Privacy policy

Effective: August 2025.

1. Scope

This policy covers personal data processed by Merki Inference Pte. Ltd. when you use the service, including the dashboard, API, and verification flows.

2. Who we are

Merki Inference Pte. Ltd. Level 42-01, Capital Horizon Tower 8 Marina Boulevard, Singapore 018981

Established August 4, 2025. Data protection contact: dpd@merki.dev. General privacy contact: privacy@merki.dev.

3. Data we collect

  • Account data. Name, email, credentials, and account settings.
  • Billing data. Credit balances, purchase records, and payment references. Payments are processed by our payment processor, identified at checkout. Merki does not store full card numbers.
  • Verification data. The result of the Sumsub check, and the minimum reference that ties it to your account, for the age-assured and identity-verified tiers. Documents are handled by Sumsub; Merki does not receive copies of your documents.
  • Operational data. Logs and metrics for reliability and abuse prevention (90 days; security logs 1 year).

4. What we do not retain

Prompt and completion content is not retained, except for cache entries (24 hours, scoped to your account). See Zero data retention and the retention matrix.

5. How we use data

To provide the service, bill correctly, keep tiers lawful, prevent abuse, and meet legal duties. Legal bases include contract, legitimate interests (security, reliability), and legal obligation (age assurance and identity records).

6. Sharing

Merki does not sell personal data. Merki does not route inference to third-party inference providers. Prompts and completions are never sent to anyone else. Verification is processed by Sumsub as our processor for that purpose only. See Subprocessors. On BYOK routes, requests go to the provider you selected under your own agreement with them.

7. Age and identity verification

Age assurance for Roleplay and identity verification for Cybersecurity are run by Sumsub. Merki receives the result, not copies of your documents. Records are kept for account lifetime plus 5 years, as required to keep these tiers lawful. See Age and identity.

8. Cookies

See the Cookie policy. No third-party cookies.

9. Retention

Retention windows are listed in the retention matrix: cache 24h, logs 90 days (security 1 year), verification records account lifetime plus 5 years, account and billing records for account lifetime then statutory periods.

10. Your rights

Under Singapore's PDPA and similar laws, you may request access, correction, and deletion of your personal data, subject to legal limits (including verification records we must keep). Contact privacy@merki.dev. We respond within 30 days.

11. Security

We apply access controls and encryption in transit and at rest, per-account cache isolation, and automatic revocation of exposed credentials. See API keys. Report vulnerabilities to security@merki.dev. See Security.

12. International transfers

Where data is transferred across borders (including to Sumsub for verification), we use appropriate safeguards: contractual clauses, necessity for the service, and minimization to the check result. Details on request to dpd@merki.dev.

13. Changes

We will announce material changes at least 30 days before they take effect, on the changelog and by email.

14. Contact

Privacy contact: privacy@merki.dev. Data protection: dpd@merki.dev.