What we collect, and who else sees it
This policy covers the saina.run website, the browser playground and the hosted API at api.saina.run. It names every company that processes data for us, says what each one sees, and explains how to ask us about your information.
In short. The hosted API does not store what you send it or what it answers. The website keeps a waitlist of email addresses and the record that you accepted the terms. Google Analytics runs on public pages. Cloudflare sits in front of everything. We do not sell personal information, use your content to train models, or send marketing email without consent. Questions go to [email protected].
1. Who is responsible
Rama Labs Inc., trading as Saina, of British Columbia, Canada ("Saina", "we", "us") operates saina.run and api.saina.run and is responsible for the personal information described in this policy. Our Privacy Contact is accountable for compliance with this policy and with the privacy laws that apply to us, including British Columbia's Personal Information Protection Act. Reach the Privacy Contact at [email protected] with "Privacy" in the subject line.
This policy does not cover software you run yourself. The open-weights model, the saina server, the SDKs and the n8n node run on your own machines under their own licenses; when you use them, nothing reaches us. If you point the browser playground at a server operated by you or someone else, that server's operator controls what happens to the requests; only the parts of this policy about the website itself still apply.
2. What we collect
Visiting the website
- Our web server does not keep access logs. It serves files and writes nothing about the visit; the only thing it logs is a failure to save a waitlist entry, without the entry.
- Cloudflare proxies every request to saina.run and api.saina.run. It terminates TLS, forwards the request to our server over a private tunnel and keeps its own edge metadata (your IP address, timestamps, request paths and status codes) under Cloudflare's privacy policy. Cloudflare may set cookies it needs to deliver and protect the site.
- Google Analytics (property
G-2ZMGS5EF0G) runs on public pages, including this one, and sets the_gaand_ga_*cookies. Google receives page views, referrers, approximate location and browser and device information under Google's privacy policy. We use it only for aggregate page-view statistics; we do not use it for advertising, and we do not connect it to waitlist entries or API keys. - Google Fonts are loaded from Google's servers, which receive your IP address and browser details in order to serve the font files.
Cookies are set by Google Analytics and, where needed, by Cloudflare; our own pages set none. You can block or delete them in your browser, or use Google's opt-out add-on. The site works without them.
Joining the hosted-API waitlist
The form on the API page asks for your email address, optionally the tool you use (n8n Cloud, Make, Zapier, your own code or other) and a note about your use case, and requires you to accept the current Terms of Service. We record:
- the email address, tool and note exactly as submitted;
- the acceptance record: the terms version you accepted, cryptographic hashes of the terms and the hosted-API data policy as published at that moment, the time of acceptance and the method (the waitlist checkbox).
We do not record your IP address with the entry. To limit abuse, the server counts form attempts per IP address in memory for ten minutes and then forgets them; that count is never written anywhere. Entries are stored in a file on our own server in British Columbia that is never served to the public, and are read by a person when issuing keys.
We use the email address to tell you about access to the hosted API, to issue a key, and to send the service and legal notices the terms require. That is a service communication, not a marketing list. Do not put confidential inputs or sensitive personal information in the use-case note.
Calling the hosted API
The hosted API data policy is the authoritative statement of how inference content is handled and is incorporated into the terms. In summary:
- Request and response bodies are never stored. The context, questions and options you send are processed in memory and discarded when the answer is returned. There is no database, no disk write, no cache of your text and no analytics on content.
- No per-request logs. The API server runs with access logging off. It logs startup and failures only, and those lines never contain request content or keys. Error responses name the field that failed, not its value.
- Not used for training. Nothing you send is used to train, evaluate or tune any model.
- Keys. Each API key identifies one caller. We keep the key together with the name or email of the person or organization it was issued to, so that we can revoke it and reach you about the service. Keys are not linked to request content, because no request content is kept.
- Transit. Requests pass through Cloudflare as described above. Cloudflare rate-limits the API per IP address and keeps edge metadata; it does not store bodies for us, and we have not enabled any Cloudflare feature that logs them.
- Standby capacity. If our own server is unavailable, the same server software can run on a RunPod GPU in a Canadian data centre first, or elsewhere only if no Canadian capacity is available. The standby runs under the same no-storage, no-access-log configuration, and its location is shown on the API page while it is in use.
- OpenRouter. If you call Saina through OpenRouter, OpenRouter receives your request first and handles it under its own privacy policy before it reaches our server, where the rules above apply.
Using the browser playground
The playground runs in your browser. Your draft context and questions, the server address you selected and your display preferences are kept in your browser's local storage until you replace or clear them. An API key you enter is kept in session storage, which normally ends when the tab closes; use the Forget control and clear site data on a shared device, because some browsers restore session storage when they reopen tabs. The version of the terms you accepted is also kept in session storage. None of this is sent to us. Requests go directly from your browser to the server address you selected; by default that is a server on your own machine, and if you choose api.saina.run the hosted API rules above apply.
Emailing us
Mail to [email protected] is received by Cloudflare Email Routing and forwarded to a Google Workspace mailbox, where we read and answer it; replies are sent through Google. Both providers process the message to deliver it, under their own policies. We keep correspondence for as long as it is needed to deal with your request and to keep a record of the relationship. Do not send prompts, confidential inputs, full card numbers or sensitive personal information by ordinary email.
