Legal
Privacy Policy
Last updated: June 2026
1. Who we are
Thalam operates an API gateway service. This policy explains what personal data we collect, why we collect it, and what we do with it. If you have questions, email privacy@thalam.ai.
2. What we collect
We collect the following information when you use our service:
- Account information — your email address and hashed password when you register
- Usage metadata — for each API request: the model used, number of input and output tokens, estimated cost, timestamp, and which API key was used
- Billing information — your account balance, top-up history, and Stripe payment records (Stripe handles card details directly; we never see your raw card number)
- API keys — we store a hashed version of your keys for authentication; the plaintext key is shown to you once at creation and not stored
3. What we do NOT store
We do not store the content of your prompts or the content of the model's responses. Your request is held in memory only for as long as it takes to route it to the model you selected and return the response to you — the prompt and response bodies are never written to our database. The only request-level data we keep is the usage metadata described in Section 2 (model, token counts, cost, timestamp, API key, and a routing trace identifier).
If an upstream provider rejects a request with an error, we may record a short technical diagnostic — such as the error status code and the request trace identifier — to investigate the failure. We do not use it to reconstruct your prompts, and it is subject to the retention limits in Section 7. What you send to AI models is your business.
4. How we use your data
We use the data we collect to:
- Calculate and deduct credits from your balance after each request
- Display your usage history in your dashboard
- Detect and prevent abuse, fraud, and policy violations
- Send you transactional emails (account confirmation, billing receipts)
- Improve the service — for example, understanding which models are most used to prioritise infrastructure
We do not sell your data. We do not use your data for advertising. We do not use your prompts or the model's responses to train, fine-tune, or improve any AI model — ours or anyone else's.
5. Third parties we work with
Running this service requires sharing some data with third-party providers:
- Supabase — hosts our database and authentication system. Your account data and usage metadata are stored on Supabase infrastructure.
- Stripe — processes payments. When you top up your balance, your payment flows through Stripe. We receive a confirmation and the amount; Stripe holds your card data under their own privacy policy.
- Cloudflare — provides the edge network that routes and protects API traffic.
- Email delivery — a third-party email provider delivers transactional messages such as account, billing, and service notices.
- AI model providers — to generate a response, your request is forwarded in real time to the third-party provider that hosts the specific model you call, which processes it under its own data-handling terms. We select providers that commit not to use API inputs to train their models; some providers retain inputs briefly for security and abuse-prevention, while others retain nothing. For sensitive workloads, we recommend reviewing the terms of the specific model you rely on.
6. Data residency and international transfer
Your account data and usage metadata are stored on our managed cloud infrastructure (Supabase). This infrastructure, and the third-party model providers that fulfil your requests, may process your data in countries outside the UAE. Where personal data is transferred across borders, we rely on your consent and, where applicable, appropriate contractual safeguards. By using the service, you consent to this processing and transfer. We can provide the specific processing region on request.
If you require a specific processing region or additional data-handling assurances for a sensitive deployment, contact us at privacy@thalam.ai.
7. Data retention
We retain your account data and usage logs for as long as your account is active. Billing records are kept for seven years to comply with financial record-keeping requirements.
If you delete your account, we delete your profile, API keys, and usage logs within 30 days. Anonymised aggregate statistics (e.g. total requests per model per day) may be retained indefinitely.
8. Your rights
You can, at any time:
- Access the data we hold about you via your dashboard
- Delete your account and all associated data by going to your dashboard settings
- Request a copy of your usage data by emailing privacy@thalam.ai
- Ask us to correct inaccurate information
Deleting your account is permanent. Unused credits cannot be recovered after account deletion.
9. Security
We use industry-standard security practices: encryption in transit (HTTPS/TLS) for all traffic and encryption at rest for stored data, hashed passwords (bcrypt), hashed API keys, and row-level security on all database tables so that each user can only access their own records.
No system is perfectly secure. If you discover a vulnerability, please report it to privacy@thalam.ai.
10. Changes to this policy
We may update this policy. If the changes are significant, we will notify you by email at least 14 days before they take effect. The date at the top of this page always reflects the last update.
11. Contact
Privacy questions or data requests: privacy@thalam.ai
For legal matters, see our .