Rainspeed LabsAll terms & policies

Rainspeed Labs / Legal

Privacy Policy

How Rainspeed Labs collects, uses, discloses and protects personal data.

Last updated: 12 August 2026

1. Scope and data controller

This Privacy Policy explains how Rainspeed Labs Solutions (business registration number 202603148143 (003857582-W)), Malaysia handles personal data when you use the websites, applications, software, APIs, developer platform, AI tools, local coding tools and support services made available by Rainspeed Labs, including AtlasFlux AI, AtlasFlux API & Platform, ONeNas Code and AtlasFlux Support. Rainspeed Labs is the data controller for processing where it determines the purpose and means of processing, unless a product or business agreement states that we act as a processor for a customer. A provider that you select directly may be a separate controller for its own processing.

This is one ecosystem-wide policy. The data involved depends on the product, feature, account, provider and configuration that you use. Product notices and the Subprocessors page provide additional detail where available.

2. Personal data you provide

  • Account and identity data, such as your name, email address, username, profile information, Clerk identifier, avatar, language, theme and other preferences.
  • Content, such as prompts, conversations, messages, files, code, images, audio, video, generated material, community posts, comments, support tickets, replies and information selected from a local workspace for a connected operation.
  • Developer data, such as API key name, prefix, one-way hash, scopes, origin restrictions, expiry, model selections, application settings, wallet settings and integration information. The complete API secret is not intended to be stored after it is shown to you.
  • Payment and transaction data, such as billing contact details, amount, currency, payment status, Stripe customer and payment-method identifiers, transaction references, refunds, disputes, receipts and webhook records. Complete card details are handled by Stripe rather than stored directly by Rainspeed Labs.
  • Support and communication data, such as ticket subjects and messages, replies, internal routing, attachments, attachment names and checksums, notifications, email content, delivery status and messages sent to us.
  • Information provided when you request access, correction, export, deletion, consent withdrawal, an appeal or other assistance.

3. Data generated when you use the Services

  • Usage and billing information, such as features used, models selected, provider route, request times, token or media usage, search counts, Credits or wallet amounts reserved or charged, job status, output references, latency, errors and account activity.
  • Technical and security information, such as IP address or IP-derived values where collected, browser or device information, operating system, request identifiers, timestamps, authentication events, rate-limit events, failed access attempts, policy flags and suspected credential exposure.
  • Operational records, such as provider attempts, usage aggregates, payment and refund records, Stripe webhook payloads, support routing, email outbox and delivery events, Help Center views, raw Help Center search queries, article feedback, audit events and security events.
  • ONeNas local state, such as local sessions, project files, configuration and locally stored authentication state. This remains on the device unless you select a connected operation or managed provider that transmits selected data.

4. How we use personal data

  • Provide, authenticate, maintain and secure the Services, including account access, model routing, local-agent authorisation, support and feature operation.
  • Process prompts, files, media, API requests, searches, tool calls, local-agent connections and other operations you request.
  • Calculate usage, reserve and charge Credits or wallet balance, process payments, issue eligible adjustments, provide receipts and reconcile transactions.
  • Provide support, send transactional service communications, operate the Help Center and investigate technical or account issues.
  • Protect users and the Services, detect abuse, apply moderation and rate limits, prevent fraud, investigate security incidents and enforce policies.
  • Debug and improve reliability, accessibility, performance and safety using operational, security and feedback information.
  • Comply with legal, accounting, tax, regulatory and dispute-resolution obligations.

5. Content and model processing

When you request an AI, search, media, file or sandbox operation, the Input and context needed for that operation may be sent to the configured provider. The provider may depend on the selected model, tool, product and current routing configuration.

AtlasFlux AI and its agent services can send prompts or selected context to OpenRouter and, for configured operations, directly to Anthropic, Replicate, WaveSpeedAI, ILMU, OpenAI, Exa, Tavily, ScrapingFish or scrape.do. AtlasFlux API requests are routed through the configured API provider and search provider. Search queries and selected public URLs may therefore be transmitted to external search or retrieval providers. The exact provider depends on the feature, selected model and current routing configuration; the Subprocessors register identifies material providers.

