Privacy Policy
Last updated: August 2026
Our Privacy Commitment — Zero Data Retained
Z-Forge operates on a Zero Data Retained (ZDR) principle. Your prompts and model responses are never stored, logged, or used for training. They pass through our routing layer in real-time and are immediately discarded. We do not retain, cache, or persist prompt content or model output at any point in our infrastructure. Your game's IP stays yours.
1. Company Information
This Privacy Policy is published by ZEUSER PTE. LTD., a company registered in Singapore under registration number 202222366K, with its registered address at 30 PETAIN ROAD, SINGAPORE 208099. We are the data controller of your personal data for the purposes of the Singapore Personal Data Protection Act (PDPA).
Our Data Protection Officer can be contacted at dpo@zeuser.ai.
2. Data We Collect — And What We Don't
What we collect:
- Email address — for account identification and support
- Password hash — stored as bcrypt hash, never in plaintext
- API key — for authentication, stored hashed in our database
- Subscription status — plan tier, billing period, payment status (processed by Stripe)
- Ephemeral rate-limit counters — token counts held in memory for the duration of your billing window, then discarded. Not written to disk.
What we do NOT collect:
- Credit card numbers or banking details (handled entirely by Stripe)
- Prompt content or model responses — never stored, logged, cached, or persisted in any form
- Your real name, phone number, or physical address
- Your game project files or source code
- Tracking data for advertising or analytics
- Your IP address (used only for real-time rate limiting, never stored)
- API request logs or response logs of any kind
3. How We Use Your Data
We use your data solely to:
- Authenticate your API requests and enforce plan token limits in real-time
- Process subscription payments via Stripe
- Send service notifications (billing, security, maintenance)
- Respond to your support requests
We do not use your data for:
- Training or fine-tuning AI models
- Marketing to third parties or selling your data
- Building user profiles or behavioral tracking
- Sharing with advertisers
- Providing usage analytics dashboards — we have no usage data to show because we do not store it
4. Data Retention — Zero Data Retained Policy
Our retention policy is simple: if we don't need it to operate the Service, we don't store it.
5. Third-Party Services
We use the following third-party services, each governed by their own privacy policy:
- Stripe — payment processing. Stripe collects your payment method details and transaction data. We receive only your subscription status and payment outcome. See Stripe's Privacy Policy.
- Upstream model providers (Anthropic, OpenAI, Google, xAI, DeepSeek) — we route your prompts to these providers to generate responses. Your prompt content is transmitted to them in real-time. Z-Forge does not store, cache, or log the prompt or response at any point. Each provider's retention policy applies to their own infrastructure; we encourage you to review their policies.
6. Data Security
We implement the following security measures:
- All data in transit is encrypted via HTTPS/TLS 1.3
- Passwords are hashed using bcrypt (10 rounds)
- API keys are stored in hashed form, never returned in full after generation
- Database access is restricted to authorized personnel
- No payment data is stored on our servers (handled by Stripe)
- Prompt and response data never touches persistent storage — it exists only in memory during routing
- Regular security reviews and penetration testing
7. Data Storage Location
Your account and billing data is stored on servers located in Singapore. Prompt and response content is never stored anywhere — it passes through our routing layer in real-time and is immediately discarded. Upstream model providers process your prompts in their respective regions (United States, Europe, or Asia-Pacific) in real-time; we do not transfer your personal data to any jurisdiction that does not provide a comparable standard of data protection to the Singapore PDPA.
8. Your Rights Under PDPA
Under the Singapore Personal Data Protection Act (PDPA), you have the right to:
- Access — request a copy of the personal data we hold about you
- Correction — request correction of inaccurate or incomplete data
- Withdrawal of consent — withdraw consent for data processing at any time
- Deletion — request deletion of your account and associated data
- Data portability — request export of your usage data in a machine-readable format
Given our minimal data practices, most requests can be fulfilled immediately. To exercise any of these rights, contact our Data Protection Officer at dpo@zeuser.ai. We will respond within 30 days.
9. Data Breach Notification
In the event of a data breach that is likely to result in significant harm to you, we will notify you and the Personal Data Protection Commission (PDPC) as soon as practicable, in accordance with our obligations under the PDPA.
10. Cookies
We use only essential cookies for authentication and session management. We do not use tracking cookies, advertising cookies, or third-party analytics. No cookie data is shared with third parties.
11. Children's Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, contact us and we will delete it immediately.
12. Changes to This Policy
We may update this Privacy Policy at any time. We will notify you by email of any material changes at least 30 days before they take effect. The effective date above reflects the last revision.
13. Contact
For privacy questions or data requests: