HomePricingHelp
Open Exypnos

Privacy Policy

Effective March 15, 2026Version 2026-03-15.5
Language
  • English
  • Español
  • 日本語
  • Filipino
  • 简体中文

Exypnos One ("Exypnos," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, who we share it with, where it is stored, how it is protected, and what rights and choices you have when you use the Exypnos platform and all related services (the "Service"). This Privacy Policy is version 2026-03-15.5, effective as of March 15, 2026. By using the Service, you acknowledge that you have read and understood this Privacy Policy.

1.Scope and Controller

Exypnos One is the entity responsible for the processing of personal data described in this policy. For users in Singapore, we are an "organisation" subject to the Personal Data Protection Act 2012 (PDPA); for users in other jurisdictions, we act as the "data controller" or equivalent under applicable law. Our business address is: Exypnos One, Level 39, Marina Bay Financial Centre Tower Two, 10 Marina Boulevard, Singapore 018983.

We have appointed a Data Protection Officer (DPO) responsible for overseeing our compliance with applicable data protection law. You may contact our DPO regarding this policy or our handling of your personal data at [email protected].

Our primary operating jurisdiction is Republic of Singapore, and our processing activities are subject to the laws of this jurisdiction (including the PDPA), as well as applicable data protection laws in the jurisdictions where our users are located.

This Privacy Policy applies to registered users of the Service and visitors to our website. It covers data collected through the Service, our website, email communications, and any other interactions you have with us.

This Privacy Policy does not apply to third-party websites, services, or applications that may be linked to or integrated with the Service. We encourage you to review the privacy policies of any third-party services you access.

2.Data We Collect

We collect the following categories of data when you use the Service:

  • Account and profile data: user ID, username, display name, email address (if provided), avatar/profile picture, account creation date, and authentication credentials.
  • User-generated content: chat inputs, messages, prompts, model outputs, conversation history, uploaded files (including images, PDFs, documents, audio, and videos), and any other content you submit to the Service.
  • Technical and operational metadata: IP address, device type, operating system, browser type and version, screen resolution, language preferences, session identifiers, access timestamps, page views, feature usage patterns, error logs, performance metrics, and reliability data.
  • Preference and consent records: legal consent state (including method of acceptance, timestamp, and Terms version accepted), cookie preferences, notification preferences, selected settings (including Training Data, Data Partners, and Usage Statistics preferences), model preferences, and UI customization choices.
  • Communication data: messages you send to our support team, feedback, bug reports, feature requests, and any other communications with Exypnos.
  • Derived and inferred data: data we derive or infer from your use of the Service, such as usage patterns, feature engagement metrics, and service quality indicators.

3.Legal Basis for Processing (EEA/UK Users)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Contract performance: Processing necessary to provide the Service to you and fulfill our obligations under the Terms of Service (e.g., processing your prompts, storing your chat history, managing your account).
  • Legitimate interests: Processing necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms (e.g., improving the Service, detecting abuse, ensuring security, analyzing usage patterns for service optimization).
  • Consent: Processing based on your explicit consent, where required (e.g., optional data sharing with partners via the Data Partners setting, non-essential analytics via the Usage Statistics setting, marketing communications, and placement of non-essential cookies).
  • Legal obligation: Processing necessary to comply with applicable laws, regulations, or legal processes (e.g., responding to lawful requests from authorities, maintaining records required by law).

4.How We Use Data

We use the data we collect for the following purposes:

  • Provide, operate, maintain, and improve the Service and its features.
  • Route prompts and inputs to selected AI models and return generated responses.
  • Store chat history, preferences, and settings for continuity across sessions and devices.
  • Process and store uploaded files as necessary to provide requested features.
  • Authenticate users, manage accounts, and maintain session security.
  • Detect, prevent, and address abuse, fraud, security threats, and technical issues.
  • Enforce rate limits, usage quotas, and fair use policies.
  • Debug failures, monitor performance, and improve service reliability and stability.
  • Analyze usage patterns and trends to improve user experience and develop new features.
  • Comply with legal obligations, respond to lawful requests, and protect the rights, property, and safety of Exypnos, our users, and the public.
  • Apply user-selected data-sharing preferences where available in product settings.
  • Communicate with you about the Service, including service announcements, security alerts, and policy updates.
  • Provide customer support and respond to your inquiries and requests.

