SSOTA

Privacy Policy

Last updated: June 21, 2026

This Privacy Policy explains how XY Space Inc ("XY Space", "we", "us"), a company based in Ontario, Canada, handles information in connection with Sota, our managed inference service (the "Service"). It should be read together with our Terms of Service.

1. Information we collect

  • Account information. The email address you use to sign in. We do not use passwords; sign-in is by one-time code sent to your email.
  • Billing information. If you subscribe to a paid plan, payments are processed by Stripe. We receive a customer identifier and subscription status from Stripe; we do not store your full card details.
  • API inputs and outputs. The prompts, code, and other content you send to the Service, and the model output returned to you, are processed to fulfil your request.
  • Technical information. Limited operational data such as your IP address, request timestamps, model selected, and token usage, used for security, rate limiting, and billing.

2. How we use information

We use the information above to:

  • provide, operate, and secure the Service;
  • authenticate you and maintain your session;
  • meter usage, enforce plan limits, and process billing through Stripe;
  • detect, prevent, and investigate abuse or technical problems;
  • comply with legal obligations.

We do not sell your personal information, and we do not use your prompts, code, or outputs to train machine-learning models.

3. Where inference runs

Requests you send to the Service are processed on Cloudflare's network, with inference running in Cloudflare locations across the United States, the United Kingdom, Germany, Japan, and Australia. Although the underlying models (such as GLM-5.2 and Kimi K2.7 Code) were developed by companies based in China, your requests are not forwarded to those companies' native APIs or infrastructure. The model weights are run on Cloudflare's infrastructure on our behalf.

4. Handling of your prompts and code

The content you send to the Service is processed to generate a response and is retained only as long as needed to operate the Service, support you, and meet security and legal requirements. We apply access controls so that this content is available only to systems and personnel that need it to run the Service. We do not use it to train models.

5. Cookies

We use a small number of strictly necessary cookies to keep you signed in and to secure your session. We do not use advertising cookies. Blocking necessary cookies will prevent you from signing in.

6. Service providers

We share information with a limited set of processors that help us run the Service:

  • Cloudflare — hosting, networking, and model inference;
  • Stripe — payment processing and subscription management;
  • Our email provider — delivery of one-time sign-in codes.

These providers process information on our behalf under their own terms and security commitments.

7. Data retention

We keep account and billing records for as long as your account is active and for a reasonable period afterward to meet legal, accounting, and security needs. Operational logs are kept for a limited period. You can request deletion of your account as described below.

8. Security

We use technical and organizational measures appropriate to the risk, including encryption in transit, access controls, and short-lived credentials. No system is perfectly secure, so we cannot guarantee absolute security.

9. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at the address below. We will respond as required by applicable law.

10. International users

The Service operates across multiple regions on Cloudflare's network. By using the Service, you understand that your information may be processed in the locations listed in section 3.

11. Children

The Service is not directed to children, and you must be at least 18 years old, or the age of majority in your jurisdiction, to use it. We do not knowingly collect information from children.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, for material changes, take reasonable steps to notify you.

13. Contact

For privacy questions or to exercise your rights, contact us at privacy@xyspace.dev.