/ LEGAL

Privacy Policy

Last updated: 6 August 2026

The short version. Your account, your files, and your projects are stored and processed on European infrastructure. We do not sell your data, and we do not train models on your content. The one place your data leaves our infrastructure is model inference: when you run an AI model, your prompt is sent to that model's provider, and most providers operate outside the EU. Section 4 sets out exactly what that means.

1. Who we are

ki-skape is operated by KeySkape Solutions LLC ("we", "us"). We are the data controller for the personal data described in this policy.

For any privacy question or to exercise your rights, contact info@keyskapesolutions.com.

2. What we collect

CategoryWhat it includesWhy we process it
Account data Email address, authentication identifiers, email verification status, plan, account preferences. To create and secure your account, and to provide the service. Legal basis: performance of a contract.
Content you provide Files you upload, prompts you write, chat history, projects, and the outputs generated for you. To deliver the feature you asked for and to store your work in your library. Legal basis: performance of a contract.
Usage and billing Credit balance, credit transactions, storage consumed, and a history of which services you used. To meter usage, bill accurately, and show you your own spending. Legal basis: performance of a contract and legal obligation.
Payment data Handled by our payment processor. We receive a customer identifier and subscription status — we never receive or store your card details. To take payment and manage subscriptions. Legal basis: performance of a contract.
Technical data IP address, browser and device information, and product analytics events. To keep the service secure, diagnose faults, and understand how the product is used. Legal basis: legitimate interests.
Waitlist data If you join the waitlist: your email address only. To contact you when access opens. Legal basis: consent, which you can withdraw at any time.

3. Where your data lives

Our own infrastructure is located in the European Union. Specifically:

4. AI model providers, and the limit of EU residency

This is the part we want to be precise about, because it is the one exception to everything above.

When you run an AI model — a chat message, an image, a video, a voiceover, a transcription — the input you supply is transmitted to the third-party provider that operates that model, so that it can generate a result. Most of these providers operate outside the European Union, including in the United States. Their processing of that input is governed by their own terms and privacy commitments.

In short: everything we host, we host in Europe. Model inference is the part we do not host, and we are not going to describe this product as end-to-end EU processing when it is not.

Personal data transferred outside the EU or EEA is processed by each provider under its own terms and privacy commitments. We are not currently in a position to state that formal transfer safeguards under Chapter V of the GDPR are in place with every one of them, and we would rather say so than imply otherwise.

The third parties that may receive your data are: Amazon Web Services (file storage and email, in the EU), Google Firebase (accounts and database, in the EU), Stripe (payments), OpenAI, Anthropic, OpenRouter, Runway and ElevenLabs (AI model processing), and Daytona (Builder sandbox previews). OpenRouter routes requests onward to further model providers, which vary by the model you choose.

If you do not want particular content sent to a model provider, do not submit it to a generative feature. Storage, file conversion, and browser-side export do not involve these providers at all.

5. What we do not do

6. How long we keep it

When you delete a file, it is removed from your library and from our object storage, and your storage allowance is adjusted accordingly.

7. Your rights under the GDPR

If you are in the EU or EEA, you have the right to:

To exercise any of these, email info@keyskapesolutions.com. We will respond within one month, as required by Article 12(3). You also have the right to lodge a complaint with your national supervisory authority.

8. Security

9. Cookies and analytics

This marketing site sets no analytics or advertising identifiers. It uses no tracking cookies, runs no third-party ad trackers, and does not profile visitors. That is why you have not been asked to accept cookies here.

Inside the signed-in application we use cookies and equivalent browser storage that are strictly necessary to keep you authenticated and to operate the service. These are exempt from consent under the ePrivacy Directive because without them the service cannot function. If we later introduce non-essential analytics, we will ask for your consent first and you will be able to decline.

10. Age and children

ki-skape is an 18+ service. It is not directed at children, and we do not knowingly collect their personal data.

If you believe someone under 18 has given us personal data, contact info@keyskapesolutions.com and we will delete the account and its data.

11. Changes to this policy

If we make a material change, we will update the date at the top of this page and, where the change significantly affects you, notify you by email.

12. Contact

For privacy questions, data protection matters, and to exercise any of the rights in section 7, contact info@keyskapesolutions.com.

Postal address and the identity of our EU representative, where one is required, are available on request at the same address.