Privacy Policy
Effective: September 7, 2026 · Cuya, Inc., a Delaware corporation
Cuya is an AI routing platform: you send a request, Cuya analyzes it and routes it to the best-fit AI model across many providers, and returns the answer with a receipt showing the route, the cost, and the rationale. This policy explains what we collect, why, and the choices you have. Plain terms, because you should be able to actually read this.
1. What we collect
- Account data. Email address and password (hashed). A name if you provide one. For paid plans, your Stripe customer relationship — we see plan status and transaction records, never full card numbers.
- Your prompts and conversations. The content you send, conversation history, project context, and any documents you attach. This is the core input to the service: we need it to route your request and to power continuity features (context, corrections, memory across turns).
- Routing and usage metadata. Per request: the selected model, rejected candidates, estimated and actual cost, latency, health signals, and quality telemetry. This is what makes the routing smarter and produces the "receipt" you see.
- Your feedback. Ratings (thumbs up/down, "too weak", "overkill") and comments you submit. These update per-model precision for your task types.
- API keys. Keys you create are stored scoped and hashed; provider credentials we hold on your behalf are encrypted at rest (AES-256-GCM).
- Operational logs. Security events, error traces, and rate-limit data, kept limited to what's needed to operate and defend the service.
2. The important one: your prompts go to third-party AI providers
Cuya does not run its own foundation models. To answer a request, your prompt (and the context needed to answer it) is sent to the third-party model provider Cuya selects — for example OpenAI, Anthropic, Google, Mistral, Moonshot, Z.ai, DeepSeek, Qwen, Perplexity, xAI, Cohere, or Meta. Each provider processes that request under its own terms of service and privacy policy. We pick providers to fit your task, your policies, and your budget; you can see exactly which model served each request in your dashboard receipts.
We do not sell your personal data, and we do not use your prompts to train foundation models.
3. How we use your data
- To provide the service: route requests, execute them, return answers and receipts.
- To measure and improve quality: precision learning per model and task type from your feedback and execution signals.
- To bill correctly: credit burn is computed from routed requests; Stripe handles payment.
- To keep the service safe and reliable: abuse detection, error diagnosis, provider health monitoring.
- Communications. Service notices and responses to support requests. We don't spam marketing.
4. Retention and deletion
Your projects, conversations, and context data are retained while your account is active — that continuity is a feature you're using. When you delete a project or conversation, it is removed from the serving stores. You can request full account deletion at support@cuya.ai; we erase account data and stop retention, except where copies remain briefly in automated backups (daily, limited window) or where law requires records (e.g., billing records we must keep for tax purposes). Routing telemetry is aggregated and stripped of prompt content where possible.
5. Security
TLS in transit everywhere. Encryption at rest for stored provider credentials (AES-256-GCM). Scoped API keys with per-key budgets, rate limits, and model pools. Access to production systems is restricted and audited. No system is perfectly secure; we commit to real measures and to telling you honestly at support@cuya.ai if something affects your data.
6. Your rights
Depending on where you live (including California under the CCPA/CPRA, and other jurisdictions with similar laws), you may have the right to: access your personal data, correct it, delete it, export it, opt out of any "sale" or "sharing" (we don't sell personal data), and not be discriminated against for exercising these rights. Exercise any of these by emailing support@cuya.ai — we respond within 30 days.
7. Where data is processed
Cuya, Inc. is a Delaware corporation. Our infrastructure runs in the United States (AWS). If you use Cuya from outside the US, your data is transferred to and processed in the US under this policy.
8. Children
Cuya is a professional tool and is not directed to children under 16. We don't knowingly collect data from children; if you believe a child has an account, contact us and we'll remove it.
9. Changes to this policy
If we change this policy, we'll update the effective date above and post the new version at this URL. Material changes get a notice in the dashboard (and by email where we have one) before they take effect.
10. Contact
Cuya, Inc. — a Delaware corporation.
Privacy questions, deletion requests, everything else: support@cuya.ai