Legal
Privacy Policy
Last updated October 1, 2026
This Privacy Policy explains how Zurelay LLC (Zurelay, we, us or our) collects, uses, shares and protects personal data when you use the zurelay websites, dashboard, playground and API (the Services). The Services are built for businesses and developers. Capitalized terms not defined here have the meanings given in our Terms of Service.
1. Our role
We are the controller of the personal data we collect to run our business: account, workspace, billing, support, security and website data.
When our business customers send content through the Services, such as prompts, files and the outputs generated from them, any personal data in that content is processed by us as a processor or service provider on the customer's behalf and under the customer's instructions, and our Data Processing Addendum applies. If you are a user of one of our customers' products, please contact that customer about your data; we will refer requests we receive to them.
2. Personal data we collect
2.1 Account and workspace data. Your email address, your name if you give it, workspace names, team membership and roles, and your settings. You sign in with one-time codes we email to you, so we do not store passwords.
2.2 API keys. Each key's name, prefix and limits. The full secret is shown to you once and stored by us only as a one-way hash.
2.3 Billing data. Your purchases, Credit balance and ledger, Promotional Credits, receipts and invoices, and identifiers from our payment processor. Card details are collected and stored by our payment processor; we never receive your full card number.
2.4 Usage data. For every request: the time, model, endpoint and API key used; token, image or video counts; cost and list price; status and error codes; latency; and which of our routes served it. We use this to bill you, show your request history, run and improve the Services and keep them secure.
2.5 Content you send through the Services.
- Chat and text requests: we process prompts and responses in memory while serving the request and do not store them.
- Images: generated images and the prompts that produced them are stored so you can view and download them, and are deleted after 30 days.
- Videos: the prompt, settings and any reference images you send are stored to produce and deliver the video. The video, the prompt and the reference images are deleted after 30 days. A record of the job without that content (time, model, length, status and cost) stays with your billing history.
- Error details: when an attempt to serve a request fails, we keep the error message returned for up to 30 days to diagnose problems. Such messages can occasionally quote part of a request or response.
- Content is sent to Infrastructure Providers to generate outputs (see Section 4). We do not use your content to train artificial intelligence models and we do not sell it.
2.6 Communications. Emails and support messages you send us, and records of the emails we send you, such as sign-in codes, receipts and account alerts.
2.7 Device and log data. IP address, browser and device information, and timestamps and security events when you use the websites, the dashboard or the API, kept in our server logs.
2.8 Cookies and local storage. We use only what the Services need to work: keeping you signed in and remembering preferences such as your theme. We do not use advertising cookies or third-party analytics trackers. If that changes, we will update this Policy and ask for consent where the law requires it.
3. How we use personal data
Where the GDPR, UK GDPR or similar laws apply, we rely on the legal bases shown in brackets.
- To create and run your account and workspaces, authenticate you, serve your requests and store your generated files (performance of our contract with you).
- To charge for the Services, process payments and promotions, prevent fraud and keep tax and accounting records (contract, legal obligation and our legitimate interest in being paid and preventing fraud).
- To secure the Services, monitor reliability, prevent abuse and enforce our Terms (legitimate interests).
- To provide support and send service messages, such as receipts, security notices and changes to our terms (contract and legitimate interests).
- To understand and improve the Services, mainly through aggregated or de-identified usage data (legitimate interests).
- To send you news about our products, where the law allows; you can unsubscribe at any time (consent or legitimate interests).
- To comply with law, respond to lawful requests and establish, exercise or defend legal claims (legal obligation and legitimate interests).
5. International transfers
Zurelay is based in the United States. We and our service and Infrastructure Providers process personal data in the United States and in other countries, which may have data protection laws different from those where you live. Where the law requires it, we use recognized safeguards for transfers, such as the European Commission's Standard Contractual Clauses.
6. How long we keep personal data
| Data | How long |
|---|---|
| Chat and text request content | Not stored |
| Generated images and videos, their prompts and reference images | 30 days |
| Error details from failed attempts | 30 days |
| Server and security logs | Up to 30 days, longer while investigating an incident |
| Account and workspace data | While your account is open, then deleted or de-identified within 90 days |
| Usage records (no content) | While your workspace exists, then as part of billing records |
| Billing, payment and tax records | Up to 7 years after the transaction |
| Support communications | Up to 3 years |
We may keep data longer where the law requires it, to resolve disputes, or to enforce our agreements. Backups are deleted on their normal schedule.
7. Security
We protect personal data with measures appropriate to the risk, including encryption in transit, storing API keys only as one-way hashes, encryption at rest provided by our hosting providers, and limiting access to production systems to the people who need it. No system is perfectly secure, so we cannot guarantee the security of personal data. You are responsible for keeping your API keys and email account secure.
8. Your rights and choices
Depending on where you live, you may have the right to access, correct or delete your personal data, to receive a copy of it, to object to or restrict our processing of it, to withdraw consent, and to opt out of the sale or sharing of personal data or targeted advertising (we do neither). If you are in the European Economic Area, the United Kingdom or Switzerland, you may also complain to your data protection authority.
To exercise a right, email support@zurelay.com with “Privacy request” in the subject. We will verify your identity before acting, may ask an authorized agent for proof of authority, and will respond within the time the law requires. If we decline a request, you may appeal by replying to our response. We will not discriminate against you for exercising your rights. Requests about content our customers sent through the Services will be referred to the customer concerned.
9. Children
The Services are for businesses and are not directed to children. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes to this Policy
We may update this Policy from time to time. We will post the updated Policy with a new date and, for material changes, notify you by email or in the Services.
11. Contact
Questions and requests about privacy can be sent to Zurelay LLC at support@zurelay.com.
Questions about this document?
Zurelay LLC answers legal and privacy questions by email.