SKTTECH skttech.io
LEGAL · PRIVACY POLICY · EFFECTIVE 2026-08-18

Privacy Policy

SKTTECH PTE. LTD. · SINGAPORE · EFFECTIVE AUGUST 18, 2026 · LAST UPDATED AUGUST 18, 2026

This Privacy Policy explains how SKTTECH PTE. LTD. ("SKTTECH", "we", "us") collects, uses, discloses, and protects personal data when you use SKTTECH, the AI model routing gateway available at skttech.io and through the API at api.skttech.io/v1 (together, the "Platform"). It is written to satisfy the Singapore Personal Data Protection Act 2012 (the "PDPA") and drafted with the EU and UK General Data Protection Regulation (the "GDPR") in mind. The short version, which the rest of this document makes precise: we never store your prompts or completions, we never use your traffic to train models, and we log only the request metadata needed to route, bill, and keep the Platform reliable.

SEC 01 · WHO WE ARE

Who We Are

The Platform is operated by SKTTECH PTE. LTD., a company incorporated in Singapore. For the personal data described in this policy, SKTTECH is the organisation responsible for compliance under the PDPA and, where the GDPR applies, the data controller. We have designated a Data Protection Officer as required by section 11(3) of the PDPA; the DPO can be reached at privacy@skttech.io.

SKTTECH is an independent platform. We are not affiliated with, sponsored by, or endorsed by any AI model provider. Model and provider names appearing on the Platform are trademarks of their respective owners and are used only to identify routing targets. Where model providers process the content of your requests, they do so as separate services under their own terms; sections 05 and 07 describe how that works.

SEC 02 · SCOPE

Scope of This Policy

This policy covers personal data handled through the skttech.io website, the account console, and the api.skttech.io API. It governs only our own collection and use of data.

It does not govern the practices of third parties, including the model providers your requests are routed to, external sites we link to, or tools and services you choose to integrate with the Platform. Each of those operates under its own privacy policy, and we encourage you to review the policies of any provider you route traffic to — particularly before sending content you consider sensitive.

If you are covered by a negotiated enterprise agreement or a Data Processing Agreement with us (section 13), the terms of that agreement control over this policy to the extent of any conflict.

SEC 03 · COLLECTION

Data We Collect

We collect personal data from three sources: directly from you, automatically when you use the Platform, and in limited cases from third parties. The categories are:

  • Account data. Your email address (required) and name (optional). Passwords are stored only as salted one-way hashes; we never hold or transmit them in plaintext.
  • Billing data. Card payments are handled by our payment processor; card details go directly to the processor and we never store full card numbers. We receive only limited confirmation data — card brand, last four digits, and payment status. Enterprise customers paying by wire transfer or invoice provide business name, billing address, and tax identifiers.
  • Usage metadata. For each API request we record the model identifier, input and output token counts, computed cost, latency, timestamps, the identifier of the API key used, and the routing outcome (including failed failover attempts, which are logged for reliability engineering and billed at $0). This metadata contains no request content.
  • BYOK key material. If you choose to bring your own provider API keys, we store them encrypted with AES-256 and use them solely to forward your requests to the corresponding provider. You can remove them at any time.
  • Support communications. Messages you send to support@skttech.io, privacy@skttech.io, or legal@skttech.io, together with the information you include in them.
  • Site and security data. Your theme preference is stored locally in your browser (localStorage) and is never transmitted to us or to anyone else. We set essential cookies only — a session cookie for console sign-in and a token that protects against request forgery. We do not use advertising cookies, third-party analytics beacons, or cross-site trackers. Our servers keep standard connection logs (IP address, user agent, request path) for security and abuse prevention.
  • Data from third parties. Payment status signals from our payment processor; fraud- and sanctions-screening results where the law requires us to check them; and, for enterprise accounts, business contact details supplied by your organisation.
SEC 04 · NON-COLLECTION

Data We Do Not Collect or Retain

Because what we refuse to keep matters as much as what we keep:

  • Prompts and completions are never stored. Zero data retention is the default for every account, not an upgrade. Request and response content passes through our systems in volatile memory only and is discarded the moment your response finishes streaming. It is never written to disk, never indexed, and never available to our staff.
  • Your traffic is never used to train models. We do not train models, and we do not make your content available to anyone else for training.
  • We never sell personal data. We have not sold personal data, we do not sell it, and we will not.
  • No interest-based advertising. We build no advertising profiles, run no ad measurement, and share nothing with ad networks or data brokers.
SEC 05 · REQUEST FLOW

How AI Requests Flow

When you call the API, your request content is received over an encrypted connection, held transiently in memory while our router selects a destination, forwarded to the selected third-party model provider, and streamed back to you. Once the response completes, the content is gone from our systems; only the usage metadata described in section 03 remains. Media inputs and outputs — images, audio, video — receive the same treatment: they exist on our infrastructure only for the duration needed to route the request and stream the result, and are never written to durable storage.

