SOKKAN Router · Legal
Privacy Policy
Draft — version 2026-10-04. Not yet approved for production. Passages marked “To be validated” are open decisions.
This policy explains how NINABOT handles personal data for the SOKKAN Router inference API and its account pages. It meets the Swiss Federal Act on Data Protection (FADP) and, for people in the European Union or the EEA, the General Data Protection Regulation (GDPR, art. 13).
1. Controller
NINABOT Sàrl, Chemin de Riantbosson 19, 1217 Meyrin (GE), Switzerland, company number CHE-287.575.522 — [email protected] (subject “Data protection”). We answer within the legal deadlines, as a rule within 30 days.
2. Scope
NINABOT is controller for the data needed to run your account: sign-in, API keys, credit, payments and usage records. For the content of API requests (prompts and completions), the customer is controller and NINABOT acts as processor under the Data Processing Agreement, which also lists where requests are processed. In short: request content is never stored by NINABOT.
3. Data we process
- Sign-in. Your e-mail address, and a single-use sign-in link valid 15 minutes, stored only as a hash. To limit abuse, sign-in requests are counted per IP address and per e-mail address for one hour, in memory only.
- Account. An account identifier, your e-mail address, the dates of creation and first sign-in, and the version and date of the Terms and DPA you accepted.
- API keys. For each key: its name, its first 12 characters (to help you recognise it), a hash of the full key, and the dates of creation, last use and revocation. The full key is shown to you once and never stored.
- Credit and payments. Your balance and a ledger of credits and debits. Payments are made on Stripe's payment page: we never see or store your card number. Stripe gives us a customer identifier, the payment session identifier, the amount, the currency and the payment status. If you enter a business name or tax identifier at checkout, Stripe collects it and makes it available to us.
- Saved card and automatic top-up. If you save a card for automatic top-ups, the card stays with Stripe. We keep only what Stripe shows us about it: the Stripe identifiers of the card and of you as a Stripe customer, the card brand, its last four digits, its expiry month and year, and a card fingerprint computed by Stripe (it lets us apply top-up limits per card without knowing the card number). With it we keep your automatic top-up settings (threshold, amount, monthly limit) and the version and date of the Terms you accepted when you turned it on.
- Identity verification (optional). To raise your top-up limits you can verify your identity with Stripe Identity: you photograph an identity document and take a selfie on a page run by Stripe. Stripe checks them and tells us the result. We keep only the Stripe verification identifier, its status (for example “verified”), its date, your verified first and last name and the country that issued the document. We do not receive or keep the images, the document number, your date of birth or your address. Stripe keeps the verification data for its own retention period, under its own privacy policy.
- Usage records. Per request: identifiers of the request, account and key, time, model, provider and country that served it, token counts, cost, status and latency. No request content (see the DPA, section 3).
- Sessions. For each browser where you are signed in: a session identifier (stored only as a hash), the dates of sign-in, last activity and expiry, the browser's user-agent string, and a keyed hash of its IP address (not the address itself). The account's Security page lists them so you can recognise and end them.
- Support tickets. When you open a ticket from your account: its number, category, subject, message, the optional request id you give, its status and dates. The ticket is stored in our database and sent by e-mail to our support team, who answer you by e-mail; that correspondence stays in our mailbox.
- Technical data. Our network provider Cloudflare receives the IP address and technical data of every connection in order to deliver and protect the service. Our application does not keep HTTP access logs.
4. Purposes and legal bases
- Opening and running your account, providing the API, charging usage and processing payments — performance of the contract (GDPR art. 6(1)(b)).
- Keeping accounting records — legal obligation (art. 6(1)(c)).
- Preventing abuse and fraud, securing the service, including top-up limits per account and per card — legitimate interest (art. 6(1)(f)).
- Identity verification to raise your top-up limits — your request, as a step before a contract (art. 6(1)(b)); the selfie comparison is biometric processing that Stripe carries out on the basis of your explicit consent, which Stripe collects on its page (art. 9(2)(a)). You can use the service without it, within the standard limits.
Under Swiss law these activities follow the principles of art. 6 FADP; none requires your consent. We do not sell your data, do not use it for advertising and do not profile you.
5. Recipients
| Provider | Function | Location |
|---|---|---|
| Akenes SA (Exoscale) | Hosting of the platform, its database and our own mail server (sign-in and support e-mails) | Geneva, Switzerland |
| Cloudflare, Inc. | DNS, TLS, network protection | United States, global network |
| Stripe Payments Europe, Limited (with Stripe, Inc.) | Payments. Stripe also processes some data for its own obligations (fraud prevention, legal duties) under its own privacy policy | Ireland; United States |
| Stripe, Inc. (Stripe Identity), with Stripe Payments Europe, Limited | Identity verification, only if you ask to raise your limits: document and selfie check. Stripe also acts under its own privacy policy for this service | United States; Ireland |
| Tailscale Inc. | Private network between our servers (connection metadata only) | Canada |
Model providers receive the content of the requests routed to them, not your account data; they are listed in the DPA. We may also disclose data to an authority where the law requires it.
6. Transfers outside Switzerland and the EEA
Our platform is hosted in Switzerland, which benefits from an adequacy decision of the European Commission. Cloudflare and Stripe may process data in the United States: Cloudflare and Stripe, Inc. are certified under the EU–US and Swiss–US Data Privacy Framework. E-mails are sent from our own mail server in Geneva.
7. Retention
- Account, API keys, sign-in records, sessions and support tickets: as long as the account exists.
- Saved card details and automatic top-up settings: until you remove the card or turn the feature off; the version of the Terms accepted for automatic top-ups stays with the payment records.
- Identity verification result (status, date, name, document country): as long as the account exists.
- Ledger, payment and usage records: 10 years, as Swiss law requires for accounting records (Code of Obligations, art. 958f), including after the account is closed.
- Request content: never stored.
To be validated: account closure and deletion are handled by e-mail request; there is no self-service deletion and no automatic purge of expired sign-in links yet.
8. Cookies
We set two cookies, both strictly necessary. skr_session keeps you signed in: signed, httpOnly,
secure, SameSite=Lax, valid 30 days. skr_pre protects the sign-in forms against cross-site request forgery:
a random value, httpOnly, secure, SameSite=Lax, valid one hour. Your choice of dark or light theme is kept in your
browser's local storage, never sent to us. We use no analytics or advertising
cookies. Stripe's payment page sets its own cookies under Stripe's policy; Cloudflare may set strictly necessary
security cookies.
9. Your rights
You may request access to your data, its rectification or erasure, the restriction of a processing, a copy in a common machine-readable format, and object to a processing based on our legitimate interest. Write to [email protected]; we may ask you to confirm your identity. Records that the law requires us to keep are deleted at the end of their retention period.
You may also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC, Bern, edoeb.admin.ch) and, if you live in the EU or the EEA, the data protection authority of your country of residence, place of work or place of the alleged infringement.
Providing your e-mail address is necessary to open an account; without it we cannot provide the service.
10. Security
All exchanges are encrypted in transit. API keys and sign-in links are stored only as hashes. Access to servers and databases is limited to the people who operate them. In case of a data breach likely to result in a high risk for you, we inform you and report it to the FDPIC and, where applicable, to the competent EU authority, within the legal deadlines.
11. Changes
Any change is published on this page with a new version date. Material changes are announced by e-mail as set out in the Terms of Service.