On this page
1. Summary
This is a plain-language summary. It does not replace the full policy below.
- Your prompts and model outputs are not stored. We process the content you send to the API only to return a response, and we do not persist that content after the request completes. See section 4.
- Account data is limited. You can sign in with Google or email. We keep what is needed to run your account: name, email address, and the basics to authenticate you and bill you.
- Usage data is metadata. Token counts, timestamps, request status, rate-limit counters, and spend. Not the content of your requests.
- Analytics is opt-in. Google Analytics stays off until you allow it, and it never receives your prompts, API keys, or payment details. See section 12.
- We do not sell your personal data and we do not use your content to train models.
- Inference runs on hardware we control. Requests are served from dedicated GPU infrastructure and are not forwarded to Zhipu AI or any other third-party model provider.
2. Who we are
WeCoding is operated by WeCoding Pte. Ltd., a company incorporated in Singapore (UEN [insert UEN], registered address [insert registered address, Singapore]). In this policy, "WeCoding", "we", "us", and "our" refer to WeCoding Pte. Ltd.
WeCoding is an independent hosting provider. We host the GLM-5.2 model (a model developed by Zhipu AI) on dedicated hardware and expose it through an OpenAI-compatible API. We are not affiliated with, endorsed by, or sponsored by Zhipu AI or OpenAI. GLM-5.2 is a model by Zhipu AI; WeCoding is an independent hosting provider.
For the purposes of EU/UK data-protection law, WeCoding Pte. Ltd. acts as the controller of your personal data. Under Singapore's Personal Data Protection Act 2012 (PDPA), we are the organisation responsible for your personal data.
3. Data we collect
3.1 Data you provide
- Account data: your name and email address, whether you register by email or through Google ("Continue with Google"). If you use Google sign-in, Google shares the profile information you authorise, typically your name and email.
- Workspace and billing data: plan selection, billing address, invoicing details, and the payment-card metadata required to process payments (handled by our payment processor; see section 7).
- Support and contact data: anything you choose to send us when you contact us at hello@WeCoding.dev.
3.2 Data generated when you use the service
- API keys and credentials: the API keys you create in the console. Keys are stored in hashed form and are shown in full only once, at creation.
- Usage metadata: per-request metadata such as timestamps, model and endpoint, token counts (prompt, completion, cached, thinking), HTTP status, error codes, rate-limit counters, and accumulated credit usage and spend. This is the data visible in your usage dashboard and request logs.
- Technical data: IP address, request headers our servers need to operate (such as user agent and locale), and approximate region inferred from network routing.
3.3 Data collected automatically (only if you allow it)
- Analytics data: if you allow analytics, basic product-usage metrics collected via Google Analytics, such as page views and session timing. See section 12.
About the content of your requests. The prompts, code, files, and model outputs you send and receive are processed to return a response, but they are not retained. See the next section.
4. What we do not collect or retain
- No prompt or output storage. We do not write the content of your prompts or the model's outputs to persistent storage. Content is held in memory for the duration of the request and is not persisted in logs, databases, or analytics.
- No model training on your content. We do not use your prompts or outputs to train, fine-tune, or improve models.
- No content in analytics. Even when Google Analytics is enabled, it never receives your prompts, outputs, API keys, or payment details.
- No sale of personal data. We do not sell your personal data to anyone.
If our practices here ever change, we will update this policy and give you notice before storing any request content.
5. How we use your data
We use personal data for these purposes:
- Provide and operate the service: authenticate you, route API requests, meter usage, apply quotas and rate limits, and generate the responses you request.
- Billing and accounts: process payments, issue invoices and receipts, calculate taxes, and manage subscriptions and refunds.
- Security, integrity, and abuse prevention: detect and prevent fraud, unauthorised access, abuse of the API, and violations of our Terms of Service, including rate-limit and fair-use enforcement.
- Communication: respond to your support requests, send service notices (for example, security or billing alerts), and provide essential account communications.
- Improvement and operations: aggregate, de-identified analytics about service reliability and performance (separate from the opt-in Google Analytics described in section 12).
- Legal compliance: meet our legal, accounting, and regulatory obligations, and protect our rights and the rights of others.
6. Legal basis
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your personal data on the following lawful bases under the GDPR:
| Category of data | Lawful basis |
|---|---|
| Account and usage data needed to provide the service | Performance of a contract with you (Art. 6(1)(b)), and steps taken at your request before entering a contract |
| Security, fraud prevention, and abuse detection | Our legitimate interests in protecting the service and other users (Art. 6(1)(f)) |
| Billing, tax, and record-keeping | Compliance with legal obligations (Art. 6(1)(c)) |
| Opt-in Google Analytics | Your consent (Art. 6(1)(a)), which you can withdraw at any time |
Under Singapore's PDPA, we collect, use, and disclose your personal data for the purposes described in this policy, having notified you of those purposes. Where consent is required, we obtain it and you may withdraw it (see section 11).