5.Data Sharing and Third-Party Providers

We share data with third parties only in the following circumstances:

  • AI model providers: When you choose third-party models, required prompts, attachments, and contextual data are transmitted to those providers to fulfill your request. Current model-provider integrations include Anthropic, Google, Moonshot AI, OpenAI, DeepSeek, and GLM (this list may expand over time). Each provider processes data according to their own privacy policies.
  • Infrastructure and service providers: We use third-party infrastructure and service providers to host, operate, and maintain the Service (for example, cloud hosting, content delivery networks, and monitoring services). These providers process data on our behalf and are contractually obligated to protect your data. A list of our current subprocessors and links to their privacy policies is available upon request by contacting [email protected].
  • Data partners (opt-in only): If you enable the Data Partners setting, Exypnos may share eligible data — meaning data that has been stripped of direct personal identifiers and aggregated with data from other users — with trusted model partners for model-improvement purposes, including potential training use by those partners. Raw prompts, personal information, and individually identifiable content are never shared with Data Partners. This sharing is entirely optional and controlled by you.
  • Legal and regulatory compliance: We may disclose data when required by law, regulation, legal process, or governmental request, or when we believe disclosure is necessary to protect the rights, property, or safety of Exypnos, our users, or the public.
  • Business transfers: In connection with a merger, acquisition, reorganization, sale of assets, or bankruptcy, your data may be transferred to the acquiring entity. We will provide notice before your data is transferred and becomes subject to a different privacy policy.
  • With your consent: We may share data with third parties when you have given us explicit consent to do so.

6.No Sale or Advertising Share

Exypnos does not sell your personal data to third parties, as defined under the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), or any other applicable law.

Exypnos does not share your personal data for cross-context behavioral advertising or targeted advertising purposes.

Exypnos does not use your personal data for profiling in furtherance of decisions that produce legal or similarly significant effects concerning you, except as necessary to provide the Service.

7.Storage, Encryption, and Access Control

User data is stored by Exypnos on infrastructure we operate and manage. We may use multiple storage locations for redundancy and performance.

We apply industry-standard encryption controls for data in transit (TLS 1.2 or higher) and at rest. Encryption methods are reviewed and updated periodically to align with evolving security standards.

Administrative decryption access to stored chat data is restricted to a limited number of authorized personnel, subject to access controls and audit logging, and is used only for service operation, security monitoring, abuse investigation, debugging, and legal compliance.

We implement access controls, including role-based access, authentication requirements, and audit logging, to limit access to personal data to authorized personnel who need it to perform their duties.

We conduct periodic security reviews and assessments to identify and address potential vulnerabilities in our systems and processes.

8.Data Retention

We retain personal data for as long as reasonably necessary to fulfill the purposes for which it was collected. The following retention periods apply by data category:

  • Account and profile data: Retained for the duration of your account and for up to 90 days after account closure to allow for account recovery, after which it is deleted or anonymized.
  • User-generated content (chats, messages, uploaded files): Retained for the duration of your account. You may delete individual chats or files at any time through the Service. After account closure, this data is deleted within 90 days, except where retention is required by law or for legitimate operational purposes.
  • Technical and operational metadata (IP addresses, access logs, error logs): Retained for up to 12 months for security, abuse detection, and debugging purposes, after which it is deleted or anonymized.
  • Preference and consent records: Retained for the duration of your account and for up to 3 years after account closure to demonstrate compliance with legal obligations.
  • Communication data (support messages, feedback): Retained for up to 2 years after the last communication for quality assurance and legal compliance purposes.
  • Derived and inferred data: Retained for up to 12 months, after which it is deleted or anonymized.

9.Cookies, Local Storage, and Similar Technologies

Exypnos uses cookies, local storage, session storage, and similar technologies for the following purposes:

  • Strictly necessary cookies: Authentication and security cookies required to verify your identity, maintain your session, and protect against unauthorized access and cross-site request forgery. These cookies are essential for the Service to function and cannot be disabled.
  • Functional cookies: Used to remember your preferences, settings, and consent choices across sessions. These cookies enhance your experience but are not strictly necessary.
  • Analytics and performance cookies: Used to collect usage data and performance metrics that help us understand how the Service is used and identify areas for improvement (subject to your Usage Statistics preference). For users in the EEA, UK, or Switzerland, non-essential analytics cookies are only placed with your prior consent, which you may provide or withdraw through our cookie consent mechanism.

