Kurrens Privacy Policy
Last Updated: September 28, 2026
This Privacy Policy (this “Policy”) describes how INFERERA PTE. LTD., a company incorporated in Singapore (UEN 202631576H), together with its subsidiaries and affiliates (collectively, “Kurrens,” “we,” “us,” or “our”), collects, uses, discloses, retains, and otherwise processes personal data in connection with the Kurrens website, API, console, documentation, and related products and services (collectively, the “Services”).
This Policy applies to individual users, business customers, and other authorized users of the Services (collectively, “you” or “your”). Jurisdiction-specific terms are provided in the Annex.
The short version. We run open-weight AI models on infrastructure we operate. We do not store, log, or train on the prompts you send or the completions you receive. We keep the account, billing, and request metadata we need to run and bill the Services. We do not sell or share your personal data. Details follow.
If you have any questions or wish to exercise your rights, contact us at support@kurrens.ai (see “How to Contact Us”).
Table of Contents
- Who Is Responsible for Your Personal Data
- Inference Data: Prompts and Completions
- Personal Data We Collect and How We Use It
- Disclosure and Transfer of Personal Data
- Where We Process Data and Cross-Border Transfers
- Retention of Personal Data
- Your Rights
- Electronic Communications
- Protection of Personal Data
- Personal Data of Minors
- Cookies and Similar Technologies
- Updates to This Policy
- How to Contact Us
- Dispute Resolution
- Annex: Jurisdiction-Specific Additional Terms
1. Who Is Responsible for Your Personal Data
INFERERA PTE. LTD. is responsible for the personal data described in this Policy as a data controller (or equivalent term under applicable law) for account, billing, website, and support data.
For personal data that may be contained in Customer Content (the prompts, files, and other inputs you submit to the API and the outputs the Services generate), we act as a data processor (or service provider) on your behalf, and our processing is governed by our Terms of Service, our Data Policy, and, where signed, our Data Processing Addendum.
For jurisdiction-specific information, see the Annex.
2. Inference Data: Prompts and Completions
- Not stored. Customer Content is processed in memory for the duration of each request and is discarded when the response is delivered. It is not written to persistent storage and is not included in our logs.
- Not used for training. We do not use Customer Content to train, fine-tune, evaluate, or otherwise improve any model, whether ours or anyone else’s.
- Not shared. We run the models ourselves. Customer Content is not sent to model developers or other third parties.
- Limited exceptions. We capture specific Customer Content only (a) when you ask us to troubleshoot a specific issue and give us written permission, in which case we delete it within thirty (30) days after the issue is resolved; or (b) where we are legally required to preserve it. Batch or asynchronous jobs, if you use them, are stored encrypted only until results are delivered, as described in our Data Policy.
Our full commitment is set out in our Data Policy, which prevails over this Policy if there is any conflict regarding Customer Content.
3. Personal Data We Collect and How We Use It
We process personal data only as necessary to provide, maintain, secure, and improve the Services and for the purposes described in this Policy. We will indicate whether information is required or optional and explain the impact of not providing required information.
3.1 Registration and Login
When you register, we collect your email address and, if you choose, your name and password. If you sign in with a third-party account (such as Google or GitHub), we receive your account identifier and email address, depending on the permissions you grant. We use this information to create and manage your account and provide access to the Services.
3.2 Account Settings
When you manage your account, organization, or team members, we process the information you provide (such as email addresses of invited members) to maintain and manage your account.
3.3 Providing the API: Request Metadata
To provide and bill for the API, we process request metadata: API key identifier, IP address, requested model, request and response timestamps, token counts, latency, response status code, service tier, and fee-related information. Request metadata does not include the content of your prompts or completions. We use it to authenticate requests, enforce rate limits, calculate fees, display usage statistics and billing records, investigate errors, detect abuse, and maintain service performance.
3.4 API Keys
API keys are the credentials for accessing the API. We store keys in hashed form and display each key only once when it is created. You can create, view metadata for, and revoke keys in the console at https://console.kurrens.ai. Revoking a key immediately stops requests made with it.
3.5 Payment Services
When you purchase credits, payments are processed by third-party payment processors, such as Stripe. We receive limited payment information, such as amount, currency, order number, payment status, card brand, and the last four digits of your card, to verify transactions, apply credits, issue invoices, and process refunds. We do not store full card numbers. For how Stripe processes personal data, see https://stripe.com/privacy.
3.6 Customer Service and Sales
When you contact us, we collect the information you provide, such as your name, email address, company, role, and the content of your message, to respond to your request, provide support, and improve the Services.
3.7 Security and Service Stability
We process operational records needed to authenticate users, provide and bill for the API, investigate errors, and protect the Services, including IP addresses, user agent, access times, authentication and security events, API key identifiers, requested models, token consumption, and billing records.