7. Sharing, sub-processors, and third parties
We share personal data only as described in this policy. We do not sell personal data. We use a limited set of service providers ("sub-processors") to operate the service. Current categories:
| Provider / category | Purpose | Data involved |
|---|---|---|
| Cloud & GPU infrastructure (dedicated hardware, Southeast Asia / Malaysia) | Host the service and run inference for your API requests | Request content transiently (in memory, not persisted), account identifiers, usage metadata |
| Payment processor (currently [assumed Stripe — confirm]) | Process payments and detect fraud | Card and billing data, handled by the processor under its own standards; we receive limited metadata |
| Google sign-in authentication; Google Analytics, if you opt in | Name and email (sign-in); analytics metrics only (opt-in) | |
| Email & transactional delivery | Send you service, security, and billing emails | Email address and email content |
| Error monitoring & logging tools | Diagnose incidents and service reliability | Technical metadata, error context (no prompt/output content) |
We may also disclose personal data when required by law, court order, or government request, or to protect our rights, property, or safety and that of our users and the public.
Important: your request content is processed on infrastructure we control. It is not forwarded to Zhipu AI or to any third-party model provider for inference. If that ever changes, we will say so here before it happens.
8. International data transfers
WeCoding is a Singapore company and the service runs on infrastructure located in Southeast Asia (including Malaysia). When you use the service from another country, your personal data may be transferred to and processed in Singapore and Malaysia.
Where the GDPR applies, we transfer personal data outside the EEA/UK only under appropriate safeguards, such as the European Commission's Standard Contractual Clauses (or any successor framework), and we can provide a copy of the relevant safeguards on request. Under the PDPA, we comply with the Transfer Limitation Obligation and ensure overseas recipients are bound to a comparable standard of protection.
9. Data retention
We keep personal data only as long as needed for the purposes in this policy, then delete it or anonymise it. Current retention defaults:
| Data type | Retention |
|---|---|
| Request content (prompts and outputs) | Not retained — held in memory only for the duration of the request |
| Usage metadata (request logs, token counts, status) | Approximately 90 days, for billing reconciliation, support, and abuse prevention |
| Account data | For as long as your account is active; deleted within 30 days after account closure |
| Billing, invoice, and tax records | As required by law (typically up to 7 years for tax/accounting records in Singapore) |
| Google Analytics data (opt-in) | As governed by Google's retention settings; you can disable analytics at any time |
These periods are defaults. [Confirm against your internal policy before publishing.] If you delete your account, we remove or anonymise your personal data within the periods above, except for records we must keep for legal reasons.
10. Security
We protect personal data with measures appropriate to its sensitivity:
- Encryption in transit. API traffic and website traffic use TLS.
- Secrets handling. API keys are stored hashed and are displayed in full only once, at creation.
- Access controls. Internal access to systems and data is restricted and logged.
- Dedicated hardware. Inference runs on infrastructure we control, limiting the parties that can come into contact with request content.
No service can be guaranteed perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify affected users and regulators as required by law.
11. Your rights and choices
Depending on where you live, you may have the following rights over your personal data. To exercise any of them, email privacy@wecoding.ai.
Under the PDPA (Singapore)
- Access and request a copy of the personal data we hold about you.
- Correct personal data that is inaccurate or incomplete.
- Withdraw consent you have given (where we rely on consent), and be informed of the consequences of withdrawal.
Under the GDPR (EEA, UK, Switzerland)
- Access, rectify, or erase your personal data; restrict or object to processing; and receive a portable copy.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with your local data-protection authority. (Our lead supervisory contact details are available on request.)
You will not be subject to solely automated decisions that produce legal or similarly significant effects about you.
Under US state laws (e.g., CCPA/CPRA, and similar laws)
- Know what personal data we collect and who we share it with.
- Delete your personal data.
- Correct inaccurate personal data.
- Opt out of any "sale" or "sharing" of personal data. We do not sell or share personal data for cross-context behavioural advertising.
- Limit our use of sensitive personal information. We do not collect sensitive personal information beyond what is strictly necessary to provide the service.
To make a verifiable request, email us from the address on your account. We respond within the time required by applicable law.
12. Cookies and analytics
We use a small number of cookies and similar technologies:
- Essential cookies. Required for authentication, session management, and security. These cannot be turned off if you want to use the service.
- Google Analytics (opt-in). Product-usage analytics that help us understand how the site is used. Analytics stays off until you allow it. Even when enabled, it never transmits your prompts, API keys, or payment details.
You can change your analytics choice at any time from the cookie banner or your account settings. Most browsers also let you refuse or delete cookies; note that disabling essential cookies may prevent you from signing in.
13. Children's privacy
The service is intended for developers and businesses. It is not directed at individuals under the age of 16 (or the higher age required in your country), and we do not knowingly collect personal data from them. If you believe a minor has provided us with personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. We will post the updated version here and update the "Last updated" date. For material changes, we will also provide notice (for example, by email or an in-product notice) before the change takes effect where appropriate.
15. Contact
If you have questions about this policy or your personal data, contact our Data Protection Officer:
- Email: privacy@wecoding.ai (privacy & data requests) or hello@WeCoding.dev (general)
- Entity: WeCoding Pte. Ltd., Singapore (UEN [insert])
- Registered address: [insert registered address, Singapore]
For EU/UK residents: if you are not satisfied with our response, you have the right to complain to your local data-protection authority.