Privacy Policy
Last updated: 23 August 2026. This policy explains what personal data Violent Delights processes, why, and what rights you have. It is written to satisfy the information duties of the EU General Data Protection Regulation (EU) 2016/679 ("GDPR").
1. Data Controller
Violent Delights, operated from Finland, is the data controller for the processing described in this policy. You can contact us about any privacy matter at the address given on this site. Finland's supervisory authority is the Office of the Data Protection Ombudsman (tietosuoja.fi).
2. What We Collect
We collect only what is needed to run the Service:
- Account data. Your username, credentials (stored only as cryptographic hashes), and authentication session records.
- API key data. The names you give your API keys, key prefixes, and key hashes. We never store full keys in recoverable form.
- Usage data. Per-request token counts, the model used, cost in cents, and timestamps. This is needed for metering and billing.
- Billing data. Invoice records and, if you manage payment, a Stripe customer reference. Card and bank details are held by Stripe, not by us.
- Waitlist data. If you join the waitlist, the email address you submit.
- Technical logs. Standard request metadata (IP address, timestamps, user agent) kept transiently by our hosting platform for security and debugging.
We do not run analytics, advertising trackers, or third-party cookies. The only cookie we set is the session cookie required to keep you logged in.
3. Prompts and Outputs
Prompts you submit and outputs the models return are processed in memory to serve each request. We do not store them. For performance, our inference servers use automatic prefix caching: fragments of recent request context are held transiently in GPU memory and evicted automatically under memory pressure, typically within seconds to minutes. This cache is never written to disk, is not readable by us as content, and cannot be used to retrieve the text of past requests. Cached fragments are isolated per customer so that one customer's context is never reused to serve another. Prompts and outputs are otherwise not retained, read, or reviewed, except where retention is required by law or needed to protect the security of the Service. If you include personal data about yourself or others in prompts, you do so at your own initiative; do not submit personal data about third parties unless you have a lawful basis to do so.
4. Lawful Bases
We process personal data on the following bases under Article 6 GDPR:
- Contract (Art. 6(1)(b)). To provide the account, API access, metering, and billing you request.
- Legitimate interests (Art. 6(1)(f)). To secure the Service, prevent abuse, and keep minimal technical logs.
- Legal obligation (Art. 6(1)(c)). To retain accounting records as required by Finnish accounting and tax law, and to comply with lawful requests from authorities.
- Consent (Art. 6(1)(a)). For the waitlist, until you ask to be removed.
5. Retention
- Account, API key, and usage records: kept while your account is active and deleted or anonymised within 90 days of account closure.
- Invoices and billing records: kept for the period required by Finnish accounting law (generally six years from the end of the accounting year).
- Waitlist emails: kept until you unsubscribe or the list is closed.
- Session records: deleted on logout or expiry.
6. Recipients and Processors
We use a small number of processors to run the Service: Cloudflare (hosting, content delivery, and D1 database) and Stripe (payment processing). Each processes data under its own data processing terms and, where data moves outside the EU/EEA, under the safeguards required by Chapter V GDPR (such as the EU-US Data Privacy Framework or standard contractual clauses). We do not sell personal data, and we do not share it with anyone else except where required by law.
7. Your Rights
Under the GDPR you have the right to: access your data; have inaccurate data rectified; have data erased ("right to be forgotten") where the legal grounds allow; restrict or object to processing; data portability for data you provided; withdraw consent at any time where processing is based on consent; and lodge a complaint with the Office of the Data Protection Ombudsman or your local supervisory authority. To exercise any right, contact us; we respond within one month as required by Article 12 GDPR.
8. Security
Passwords and API keys are stored only as SHA-256 hashes. Sessions use HttpOnly, Secure, SameSite cookies. API endpoints are rate-limited and served over HTTPS. No system is perfectly secure, but we apply measures proportionate to the risk as required by Article 32 GDPR.
9. Children
The Service is not directed at children, and we do not knowingly collect personal data from anyone under 18. Because the models are uncensored, the Service is unsuitable for minors.
10. Changes
We may update this policy from time to time. The version posted on this page, with its stated revision date, is the version in force. Material changes will be announced on this site before they take effect.
11. Related Terms
Your use of the Service is also subject to our Legal Disclaimer, which covers acceptable use, limitation of liability, and governing law.