3.8 Optional Website Analytics
With your consent, we use Google Analytics to understand how our website is used and to improve it — not for advertising. Analytics may include page visits, selected clicks and scrolling events, browser and device information, and pseudonymous cookie or account identifiers. Analytics is never used to collect prompts, completions, API key secrets, passwords, or payment details. Rejecting analytics does not affect your use of the Services. Accepting this Policy or continuing to browse does not by itself constitute consent to analytics. See our Cookie Policy.
4. Disclosure and Transfer of Personal Data
We do not sell personal data, and we do not provide personal data to third parties for their own marketing. We disclose personal data only to:
- Service providers (sub-processors) that help us operate the Services, such as cloud and data center providers, payment processors, email delivery providers, analytics providers (with your consent), and customer support tools. They may access personal data only as needed to perform services for us and must protect it. Our current list is at Sub-processors.
- Affiliates that help us operate, develop, and support the Services, subject to this Policy.
- Public authorities, where required by law or legal process, or where necessary to protect the rights, property, or safety of Kurrens, our users, or others, including to prevent fraud or abuse.
- Successors, in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
We do not “sell” or “share” personal data as those terms are defined under California law.
5. Where We Process Data and Cross-Border Transfers
Inference requests are processed in data centers located in Malaysia (Johor), Indonesia (Jakarta), and Ireland (Dublin). Requests are served from Johor by default, with Jakarta as a second Asia Pacific region; Dublin hosts European dedicated deployments and serves as a failover region. Account, billing, and website data are stored with our cloud providers in {{COUNTRY}}. Our sub-processors and affiliates may process personal data in other countries, as listed on our Sub-processors page.
When we transfer personal data across borders, we use appropriate safeguards required by applicable law, such as contractual protections (including the European Commission’s Standard Contractual Clauses where applicable) and, for transfers out of Singapore, measures that provide a standard of protection comparable to the Personal Data Protection Act 2012.
6. Retention of Personal Data
| Data | Retention |
|---|---|
| Customer Content (prompts, completions) | Not retained (see Section 2 and our Data Policy) |
| Request metadata | [[13 months]], then deleted or aggregated, unless needed longer to resolve a dispute or comply with law |
| Account data | While your account is active; deleted or anonymized within three (3) months after account closure, unless required by law |
| Payment and invoice records | As long as required by tax and accounting laws |
| Support communications | While your account is active or as long as necessary to resolve the request |
| Analytics data | As configured in Google Analytics, not longer than [[14 months]] |
7. Your Rights
Subject to applicable law, you may have the right to know about, access, correct, delete, restrict or object to the processing of, and receive a portable copy of your personal data; to withdraw consent; and to lodge a complaint with a supervisory authority. To exercise these rights, email support@kurrens.ai. We may need to verify your identity. We will not discriminate against you for exercising your rights. We may charge a reasonable fee for requests that are manifestly unfounded or excessive where permitted by law.
Because we do not retain Customer Content, we cannot access, export, or delete prompts or completions after a request completes.
See the Annex for jurisdiction-specific rights and response times.
8. Electronic Communications
We send service communications (such as security alerts, billing notices, model retirement notices, and maintenance updates) that you cannot opt out of while you have an account. If you subscribe to product updates, we use a double opt-in process, and you can unsubscribe at any time using the link in each email.
9. Protection of Personal Data
We use technical and organizational measures designed to protect personal data, including encryption in transit (TLS), encryption of stored credentials, access controls based on least privilege, logging of administrative access, and incident response procedures. No system is completely secure. If we become aware of a personal data breach, we will notify you and the relevant authorities as required by applicable law.
10. Personal Data of Minors
The Services are intended for adults and businesses and are not directed to children. We do not knowingly collect personal data from children under 13 (in the United States), under 16 (in the EU/UK), or under the age defined by local law. If you believe a child has provided us with personal data, contact support@kurrens.ai and we will delete it.
11. Cookies and Similar Technologies
We use strictly necessary cookies to operate our website and console, and, only with your consent, analytics cookies. See our Cookie Policy.
12. Updates to This Policy
We may update this Policy from time to time. We will post the updated Policy with a new “Last Updated” date and, for material changes, notify you by email or through the Services before the changes take effect.
13. How to Contact Us
INFERERA PTE. LTD., 152 Beach Road, #11-05, Gateway East, Singapore 189721
Privacy and data protection requests, including for our Data Protection Officer: support@kurrens.ai (subject line “Privacy” or “Attn: Data Protection Officer”)
We will respond to verified requests within the timeframes required by applicable law.
14. Dispute Resolution
Depending on your jurisdiction, you may have the right to lodge a complaint with a competent data protection authority.
Any dispute arising out of or relating to this Policy will be finally resolved by arbitration administered by the Singapore International Arbitration Centre (SIAC) in accordance with the SIAC Arbitration Rules then in force. The seat of arbitration is Singapore, the tribunal consists of one (1) arbitrator, and the proceedings are conducted in English. All claims must be brought in an individual capacity and not as part of any class, consolidated, or representative proceeding.
If you reside in a jurisdiction listed in the Annex, this Policy is governed by the laws of that jurisdiction to the extent required by those laws. Otherwise, it is governed by the laws of Singapore.