10.Cookie Consent (EEA/UK/Swiss Users)

If you are located in the European Economic Area, United Kingdom, or Switzerland, we will present you with a cookie consent mechanism before placing any non-essential cookies on your device. You may accept or reject non-essential cookies at that time.

You may change your cookie preferences at any time through the cookie settings accessible in the Service. Withdrawing consent for non-essential cookies will not affect the lawfulness of processing based on consent before its withdrawal.

Strictly necessary cookies do not require consent and will be placed regardless of your cookie preferences, as they are essential for the Service to function.

For more information about the specific cookies we use, their purposes, and their retention periods, please contact us at [email protected].

11.International Data Transfers

Depending on model routing, infrastructure location, and third-party provider locations, your data may be processed in jurisdictions other than your own, including the United States and other countries where data protection laws may differ from those in your jurisdiction.

By using the Service, you acknowledge and consent to the transfer of your data to jurisdictions outside your own as necessary to provide the Service.

Where required by applicable law (such as the GDPR), we implement appropriate safeguards for international data transfers, which may include standard contractual clauses (SCCs) approved by the European Commission, adequacy decisions, or other legally recognized transfer mechanisms. Copies of the relevant transfer mechanisms are available upon request by contacting [email protected].

If you are in Singapore, where we transfer your personal data outside Singapore we will take reasonable steps to ensure that the receiving party is bound by legally enforceable obligations to provide a standard of protection comparable to that under the PDPA, in accordance with Section 26 of the PDPA and the Personal Data Protection Regulations.

If you are located in the EEA, UK, or Switzerland and have concerns about international data transfers, please contact us at [email protected] for more information about the safeguards we have in place.

12.Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: You can request information about the personal data we hold about you and obtain a copy of that data.
  • Correction: You can request that we correct inaccurate or incomplete personal data.
  • Deletion: You can request that we delete your personal data, subject to certain exceptions (such as data we are required to retain by law).
  • Data portability: You can request a copy of your personal data in a structured, commonly used, and machine-readable format.
  • Restriction: You can request that we restrict the processing of your personal data in certain circumstances.
  • Objection: You can object to the processing of your personal data based on our legitimate interests.
  • Withdrawal of consent: Where processing is based on your consent, you can withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
  • In-product controls: You can manage profile details, delete chats, and adjust settings (Training Data, Data Partners, Usage Statistics) directly within the Service.
  • Account closure: You can stop using the Service at any time and request account closure by contacting [email protected].

13.California Residents — CCPA/CPRA Rights

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including:

  • The right to know what personal information we collect, use, disclose, and sell (if applicable).
  • The right to request deletion of your personal information.
  • The right to opt out of the sale or sharing of your personal information (Exypnos does not sell or share personal information for advertising purposes).
  • The right to correct inaccurate personal information.
  • The right to limit the use and disclosure of sensitive personal information.
  • The right to non-discrimination for exercising your privacy rights.

14.Security and Incident Handling

We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. These safeguards include encryption, access controls, monitoring, and regular security assessments.

No system is perfectly secure, and we cannot guarantee the absolute security of your data. You acknowledge that you transmit data to the Service at your own risk.

If we confirm a data breach that is reportable under applicable law, we will provide notifications to affected individuals and regulatory authorities as required, within the timeframes specified by applicable law. For data breaches that are notifiable under the PDPA, we will notify the Personal Data Protection Commission of Singapore (PDPC) and affected individuals in accordance with the data breach notification obligations under the PDPA.

If you discover a security vulnerability in the Service, we encourage you to report it responsibly to [email protected]. Please do not publicly disclose the vulnerability until we have had a reasonable opportunity to address it.

15.Children's Privacy

The Service is not intended for or directed at children under 13 years of age, or under the minimum age required by applicable law in their jurisdiction, whichever is higher.

We do not knowingly collect personal data from children under the applicable minimum age. If we become aware that we have collected personal data from a child under the applicable minimum age without verifiable parental consent, we will take steps to delete that data as soon as reasonably practicable.

