Privacy Policy

What we collect, and who else sees it

This policy covers the saina.run website, the browser playground and the hosted API at api.saina.run. It names every company that processes data for us, says what each one sees, and explains how to ask us about your information.

Rama Labs Inc. · Effective October 9, 2026

In short. The hosted API does not store what you send it or what it answers. The website keeps a waitlist of email addresses and the record that you accepted the terms. Google Analytics runs on public pages. Cloudflare sits in front of everything. We do not sell personal information, use your content to train models, or send marketing email without consent. Questions go to [email protected].

1. Who is responsible

Rama Labs Inc., trading as Saina, of British Columbia, Canada ("Saina", "we", "us") operates saina.run and api.saina.run and is responsible for the personal information described in this policy. Our Privacy Contact is accountable for compliance with this policy and with the privacy laws that apply to us, including British Columbia's Personal Information Protection Act. Reach the Privacy Contact at [email protected] with "Privacy" in the subject line.

This policy does not cover software you run yourself. The open-weights model, the saina server, the SDKs and the n8n node run on your own machines under their own licenses; when you use them, nothing reaches us. If you point the browser playground at a server operated by you or someone else, that server's operator controls what happens to the requests; only the parts of this policy about the website itself still apply.

2. What we collect

Visiting the website

Cookies are set by Google Analytics and, where needed, by Cloudflare; our own pages set none. You can block or delete them in your browser, or use Google's opt-out add-on. The site works without them.

Joining the hosted-API waitlist

The form on the API page asks for your email address, optionally the tool you use (n8n Cloud, Make, Zapier, your own code or other) and a note about your use case, and requires you to accept the current Terms of Service. We record:

We do not record your IP address with the entry. To limit abuse, the server counts form attempts per IP address in memory for ten minutes and then forgets them; that count is never written anywhere. Entries are stored in a file on our own server in British Columbia that is never served to the public, and are read by a person when issuing keys.

We use the email address to tell you about access to the hosted API, to issue a key, and to send the service and legal notices the terms require. That is a service communication, not a marketing list. Do not put confidential inputs or sensitive personal information in the use-case note.

Calling the hosted API

The hosted API data policy is the authoritative statement of how inference content is handled and is incorporated into the terms. In summary:

Using the browser playground

The playground runs in your browser. Your draft context and questions, the server address you selected and your display preferences are kept in your browser's local storage until you replace or clear them. An API key you enter is kept in session storage, which normally ends when the tab closes; use the Forget control and clear site data on a shared device, because some browsers restore session storage when they reopen tabs. The version of the terms you accepted is also kept in session storage. None of this is sent to us. Requests go directly from your browser to the server address you selected; by default that is a server on your own machine, and if you choose api.saina.run the hosted API rules above apply.

Emailing us

Mail to [email protected] is received by Cloudflare Email Routing and forwarded to a Google Workspace mailbox, where we read and answer it; replies are sent through Google. Both providers process the message to deliver it, under their own policies. We keep correspondence for as long as it is needed to deal with your request and to keep a record of the relationship. Do not send prompts, confidential inputs, full card numbers or sensitive personal information by ordinary email.

What we do not collect

There are no user accounts, passwords, payment details or purchases on the service today. We do not buy data about you, combine your information with data from other sources, or build profiles. We do not use automated decision-making about you.

3. Service providers

These companies process information for us, only for the purposes listed. None of them receives your API content except as shown in the "Data it handles" column.