If you set the zdr:true flag on a request, the router will only consider providers whose terms we have verified to include zero-retention commitments for API traffic. Requests carrying the flag fail rather than fall back to a provider without such terms.

Model providers process the content of routed requests as independent services under their own terms and privacy policies. Their retention windows, abuse-monitoring practices, and — for some providers — training policies are set by them, not by us, and are described in their published terms. Review a provider's terms before routing content to it that you consider sensitive, or use zdr:true to restrict routing.

One responsibility sits with you: the content of your requests may itself contain personal data, and for that content you act as the party responsible under applicable data protection law. Before submitting personal data about anyone other than yourself, ensure you have a lawful basis to do so. This matters most for content that could qualify as biometric or otherwise sensitive data — a recognisable face in an image, a voice in an audio clip — where many jurisdictions require explicit consent from the person concerned before processing.

SEC 06 · PURPOSES & LEGAL BASES

Purposes and Legal Bases

We process personal data for the following purposes, on the following bases:

  • Operating the Platform — creating and administering accounts, routing requests, metering usage, calculating your bill from the AI inference your requests use together with the platform services provided, and responding to support requests. Basis: performance of our contract with you; under the PDPA, your consent or deemed consent by contractual necessity.
  • Security and integrity — detecting fraud and abuse, protecting API keys and accounts, enforcing our Terms of Service. Basis: our legitimate interests in keeping the Platform safe, and legal obligations where screening is mandated.
  • Service communications — receipts, low-balance and security notices, and material changes to terms or this policy. Basis: contract performance and legitimate interests. These are not marketing and cannot be opted out of while your account is open.
  • Platform improvement — analysing aggregated, de-identified usage metadata (routing statistics, latency percentiles, error rates) to improve routing quality and reliability. Basis: legitimate interests, and the PDPA business improvement exception. This analysis never involves request content, and the aggregates cannot be traced back to an individual.
  • Legal compliance — tax, accounting, and record-keeping duties under Singapore law and other laws that apply to us. Basis: legal obligation.
  • Marketing, if you opt in — occasional product announcements. Basis: consent, which you can withdraw at any time; every message includes a working unsubscribe link.

Where the GDPR applies, the bases above correspond to Article 6(1)(b) (contract), 6(1)(f) (legitimate interests), 6(1)(c) (legal obligation), and 6(1)(a) (consent) respectively.

SEC 07 · DISCLOSURE

Sharing and Disclosure

We disclose personal data only to the recipients below, and only to the extent each needs it:

  • Model providers. The transient content of your requests, together with the minimum technical parameters needed for inference, is passed to the provider selected for each request. Providers act as separate services under their own terms, as described in section 05.
  • Infrastructure providers. The cloud vendors that host the Platform process data on our behalf under contracts imposing confidentiality and data protection obligations.
  • Payment processor. Card data flows directly to the processor; we exchange only the confirmation data described in section 03.
  • Professional advisers. Lawyers, accountants, and auditors, bound by confidentiality, where their advice requires it.
  • Authorities. Where disclosure is required by law, regulation, court order, or binding government demand, or is necessary to protect the rights, property, or safety of SKTTECH, our customers, or the public. We review every demand and disclose the narrowest set of data the law permits.
  • Business transactions. If SKTTECH is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. Any successor remains bound by this policy, and we will notify you before your data becomes subject to a different one.

We do not sell personal data, do not share it with data brokers or advertising networks, and do not pass it to affiliated or partner companies for their own marketing.

SEC 08 · TRANSFERS

International Data Transfers

We operate from Singapore, and our infrastructure providers and the model providers we route to are located in a range of jurisdictions. Routing a request means its content is transiently processed in whichever region hosts the model you selected; stored personal data (account data, usage metadata) may likewise be held outside your home jurisdiction.

Where we transfer personal data out of Singapore, we comply with the PDPA's transfer limitation obligation by ensuring, through contractual safeguards, that the data receives a standard of protection comparable to the PDPA. Where the GDPR or UK GDPR applies to a transfer outside the EEA or the UK, we rely on adequacy decisions where available and otherwise on standard contractual clauses adopted under Article 46 GDPR (or the UK equivalent), supplemented where appropriate by additional technical measures such as encryption in transit. Enterprise customers can obtain transfer documentation as part of the Data Processing Agreement described in section 13.

