • Inference usage logs. For each API call we record the model, endpoint, input and output token counts, and the resulting cost. We do not retain the prompt text or the completion text in these logs.
  • Credit transactions. Every credit movement (plan credits, grants, debits) is recorded with timestamp, amount, and a short description, as required for billing and accounting.
  • Payment data. If you pay with a card, payment details are handled by our payment processor and we never see or store your full card number. If you pay with x402 over USDC on the Base network, the transaction is recorded on the public blockchain by design.
  • Operational logs. Standard HTTP logs (IP address, user agent, request path, response status) are kept short-term for security and abuse prevention.

Cookies and analytics

We do not use cookies for advertising and we run no third-party trackers. Three kinds of browser storage exist:

  • Strictly necessary. Session and authentication storage that keeps you signed in, plus your saved preferences such as theme and your choice below. Always on.
  • Product analytics (PostHog). Page views, and a first-party identifier stored as a cookie and in local storage so a return visit counts as the same person instead of a new one. Autocapture of clicks and form inputs is switched off.
  • Session replay (PostHog). A recording of screen activity inside the signed-in build area only, so we can see where the product confuses people. Marketing pages, shared cockpits, and shared views are never recorded.

If you are in the EEA, the UK, or Switzerland, analytics and session replay stay off until you allow them, and nothing is stored before that. You can change your choice any time with the "Cookies" link in the footer. Charts you embed on other sites are never tracked.

4. Retention

  • Inference usage rows are pruned automatically after roughly 24 hours. They exist only to power the in-app billing view.
  • Async inference job rows are deleted as soon as a job completes or fails.
  • Credit transactions are kept for the lifetime of the account, plus the period required by tax and accounting law (typically up to seven years).
  • Account data is kept while your account is active. If you delete your account, account data is removed within 30 days, except where retention is legally required.
  • Operational logs are retained for up to 30 days.

5. How we use data

We use the data described above only to:

  • Authenticate you and verify your API tokens.
  • Route your inference requests to the correct model and bill them accurately.
  • Detect abuse, enforce rate limits, and protect the service.
  • Send you transactional email about your account (for example, billing notices). We do not send marketing email without explicit opt-in.

6. Subprocessors

We rely on a small number of third-party providers to run the service. Today these include:

  • Cloud hosting and managed PostgreSQL (DigitalOcean).
  • A card payment processor (Stripe) for monthly subscription payments.
  • The x402 facilitator and the Base blockchain network, for crypto micropayments.
  • Product analytics (PostHog) to understand how our website and product are used.

We will keep this list current as we add or change subprocessors.

7. Security

All API traffic is served over TLS. Passwords are hashed with bcrypt. API tokens are stored as SHA-256 hashes, so a database leak does not expose usable tokens. Database access is restricted to the application backend on a private network. Beyond the strictly necessary frontend bundle and our product-analytics script (PostHog), we do not run third-party scripts in the browser.

8. Your rights

You can request access to, correction of, or deletion of your personal data at any time. If you are in the EEA, the UK, or California, you also have rights under GDPR or the CCPA, including the right to portability and the right to object to certain processing. To exercise any of these rights, email the address in section 11.

9. International transfers

Our infrastructure is currently located in the United States. If you access the service from outside the United States, your data will be transferred to and processed there. We rely on standard contractual clauses or equivalent mechanisms where required.

10. Children

Napu AI is not directed to children. You must be at least 16 years old to create an account. We do not knowingly collect personal data from anyone under that age.

11. Contact

For privacy questions, data access requests, or deletion requests, email support@napu.ai. We respond to verified requests within 30 days.

12. Changes to this policy

We may update this policy as the service evolves (for example, when we add monitoring features or new subprocessors). Material changes will be posted here with a new "Last updated" date. Continued use after a change constitutes acceptance.