Privacy Policy

Effective Date: April 1, 2026 · Last Updated: August 17, 2026

Shineon Intelligence LIMITED ("Shineon", "we", "us", or "our") takes the protection of your personal information seriously. This Privacy Policy describes how we collect, use, store, share, and protect your information when you use the Shineon platform and related services (the "Service"), available at https://www.shineon.dev. Please read this Policy carefully before using the Service, paying particular attention to the sections marked as important.

1. Information We Collect

We collect the following information under the principle of "minimum necessity":

  • Registration & Login: email address, phone number, and password (stored in encrypted form) — used to create and manage your account and verify your identity.
  • Payments & Billing: transaction records and order information returned by payment providers — used to complete billing, reconciliation, and issue receipts.
  • API Access: the API keys issued to your account and records of their use — used to authenticate your API requests, manage access, and detect unauthorized use. Keep your API keys confidential; we store them securely and never ask you to disclose them outside the Service.
  • Service Usage: IP address, access times, models invoked, tokens or credits consumed, usage volume, and request status — used for billing and token accounting, risk control, troubleshooting, and security auditing.
  • Content You Submit: the prompts, images, and other assets you send to the Service and the outputs generated in response — forwarded solely to complete your request; by default not used for any other purpose (see Section 5). At the model invocation layer we operate on a zero-data-retention basis (see Section 6).

2. How We Use Your Information

  1. To provide, maintain, and improve the Service, and to complete billing and account management;
  2. To prevent abuse, fraud, and security risks, and to fulfill legally required log-retention obligations;
  3. To send you service notifications, subject to your separate consent where required.

3. Cookies and Similar Technologies

We use necessary cookies and local storage to maintain your login session and preferences. You can manage these through your browser settings, but disabling them may affect certain features of the Service.

4. Sharing and Entrusted Processing

  • Upstream model providers: to complete requests you initiate — whether through the platform interface or the API — we forward your submitted content to the upstream service provider of the model you selected or that the Service routed your request to. We contract for zero data retention with our upstream model providers, meaning they process your content only for as long as it takes to return a response and do not retain or log it afterwards. Where a provider cannot offer zero data retention, they process data in accordance with their own privacy policies and we identify them in our subprocessor list.
  • Payment providers: we provide the order information necessary to complete transactions to third-party payment processors.

Except in the circumstances above, with your consent, or as otherwise required by law, we do not sell or share your personal information with any third party.

5. Service Improvement and Model Training (Important)

  • By default, we do not use the content of your requests for model training.
  • Only with your separate, explicit consent (opt-in) may we use de-identified and desensitized conversation data to improve the Service. You may withdraw your consent (opt-out) at any time in your settings; withdrawal does not affect processing already carried out before withdrawal.
  • Before any such data is stored, we desensitize personal information such as phone numbers, email addresses, ID numbers, bank card numbers, API keys, names, and addresses. Data retained under this opt-in is held as operational data in Singapore; it does not change the zero-data-retention posture of the model layer described in Section 6.

6. Data Retention and Storage Location (Important)

We treat the model layer and our operational systems differently, and the distinction matters to what is kept and where.

  • Model layer — zero data retention (ZDR). The content you submit for inference, and the outputs generated from it, are held only in memory for as long as it takes to complete your request. They are not written to persistent storage at the model invocation layer, and — as described in Section 4 — our upstream model providers are contractually required not to retain or log them either.
  • Operational data — stored in Singapore. Account and registration details, billing and transaction records, API keys, usage and metering records, security logs, and any content you choose to save into your account are stored on servers located in Singapore.
  • We retain operational data only for as long as necessary to fulfill the purposes described in this Policy, unless a longer retention period is required by applicable law (for example, network logs must be kept for no less than six months in certain jurisdictions).
  • After the retention period expires, we delete or anonymize your personal information.

7. Cross-Border Data Transfers (Important)

Your operational data resides in Singapore. If you are located elsewhere, using the Service therefore involves a transfer of that data to Singapore.

Separately, when you invoke models operated by providers located outside your jurisdiction, the content of your requests will be transmitted to servers abroad for processing — under the zero-data-retention terms described in Sections 4 and 6, but outside Singapore. Please do not include sensitive personal information, or data that is restricted from cross-border transfer under applicable law, in your requests.

By using the Service, you acknowledge and consent to the cross-border transfers described above. Where applicable law imposes compliance obligations for cross-border transfers of personal information, we will fulfill them in accordance with the law.

8. Data Security

We employ technical and organizational measures to protect your information, including encryption in transit (HTTPS), encrypted password storage, access controls, and the principle of least privilege. However, please understand that no method of transmission or storage over the internet is absolutely secure.

9. Your Rights

Subject to applicable data protection laws, you have the following rights regarding your personal information:

  • To access, copy, and port your personal information;
  • To correct or supplement inaccurate information;
  • To delete your information and deactivate your account;
  • To withdraw consent you have previously given;
  • To obtain an explanation of our personal information processing practices.

You may exercise these rights by contacting us as described in Section 12, and we will respond within the time limits required by law.

10. Children's Privacy

The Service is intended for adults. We do not provide services to children under the age of 14. If we discover that we have collected a child's information without verified guardian consent, we will delete it promptly.

11. Changes to This Policy

We may update this Policy from time to time. For material changes, we will notify you through platform announcements or other appropriate means. Your continued use of the Service constitutes acceptance of the updated Policy.

12. Contact Us

If you have any questions, comments, or complaints about this Policy, or wish to exercise your personal information rights, please contact us at contact@shineon.dev.

Please also review our Terms of Service, which govern your use of the Service.