Data Security & Privacy Statement
Last updated: September 2026
This statement outlines our data flow, retention rules and shared security responsibilities. The signed agreement prevails for formal terms.
1. Data Flow Overview
Your application / client │ HTTPS encryption (TLS 1.2+) ▼ TK NovaLink API gateway (Singapore region) │ Authentication · quota & billing · usage metadata only │ Conversation content (prompts / responses) is never persisted ▼ HTTPS encryption Official direct-connect interfaces of model providers (e.g. AWS) ▼ The selected model runs inference and returns the result
2. How Data Flows
Your requests travel over HTTPS to the TK NovaLink API gateway hosted in a Singapore region data center. The gateway performs authentication, quota metering and request forwarding only, then passes the request over an encrypted channel to the official direct-connect interface of the model provider (e.g. AWS), where the selected model runs inference and returns the result. The path is encrypted end to end, and conversation content is never cached or persisted at the gateway.
3. We Do Not Store Conversation Content
We do not store, read or analyze the prompts you submit or the content returned by models. Playground chat history is stored only in your own browser's local storage, never uploaded to our servers, and you may clear it at any time.
4. What We Do Store
To operate accounts and billing, the platform stores only: ① account information (username, email, salted password hash); ② API keys (encrypted at rest; the full key is shown only once at creation); ③ usage metadata logs (model name, token counts, cost, timestamp) for billing reconciliation; ④ redemption codes and redemption records.
5. Retention & Deletion
Usage metadata logs are retained for reconciliation by default. If you require a defined retention period (e.g. 90 days), contact us and we will configure a periodic purge. After account closure, associated account data is deleted within a reasonable period.
6. Transport & Storage Security
HTTPS (TLS 1.2+) is enforced site-wide; passwords and API keys are stored encrypted; administrative access follows role-based permissions with audit trails; servers are hosted in a Singapore region data center and operated independently by us.
7. Upstream Model Providers
Inference requests are processed by model providers (e.g. AWS) through their official direct-connect interfaces, subject to each provider's API data policy; mainstream commercial API tiers do not use customer data for model training by default. For highly sensitive workloads, choose models with explicit zero-retention commitments, or contact us for a dedicated channel deployment.
8. Shared Responsibility
We are responsible for: gateway and server security, transport encryption, key management, access control, billing log accuracy and anomaly monitoring. Model providers are responsible for: data handling during model inference, under their own data policies. Customers are responsible for: safeguarding accounts and API keys, and for the compliance of submitted content — we recommend not sending classified data or sensitive personal information, or de-identifying it before calling the API.
9. Contact Us
For further security documentation, due-diligence materials or dedicated deployment options, reach us via the business contact email on the About page.