Operator: Zable AI. Registration country, contact details, retention schedules and final purchase policies are pending confirmation. This is a local review draft, not a final published policy.
01Scope and operator
Zable AI operates the customer service described here. This notice covers information processed for accounts, API access, billing and support. Registered location, contact details and deployment-specific retention information remain to be completed before public release. A separate written data-processing agreement, if entered into, may govern processing for a business customer.
02Account and authentication data
The service processes your email address, profile name, password hash, verification and recovery information, account status and access permissions. If enabled and chosen, GitHub or Google sign-in supplies identity information such as a provider identifier, verified email and profile information. Zable does not receive your GitHub or Google password. Authentication cookies are used to maintain your session.
03Requests and technical records
Your prompts, messages, attachments and other request inputs pass through Zable and the configured inference provider to generate responses. Operational records can include model and API-key identifiers, timestamps, token counts, credit charges, response mode, latency, IP address, user agent, request IDs and error information. Troubleshooting or security records may contain request-related content depending on configuration. This service does not currently offer a verified, universal zero-retention guarantee.
04Why information is used
Information is used to create and secure accounts, verify email, provide model responses, calculate usage, manage payments, investigate failures and abuse, respond to support and meet applicable legal obligations. Where data-protection law requires a legal basis, the relevant basis may be performance of a contract, compliance with law, a legitimate interest subject to applicable balancing requirements, or consent for a genuinely optional activity. Acknowledging this notice is not blanket consent to unrelated marketing or every possible use of data.
05Providers and recipients
Inference providers receive the content needed to fulfill model requests. Infrastructure and security providers may process operational data. Resend currently supplies transactional email delivery and receives recipient addresses and message content, including verification or recovery messages. GitHub and Google process their own authorization flows when used. When payments are enabled, the selected payment provider processes payment details and returns transaction status and identifiers. Information may also be disclosed when lawfully required or necessary to resolve abuse or legal claims.
06Model providers and international processing
The model developer and the inference supplier serving a request may be different organizations. Their retention, training and other processing practices may differ. A model brand alone does not identify where its inference takes place or how its supplier uses data. Requests may be processed outside your country, potentially including China or other supplier locations. Do not assume regional isolation or that every supplier excludes training. Supplier identities, applicable data terms and any necessary transfer arrangements must be verified for the deployed routes before sensitive or regulated data is submitted.
07Cookies and choices
The customer site uses authentication and OAuth cookies, temporary verification-session cookies and a language-preference cookie. These support sign-in, authorization and your selected language. Blocking essential cookies may prevent account functions from working. The current customer frontend does not include an advertising or audience-analytics SDK. Any future optional tracking would require its own disclosure and any choice or consent required by applicable law.
08Retention and security
Different records have different purposes: account data supports your account, usage data supports billing and support, and security records support investigation. Billing or legal records may need to be retained after account closure. The exact production retention schedule, backup deletion process and supplier periods have not yet been finalized for this draft; no fixed deletion deadline is promised here. Password hashing, session controls and access restrictions help protect information, but no system can eliminate all risk. Deleting an API key revokes access; it does not by itself erase historical usage records.
09Your requests and responsibilities
Depending on applicable law, you may have rights to access, correct, delete or receive a copy of personal data, object to or restrict certain processing, withdraw consent where relied upon, and complain to a competent authority. Identity or authority verification may be needed. These rights can be subject to lawful exceptions, including necessary billing or legal records. Contact channels for these requests will be added before public launch. Submit only data you are authorized to use, and avoid unnecessary sensitive data. The service is not designed for children.
10Updates and contact
Updates will be identified by the version on this page, with additional notice where required. The operator is Zable AI. Its privacy email, registered jurisdiction and address remain pending and will be added here. This draft does not claim a certification, a completed transfer assessment or a guaranteed response period that has not been established.