ZilAPI (zilapi.com) is run by Inverse.AI LLC ("we", "us"). This policy explains what we collect, why, who helps us process it, and how long we keep it.
1. What we collect
Account details
- Your email address and name.
- If you sign in with Google or GitHub: the basic profile those services share (email, name, account ID). [TO CONFIRM: TC-24 the exact fields we store.]
- A fingerprint (hash) of each API key, not the key itself, so we cannot read your keys back.
Billing details
- Your purchases, credit balance and usage.
- Card payments are handled by Stripe. We do not see or store your full card number.
- Your billing country and address, as needed for tax.
Your files
- The audio you upload, and the results we produce.
Server logs
When you use the website or the API, our servers record technical data: IP address, date and time, the request path and its result status, your user ID, the amount of data sent, browser and operating system, and the referring page. Logs do not contain your audio. We use this to keep the service secure, give support and improve the service. [TO CONFIRM: TC-15 how long logs are kept, and that this list matches what ZilAPI actually logs.]
2. How we use your files
- We use your files to run the jobs you ask for.
- Data in transit is encrypted with TLS.
- Retention: uploads are deleted 3 days after we validate them. Results are deleted 7 days after the job succeeds.
3. Using your audio to improve our models
We may use the audio you send us to train and improve our models.
- This applies only to jobs created after you accept the version of the Terms of Service that allows it (this draft is version 2026-10-draft; the final version number is set at publication). Earlier jobs are not used.
- We record this on your account and on each job.
- Copies we keep for training are kept separately from your job files. They are not subject to the 3-day and 7-day deletion periods above.
- [TO CONFIRM: TC-11 whether you can opt out, how, how long training copies are kept, and what opting out or closing your account means for copies and models already trained.]
- Only send audio of other people if you have their permission, or another lawful basis, for this use. [TO CONFIRM: TC-20]
4. Who processes your data (sub-processors)
We use these companies to run ZilAPI:
| Company | What they do for us |
|---|---|
| Cloudflare | DNS, network protection and content delivery (CDN); file storage (R2) for uploads and results |
| DigitalOcean | Our servers and database |
| RunPod | GPU processing of your audio |
| Stripe | Payments, invoices and tax (Stripe Tax) |
| Netlify | Hosting the zilapi.com website |
| Optional "Sign in with Google" | |
| GitHub | Optional "Sign in with GitHub" |
| Email provider [TO CONFIRM: TC-3 which email service sends sign-up and receipt emails] | Sending account and receipt emails |
We do not sell your data. [TO CONFIRM: TC-22 Mijan to confirm this commitment.] We share log data with authorities only if the law requires it (Noise Reducer's wording; [TO CONFIRM: TC-24]).
5. Where your data is stored
[TO CONFIRM: TC-9 the countries or regions where data is stored and processed, the legal basis for international transfers, our role and each provider's role (controller or processor), and the data processing agreements in place.]
6. How long we keep other data
| Data | How long |
|---|---|
| Uploads | 3 days after we validate them |
| Results | 7 days after the job succeeds |
| Training copies | [TO CONFIRM: TC-11] |
| Account details | While your account is open [TO CONFIRM: TC-10 how long after closing] |
| Billing records | [TO CONFIRM: TC-10 as long as tax law requires] |
| Server logs | [TO CONFIRM: TC-15] |
7. Cookies
We use cookies to keep you signed in and to make the website work. You can manage cookies in your browser settings. [TO CONFIRM: TC-12 the cookies zilapi.com actually sets, including any analytics or marketing cookies.]
8. Security
We protect your data with encryption in transit (TLS) and access controls. [TO CONFIRM: TC-24 the security measures we describe here.] No system is perfectly secure; if we learn of a breach that affects you, we will tell you as the law requires.
9. Your rights
You can ask us to see, correct, export or delete your personal data by emailing support@zilapi.com. [TO CONFIRM: TC-9 which privacy laws (for example GDPR, UK GDPR, CCPA) we must name, the lawful basis for each use (service, billing, logs, training), and the rights to object, withdraw consent and complain that each law needs.]
10. Links to other sites
Our website may link to other sites. Their own privacy policies apply there.
11. Changes to this policy
We may update this policy. Each version has a date and a version number, and we will tell you about important changes as the law requires.
Contact
Privacy questions: Inverse.AI LLC, support@zilapi.com. Company address: [TO CONFIRM: TC-1].