Skip to content

Legal

Privacy Policy

Revision of July 3, 2026.

This English text is a convenience translation. In case of any discrepancy, the Russian version of the Policy prevails.

1. General provisions

1.1. This Privacy Policy (the “Policy”) defines the principles of handling user information of the Kumo AI model access service (the “Service”, “Kumo”) and is drafted in accordance with Federal Law No. 152-FZ “On Personal Data” of 27.07.2006 and the applicable laws of the Russian Federation.

1.2. This document governs the relationship between the Service and individuals (the “User”) interacting with the Service through the official website https://openkumo.cloud (the “Website”) and the Service’s application programming interface (the “API”).

1.3. Before using the Service, the User undertakes to carefully review this Policy and the terms of technical information processing.

1.4. The fact of starting to use the Service confirms the User’s full and unconditional acceptance of all terms of this Policy.

1.5. If the User objects to any provision of this Policy, the User must immediately stop interacting with the Service.

1.6. The Service does not collect or process personal data such as first name, last name, postal address, passport details, or other information directly identifying a person. Processing is limited to the email address used as the account identifier and the technical identifiers of the account and API keys required for the performance of the contract under Art. 6(5) of Federal Law No. 152-FZ.

2. Definitions

2.1. Personal data — information relating directly or indirectly to an identified or identifiable individual.

2.2. Personal data processing — any set of operations performed on personal data with or without automated means, including accumulation, systematization, storage, modification, use, distribution, anonymization, blocking, and destruction.

2.3. Automated processing — processing of data by means of computing equipment and software.

2.4. Website — the Service’s official web resource at https://openkumo.cloud providing access to the Service, including account registration, the user dashboard, and API key management.

2.5. API — the Service’s application programming interface through which the User sends requests to AI models using individual API keys.

2.6. User — a legally capable individual using the Service to access AI models in accordance with the applicable laws of the Russian Federation.

2.7. Technical identifiers — the set of technical data automatically transmitted or generated when using the Service: account identifier, API key identifiers, IP address, client software details (User-Agent), request metadata (date and time, selected model, number of processed tokens). Together with account credentials, they are used to link API keys to the User’s balance.

3. Principles of personal data processing

3.1. The Service does not collect or process personal data such as first name, last name, postal address, passport details, or other information directly identifying a person. Processing is limited to the email address and the technical identifiers of the account and API keys required for the performance of the contract under Art. 6(5) of Federal Law No. 152-FZ.

3.2. The technical parameters accessible to the Service are:

  • the email address provided by the User at registration — used solely as a unique account identifier and a channel for system notifications;
  • technical identifiers of the User’s API keys — generated automatically when keys are created in the dashboard;
  • API request metadata: date and time of the request, selected model, number of processed tokens — for billing and technical monitoring of account activity;
  • IP address and client software details (User-Agent) — for security and abuse prevention.

3.3. The content of the User’s requests to AI models (prompts) and the models’ responses is not stored by the Service after the request has been processed, is not used for model training, and is not shared with third parties, except for transmission to the provider of the selected model to the minimum extent necessary to fulfill the User’s request.

3.4. The Service does not request, collect, or store the following categories of information: last name, first name, patronymic, phone numbers, residential or registration addresses, passport details, income information, or other personal details of Users.

3.5. Users’ payment information and bank card details never reach the Service. Financial transactions are processed by certified payment systems compliant with PCI DSS security standards.

4. Purposes of data processing

4.1. Technical identifiers are used by the Service exclusively for:

  • automatic authorization of the User in the system;
  • generation and provision of unique API keys for access to AI models;
  • sending system notifications about balance status, account status, and changes to the terms of service;
  • technical identification of the User when topping up the balance or purchasing token packages;
  • operation of the referral (partner) program and crediting of bonus funds;
  • operation of the technical support service;
  • linking API keys to the account: identification and accounting of keys created within one account, including spending-limit control and per-key access management;
  • collection of anonymized usage statistics to improve the quality of the Service.

5. Processing and storage terms

5.1. Technical identifiers are stored in the Service’s technical database solely to support the authorization system and automatic management of Users’ access to AI models. Technical identifiers are stored for the lifetime of the account and are deleted no later than 30 (thirty) calendar days after the termination of the contractual relationship or upon the User’s request.

5.2. Kumo guarantees that technical identifiers are not transferred, sold, or disclosed to third parties, except in cases expressly provided for by the applicable laws of the Russian Federation.

5.3. Upon ceasing to use the Service, the User may request the deletion of their data from the technical database.

5.4. The Service applies a set of organizational and technical measures to protect stored information from unauthorized access, modification, or destruction.

6. Security

6.1. Kumo implements a set of legal, organizational, and technical measures to protect technical information from unlawful or accidental access, modification, blocking, copying, destruction, or distribution.

6.2. Security measures include, without limitation: database encryption, access control to server equipment, regular security audits of information systems, and data backups.

6.3. Access to the Service’s technical databases is granted exclusively to authorized personnel to the extent necessary to perform their duties.

7. Data subject rights

7.1. The User has the right to receive complete information about the processing of their technical data, except in cases established by federal law. The Service provides the requested information in an accessible and clear form.

7.2. The User may request that the Service clarify, block, or delete technical information if it is found to be outdated, incomplete, inaccurate, unlawfully obtained, or no longer necessary for the stated purposes of processing.

7.3. If violations of the law are identified, the User has the right to demand that the Service stop processing technical information.

7.4. The User may at any time demand the termination of processing, blocking, and deletion of technical information related to them, at their own discretion and without stating reasons.

7.5. To exercise these rights, the User submits a request via the feedback form on the Service’s official Website or to the support email address listed in the Contacts section of the Website.

8. Data sharing with third parties

8.1. The Service shares technical information with third parties only in the following cases:

  • the User’s written consent to such actions;
  • the transfer is necessary to provide the User with the requested services or to perform the concluded agreement;
  • a lawful request from authorized state bodies submitted in accordance with the procedure established by Russian law.

8.2. Kumo does not transfer, sell, or provide technical information for commercial purposes without the User’s consent.

9. Data retention

9.1. Users’ technical information is processed and stored for the period necessary to achieve the processing purposes set out in this Policy, or for the period established by applicable law, or for the duration of the contractual relationship between the Service and the User.

9.2. Upon expiry of these periods or upon the User’s request, technical information is deleted or anonymized.

9.3. The Service reserves the right to retain anonymized statistical information for analysis and improvement of the quality of the services provided.

10. Changes to the Policy

10.1. Kumo has the right to amend and supplement this Policy unilaterally, including but not limited to cases of changes in applicable law or modifications to the functionality or technology of the Service.

10.2. When the document is amended, the revision date is updated. The updated version of the Policy takes legal effect upon its publication on the Service’s official Website, unless a different effective date is specified directly in the new version.

10.3. The User is responsible for independently monitoring the current version of this Policy by periodically reviewing its contents.

10.4. Continued use of the Service after the publication of an updated version of the Policy constitutes the User’s full and unconditional acceptance of the changes.