If you are a parent or guardian and believe that your child has provided personal data to us without your consent, please contact us at [email protected] so that we can take appropriate action.

16.Automated Decision-Making

The Service uses automated processing, including AI and machine learning, to generate responses to your inputs, route requests to appropriate models, detect abuse, enforce usage limits, and maintain service quality.

We do not use automated decision-making that produces legal or similarly significant effects on you without human oversight, except as necessary to provide the core functionality of the Service (i.e., generating AI responses to your prompts).

If you are located in a jurisdiction that grants you the right to not be subject to automated decision-making, and you believe that an automated decision has significantly affected you, please contact us at [email protected] to request human review.

17.Do Not Track Signals

Some web browsers transmit "Do Not Track" (DNT) signals. Because there is no universally accepted standard for how to respond to DNT signals, the Service does not currently respond to DNT signals. We will update this policy if a standard for responding to DNT signals is established.

18.Policy Updates

We may revise this Privacy Policy from time to time to reflect changes in our practices, the Service, or applicable law. When we make material changes, we will update the version number and effective date at the top of this policy.

For material changes, we will make reasonable efforts to notify you through the Service (such as a banner, consent prompt, or email notification) before the changes take effect.

Your continued use of the Service after the updated Privacy Policy becomes effective constitutes your acceptance of the revised policy. If you do not agree to the updated policy, you must stop using the Service.

We recommend reviewing this Privacy Policy periodically to stay informed about how we protect your data.

19.Language and Translation

The English version of this Privacy Policy is the authoritative and legally binding version.

Any translated version is provided solely for convenience and informational purposes. In the event of any conflict, inconsistency, or ambiguity between the English version and any translation, the English version shall prevail.

Translations of this Privacy Policy published on the Service — including the Spanish, Japanese, Filipino, and Simplified Chinese versions — are produced using artificial intelligence and are not certified or independently verified translations. To the fullest extent permitted by applicable law, Exypnos accepts no liability for any error, omission, mistranslation, or ambiguity introduced by a translated version, or for any reliance placed on one. This does not limit any right you have under applicable law to receive information about the processing of your personal data in a language you understand; if any part of this policy is unclear to you, contact us and we will explain it.

20.EEA/UK Representative

If Exypnos is required to appoint a representative in the European Economic Area under Article 27 of the GDPR, or in the United Kingdom under equivalent UK data protection legislation, details of such representative will be published on our website and updated in this section.

As of the Effective Date of this Privacy Policy, data protection inquiries from EEA and UK residents may be directed to [email protected]. We will update this section with appointed representative details if and when such appointment is made.

21.Contact and Data Protection Inquiries

The Service is operated by Exypnos One, based in the Republic of Singapore. Our business address is: Exypnos One, Level 39, Marina Bay Financial Centre Tower Two, 10 Marina Boulevard, Singapore 018983.

For privacy questions, data protection inquiries, or to exercise any of your rights described in this policy, please contact us at [email protected]. For formal data protection or legal notices, contact [email protected].

We will endeavor to respond to your request within a reasonable timeframe. Response times may vary depending on the nature and complexity of the request, but we aim to respond within 14 business days. For requests under the GDPR, we will respond within one month as required by law, with the possibility of a two-month extension for complex requests.

For urgent privacy or security issues, you may also reach us through Discord: https://discord.gg/ZmeyrHkh.

If you are located in Singapore and are not satisfied with our response to your privacy concern, you may lodge a complaint with the Personal Data Protection Commission of Singapore (PDPC).

If you are located in the EEA and are not satisfied with our response to your privacy concern, you have the right to lodge a complaint with your local data protection supervisory authority.

If you are located in the UK, you may contact the Information Commissioner's Office (ICO) with any privacy concerns.

Related policyTerms of Service→Return toHome→

Orchestrating AI that makes your vision real.

© 2026 Exypnos One. All rights reserved.

Product

Try ExypnosPricingHome

Features

ChatLearnImage GenerationWorkflowsWorkspace

Company

TeamEthan MacDonaldHelp CenterDiscord

Legal

Terms of ServicePrivacy Policy
HomePricingHelp
DiscordTerms of ServicePrivacy Policy
Open Exypnos