ProviderWhat it does for usData it handlesWhere
CloudflareProxies saina.run and api.saina.run (TLS, tunnel to our server, rate limiting); routes inbound email to [email protected]Requests in transit, including API content while it passes through; IP address, timestamps, paths and status codes at the edge; email in transitGlobal edge network; the data centre nearest you
GoogleGoogle Analytics on public pages; Google Fonts; the mailbox behind [email protected]Page views, approximate location, browser and device data via cookies; IP address and browser details for font requests; email you send usUnited States and other Google locations
RunPodStandby GPU for the hosted API when our own server is unavailableAPI content in memory while the standby is in use; nothing is storedCanada first; elsewhere only if no Canadian capacity is available, shown on the API page while active

Our own server in British Columbia, Canada, serves the website, stores the waitlist and runs the model. OpenRouter is not our provider: it is a platform you may choose to call us through, under its own policy. We will list any other provider here before we use it, and a provider that handles inference content will be named on the hosted API data policy as well.

Cloudflare, Google and, when active outside Canada, RunPod process information outside Canada. While it is there, it may be accessible to the courts, law-enforcement and national-security authorities of those countries under their laws. Personal information kept by us stays in Canada.

4. Why we use it

We do not sell personal information, do not share it for advertising, do not use your content to train or evaluate models and do not send marketing email without your consent. Where consent is the legal basis, for example for analytics cookies in some countries, you can withdraw it at any time by blocking or deleting the cookies; withdrawing consent does not affect processing that happened before.

5. How long we keep it

DataKept for
API request and response contentNot kept. Processed in memory and discarded when the answer is returned.
API server logsStartup and failure lines only, without content, in the system journal under its normal rotation.
Waitlist entries (email, tool, note)Until you are issued a key, you ask to be removed, or the waitlist is closed; a copy of the entry is then kept only as part of the key-holder record below.
Key-holder records and terms acceptance recordsFor as long as the key is active and afterwards for as long as needed to evidence the agreement, defend claims and meet legal retention periods.
Email correspondenceFor as long as needed to deal with the request and keep a record of the relationship.
Abuse counters for the waitlist formTen minutes, in memory only.
Browser storage (playground)In your browser until you clear it; session storage normally ends when the tab closes.
Cloudflare edge metadata, Google Analytics dataUnder each provider's retention policy; we do not export it.

When we delete information, we delete it from our server; backups of the server, if any, are overwritten on their normal cycle. Removal from the waitlist does not require us to delete records we must lawfully keep, such as evidence that an agreement was accepted.

6. How we protect it

All traffic to saina.run and api.saina.run is encrypted with TLS and the site sends HTTP Strict Transport Security headers. Our server accepts connections only through Cloudflare's tunnel; no ports are open to the internet. The waitlist file lives outside the directory the web server publishes and cannot be requested. API keys are revoked individually by removing them from the server's configuration. Access to the server is limited to the people who operate it. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify you and any regulator as the law requires.

7. Your rights and choices

You can ask us to:

Email the Privacy Contact at [email protected]. We may ask you to confirm that you control the email address the request concerns. We answer within 30 days, or tell you if we need longer and why. There is no charge for a reasonable request. If you are not satisfied, you may complain to the Office of the Information and Privacy Commissioner for British Columbia; depending on where you live, your local data-protection authority may also hear a complaint. If you are in the European Economic Area, the United Kingdom or another jurisdiction with additional rights, such as portability or objection, those rights apply to you to the extent the law gives them; the process is the same.

8. Children

The service is for people who are at least 18 and have reached the age of majority where they live. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.

9. Changes to this policy

We will update this page when how we handle personal information changes, and show the new effective date at the top. If a change materially affects people who have a key or are on the waitlist, for example a new provider that handles inference content, a change of processing location or a new retention period, we will email the address we have for you before the change takes effect and, where the terms or the law require it, ask for your acceptance. The hosted-API data policy and the Terms of Service have their own version and notice rules, described in section 15 of the terms. Paid plans, if offered, will have their providers, locations and retention disclosed before they are activated; nothing in this policy enables them.

10. Contact

Rama Labs Inc., trading as Saina, British Columbia, Canada. Privacy Contact: [email protected]. The same address handles service, billing and legal notices; put "Privacy" in the subject line so a privacy request is handled as one. Related documents: Terms of Service and the hosted API data policy.