SEC 09 · RETENTION

Data Retention

We keep personal data only as long as a business purpose or legal obligation requires, then delete it or irreversibly de-identify it. The schedule:

CategoryRetentionNotes
Prompts & completionsNot retainedTransient, in-memory processing only — the default for every account.
Media inputs / outputsNot retainedHeld only for the duration of routing and streaming.
Usage metadata12 monthsThen deleted or reduced to aggregates that identify no one.
Account dataLife of account + 30 daysThe trailing period covers backup rotation after deletion.
Billing recordsUp to 7 yearsAs required by Singapore tax and accounting law.
BYOK keysUntil you remove themDeleted promptly on your instruction or at account closure.
Support threads24 monthsMeasured from resolution of the matter.
Server security logs90 daysIP-level connection logs kept for abuse investigation.

Model providers maintain their own retention schedules for content they process; the zdr:true flag restricts routing to providers with verified zero-retention terms. You may ask us to delete retained personal data earlier by writing to privacy@skttech.io; we will honour the request except where the law requires us to keep specific records.

SEC 10 · SECURITY

Security

We protect personal data with technical and organisational measures proportionate to its sensitivity: TLS encryption for all data in transit; AES-256 encryption at rest for stored data, including BYOK keys; credentials held only as salted hashes; role-based access controls on the principle of least privilege; audit logging of administrative access; and segregation between production and non-production environments. Because request content is never written to storage, the most sensitive data you send us is protected by not existing on our systems at all.

Some of the perimeter belongs to you: keep your password and API keys confidential, rotate keys you suspect are exposed, and tell support@skttech.io immediately if you believe your account has been compromised.

No transmission over the internet and no storage system can be guaranteed absolutely secure, and we do not promise the impossible. If a data breach occurs that meets the notification thresholds of the PDPA or the GDPR, we will notify the affected individuals and the relevant regulator within the timelines those laws require.

SEC 11 · YOUR RIGHTS

Your Rights and Choices

Under the PDPA you may request access to the personal data we hold about you and how it has been used or disclosed in the past year, request correction of errors or omissions, and withdraw consent to processing (which may limit or end our ability to provide the Platform to you). Where the GDPR applies, you additionally have the rights to erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. We do not make automated decisions about you that produce legal or similarly significant effects — routing decisions are technical selections among model providers, not evaluations of you.

Much of this is self-service: in the console you can view and update your account information, manage and revoke API keys, remove BYOK keys, review your usage metadata, and close your account. Account deletion is irreversible — once processed, your account data is deleted on the schedule in section 09 and cannot be restored, and unused prepaid credits are handled as described in the Terms of Service.

To exercise a right that is not self-service, write to privacy@skttech.io. We will verify your identity before acting, and respond within the timelines of applicable law — as soon as reasonably possible under the PDPA, and within one month (extendable for complex requests) under the GDPR. If you opted into marketing, every message carries an unsubscribe link, and withdrawal takes effect promptly.

If you believe we have handled your personal data improperly and we have not resolved your concern, you may complain to the Personal Data Protection Commission of Singapore (PDPC). If you are in the EEA or the UK, you may also complain to your local supervisory authority.

SEC 12 · ELIGIBILITY

Children and Eligibility

The Platform is a developer infrastructure service for adults with the capacity to contract. It is offered only to persons aged 18 or older, is not directed at children, and we do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has created an account, tell us at privacy@skttech.io and we will delete the account and its data.

SEC 13 · ENTERPRISE DPA

Enterprise Data Processing Agreement

Customers who need contractual processor commitments can enter into our Data Processing Agreement. The DPA sets out our obligations as a processor of the personal data contained in your traffic and account, incorporates standard contractual clauses for international transfers, lists our sub-processors with a mechanism for notice of changes, and includes audit and breach notification terms. To request the DPA, contact legal@skttech.io.

SEC 14 · GOVERNING LAW

Governing Law

This policy, and any dispute about our handling of personal data, is governed by the laws of Singapore, and disputes are resolved as set out in the Terms of Service, by arbitration in Singapore under the SIAC rules. Nothing in this section deprives you of protections that mandatorily apply under the data protection law of your own jurisdiction, or of your right to complain to a supervisory authority as described in section 11.

SEC 15 · CHANGES

Changes to This Policy

We may revise this policy as the Platform, the law, or our practices change. The effective date at the top of the page always reflects the current version. For material changes — anything that expands what we collect, how long we keep it, or who we share it with — we will notify you by email or a prominent console notice at least 14 days before the change takes effect. Continued use of the Platform after a change takes effect constitutes acceptance; if you do not accept a change, close your account before it takes effect. Prior versions are available on request from privacy@skttech.io.

SEC 16 · CONTACT

Contact

Questions, requests, and complaints about personal data: privacy@skttech.io (Data Protection Officer). Legal notices: legal@skttech.io. General support: support@skttech.io. Postal correspondence may be addressed to SKTTECH PTE. LTD., Singapore; write to legal@skttech.io for the current registered address.