What we do not collect
There are no user accounts, passwords, payment details or purchases on the service today. We do not buy data about you, combine your information with data from other sources, or build profiles. We do not use automated decision-making about you.
3. Service providers
These companies process information for us, only for the purposes listed. None of them receives your API content except as shown in the "Data it handles" column.
| Provider | What it does for us | Data it handles | Where |
|---|---|---|---|
| Cloudflare | Proxies saina.run and api.saina.run (TLS, tunnel to our server, rate limiting); routes inbound email to [email protected] | Requests in transit, including API content while it passes through; IP address, timestamps, paths and status codes at the edge; email in transit | Global edge network; the data centre nearest you |
| Google Analytics on public pages; Google Fonts; the mailbox behind [email protected] | Page views, approximate location, browser and device data via cookies; IP address and browser details for font requests; email you send us | United States and other Google locations | |
| RunPod | Standby GPU for the hosted API when our own server is unavailable | API content in memory while the standby is in use; nothing is stored | Canada first; elsewhere only if no Canadian capacity is available, shown on the API page while active |
Our own server in British Columbia, Canada, serves the website, stores the waitlist and runs the model. OpenRouter is not our provider: it is a platform you may choose to call us through, under its own policy. We will list any other provider here before we use it, and a provider that handles inference content will be named on the hosted API data policy as well.
Cloudflare, Google and, when active outside Canada, RunPod process information outside Canada. While it is there, it may be accessible to the courts, law-enforcement and national-security authorities of those countries under their laws. Personal information kept by us stays in Canada.
4. Why we use it
- To provide the service: answer API requests, manage waitlist access, issue and revoke keys, and send the notices the service needs.
- To keep it secure and working: block abuse and bots, enforce rate limits, investigate failures and recover from outages.
- To understand how the website is used, in aggregate, through Google Analytics.
- To meet legal and accounting obligations and to keep evidence of the agreement you accepted.
We do not sell personal information, do not share it for advertising, do not use your content to train or evaluate models and do not send marketing email without your consent. Where consent is the legal basis, for example for analytics cookies in some countries, you can withdraw it at any time by blocking or deleting the cookies; withdrawing consent does not affect processing that happened before.
5. How long we keep it
| Data | Kept for |
|---|---|
| API request and response content | Not kept. Processed in memory and discarded when the answer is returned. |
| API server logs | Startup and failure lines only, without content, in the system journal under its normal rotation. |
| Waitlist entries (email, tool, note) | Until you are issued a key, you ask to be removed, or the waitlist is closed; a copy of the entry is then kept only as part of the key-holder record below. |
| Key-holder records and terms acceptance records | For as long as the key is active and afterwards for as long as needed to evidence the agreement, defend claims and meet legal retention periods. |
| Email correspondence | For as long as needed to deal with the request and keep a record of the relationship. |
| Abuse counters for the waitlist form | Ten minutes, in memory only. |
| Browser storage (playground) | In your browser until you clear it; session storage normally ends when the tab closes. |
| Cloudflare edge metadata, Google Analytics data | Under each provider's retention policy; we do not export it. |
When we delete information, we delete it from our server; backups of the server, if any, are overwritten on their normal cycle. Removal from the waitlist does not require us to delete records we must lawfully keep, such as evidence that an agreement was accepted.
6. How we protect it
All traffic to saina.run and api.saina.run is encrypted with TLS and the site sends HTTP Strict Transport Security headers. Our server accepts connections only through Cloudflare's tunnel; no ports are open to the internet. The waitlist file lives outside the directory the web server publishes and cannot be requested. API keys are revoked individually by removing them from the server's configuration. Access to the server is limited to the people who operate it. No system is perfectly secure; if we learn of a breach affecting your personal information, we will notify you and any regulator as the law requires.
7. Your rights and choices
You can ask us to:
- tell you whether we hold personal information about you, and give you access to it;
- correct it if it is inaccurate or incomplete;
- remove you from the waitlist, revoke your API key, or delete information we do not need to keep;
- explain how we have used or disclosed it;
- withdraw consent where consent is the basis for processing.
Email the Privacy Contact at [email protected]. We may ask you to confirm that you control the email address the request concerns. We answer within 30 days, or tell you if we need longer and why. There is no charge for a reasonable request. If you are not satisfied, you may complain to the Office of the Information and Privacy Commissioner for British Columbia; depending on where you live, your local data-protection authority may also hear a complaint. If you are in the European Economic Area, the United Kingdom or another jurisdiction with additional rights, such as portability or objection, those rights apply to you to the extent the law gives them; the process is the same.
8. Children
The service is for people who are at least 18 and have reached the age of majority where they live. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact us and we will delete it.
9. Changes to this policy
We will update this page when how we handle personal information changes, and show the new effective date at the top. If a change materially affects people who have a key or are on the waitlist, for example a new provider that handles inference content, a change of processing location or a new retention period, we will email the address we have for you before the change takes effect and, where the terms or the law require it, ask for your acceptance. The hosted-API data policy and the Terms of Service have their own version and notice rules, described in section 15 of the terms. Paid plans, if offered, will have their providers, locations and retention disclosed before they are activated; nothing in this policy enables them.
10. Contact
Rama Labs Inc., trading as Saina, British Columbia, Canada. Privacy Contact: [email protected]. The same address handles service, billing and legal notices; put "Privacy" in the subject line so a privacy request is handled as one. Related documents: Terms of Service and the hosted API data policy.