15. Annex: Jurisdiction-Specific Additional Terms
15.1 Singapore
Identity. We are subject to the Personal Data Protection Act 2012 (“PDPA”). INFERERA PTE. LTD. is an “organisation” under the PDPA.
Data Protection Officer. Our Data Protection Officer can be contacted at support@kurrens.ai.
Consent and withdrawal. Where we rely on consent, you may withdraw it at any time by contacting our DPO. We will inform you of the likely consequences of withdrawal before acting on it.
Access and correction. You may request access to your personal data in our possession or control and information about how it has been used or disclosed within the year before your request, and you may request correction of errors or omissions. We will respond as soon as reasonably possible and, for access requests, within thirty (30) days or inform you of the time needed.
Accuracy. You agree to provide accurate information and to tell us about changes.
Data breach notification. We will notify the Personal Data Protection Commission and affected individuals of notifiable data breaches as required by the PDPA.
Do Not Call. We do not send marketing messages to Singapore telephone numbers without complying with the PDPA’s Do Not Call provisions.
15.2 European Union, European Economic Area, and United Kingdom
Identity. For the processing described in Section 3, INFERERA PTE. LTD. is the “controller” under the General Data Protection Regulation (“GDPR”) and the UK GDPR. For Customer Content, we are a “processor” under our Data Processing Addendum. [[EU/UK representative under Art. 27 GDPR: {{NAME / CONTACT}}]]
Legal bases.
| Category of Personal Data | Purpose | Legal Basis |
|---|---|---|
| API key identifier, IP address, requested model, timestamps, token counts | Providing the API, authenticating requests, enforcing rate limits | Contract |
| Usage and fee data | Usage statistics, billing records, invoices | Contract |
| Email, name, third-party account ID, password | Account registration and login | Contract |
| Payment amount, order number, payment status | Processing payments and applying credits | Contract; Legal obligation (tax records) |
| Contact details and message content | Responding to inquiries and support requests | Legitimate interests; Consent (sales inquiries) |
| Security and diagnostic records (IP, user agent, access times, errors) | Protecting accounts, preventing abuse, maintaining stability | Legitimate interests |
| Optional website analytics | Understanding and improving our website (not advertising) | Consent |
Your rights. Access; rectification; erasure; restriction of processing; data portability; objection (including to processing based on legitimate interests and at any time to direct marketing); not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects; withdrawal of consent; and the right to lodge a complaint with a supervisory authority (see https://www.edpb.europa.eu/about-edpb/about-edpb/members_en). We respond within one (1) month, extendable by two (2) months for complex or numerous requests.
Transfers. Transfers outside the EEA/UK rely on adequacy decisions or the Standard Contractual Clauses (and the UK Addendum), as applicable.
Children. We do not knowingly collect data from children under 16.
15.3 United States
Definitions. “Personal information” and “sensitive personal information” have the meanings given in applicable state privacy laws.
Identity. This section is provided for California residents under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”) and applies to residents of other U.S. states with comparable laws. INFERERA PTE. LTD. is a “business” for the data in Section 3 and a “service provider” for Customer Content.
Personal information collected in the past 12 months.
| Category | Statutory Category | Business Purpose |
|---|---|---|
| Email, name, company, role | Identifiers | Account management, support |
| Password, third-party account ID | Sensitive personal information (account log-in) | Account login only |
| IP address, user agent, requested model, timestamps, token counts | Identifiers; Internet or other electronic network activity | Providing and securing the API |
| Payment amount, order number, payment status | Commercial information | Payments and billing |
We do not sell or share personal information, and we do not use or disclose sensitive personal information for purposes that would give rise to a right to limit.
Your rights. To know and access; to correct; to delete; to opt out of sale or sharing (we do neither); to limit use of sensitive personal information; and to non-discrimination. Submit requests to support@kurrens.ai. You may use an authorized agent. We respond within forty-five (45) days.
Do Not Track / Global Privacy Control. We do not track users across third-party websites for advertising. We honor Global Privacy Control signals as a rejection of optional analytics cookies.
Children. We do not knowingly collect data from children under 13.
15.4 South Korea
Identity. We are subject to the Personal Information Protection Act (“PIPA”). INFERERA PTE. LTD. is a “personal information controller.”
Your rights. To know; to access; to data portability; to rectification and erasure (except where collection is required by law); to suspend processing and withdraw consent; to object to and request an explanation of automated decisions that significantly affect your rights; and to claim compensation for damages caused by our violation of PIPA.
15.5 Indonesia
Identity. We are subject to Law No. 27 of 2022 on Personal Data Protection (“PDPL”). INFERERA PTE. LTD. is a “data controller.”
Your rights. To obtain information about processing; to complete and correct your data; to access and obtain a copy; to erasure and termination of processing; to withdraw consent; to object to decisions based solely on automated processing; to delay or restrict processing; to complain and claim compensation; and to data portability.