The Support AI agent can send the conversation, page context and tool results to OpenRouter. Where the Customer 360 feature is enabled, that tool result can include the current user's AtlasFlux profile, recent credit information, wallet information, API-key metadata and recent API usage. The lookup is keyed to the signed-in user's Clerk ID and is read-only.

When ONeNas uses the managed AtlasFlux provider, prompt and assistant text may be written to AtlasFlux session and event records. When you configure a direct provider, the selected content is sent to that provider under your configuration and its privacy policy.

Rainspeed Labs does not use Content for a general-purpose model-training programme unless the relevant product notice or a separate agreement says otherwise. This does not mean that an upstream provider never retains, reviews or trains on Content. Review the applicable provider terms and privacy notices, and do not submit secrets or regulated data unless authorised and appropriate.

6. Local files and connected software

Opening a local project in ONeNas Code does not by itself upload the complete project to Rainspeed Labs. Local files, terminal commands and local sessions are controlled by the operating system and the permissions available to the software.

A connected model, relay, tool or action may transmit the prompt, selected files or context, instructions, status and Output needed for that operation to Rainspeed Labs and the configured providers. Review the selected context and operation before sending it.

ONeNas local execution is not a security sandbox. The local permission model helps you review actions but does not provide isolation from a malicious command or project. Use least privilege, backups and a trusted environment.

7. Community and public Content

Content you publish through a community or public feature can be viewed, copied or retained by other users. It may be associated with your username, avatar, prompt, model, settings or reference media according to the feature. Deleting an account does not necessarily remove copies made by others or public material that must remain for legal, safety or dispute purposes.

Remove public Content before closing an account where the relevant controls are available. Some generated media and artifacts may also be reachable through public object URLs; do not upload material that must remain private to a feature that serves public URLs.

8. How we disclose personal data

We disclose personal data to providers that perform functions for the relevant Service, including authentication, hosting, databases, object storage, model inference, search, media processing, payments, email, webhook verification, documentation retrieval and sandbox execution. The Subprocessors page identifies the material providers evidenced in the current architecture.

Support may read limited account information from the AtlasFlux AI and AtlasFlux API systems through a server-side, read-only Customer 360 lookup when that feature is enabled. This lookup is restricted to the signed-in user's Clerk ID.

We may disclose information to professional advisers, regulators, courts, law enforcement or other parties where reasonably necessary to comply with law, protect rights and safety, investigate fraud or respond to valid legal process. If Rainspeed Labs is involved in a merger, financing, reorganisation, sale of assets or transfer of a Service, information may be disclosed subject to applicable confidentiality and legal requirements.

We do not sell personal data for advertising. We do not use the Services as an advertising profile or targeted-advertising service.

9. Retention

There is no single retention period for the whole Rainspeed Labs ecosystem. We retain records for as long as reasonably necessary for the feature, security, support, accounting, dispute or legal purpose, and then delete or anonymise them where the applicable system and reason allow.

Certain unpinned generated media and completed or failed media jobs have a 30-day cleanup target. Pinned, published, community, billing, safety, support and legally required records follow different rules. Cleanup depends on the relevant storage and maintenance process, so this is a target rather than a guarantee that every object is removed at exactly 30 days.

The AtlasFlux API retention policy targets 90 days for API request records and 7 days for idempotency records, while financial ledgers are retained separately. Actual deletion may depend on an authorised maintenance process, so records can remain longer than the target. A completed non-streaming response may be present in an idempotency record during that period.

AtlasFlux Support has a 24-hour cleanup eligibility period for abandoned, unverified staged attachment uploads. Tickets, replies, notes, notifications, email records, Help Center search and feedback records, audit events and security events may not have a general automatic expiry. Support customers can delete eligible agent conversations and unattached uploads, but other Support records may require a rights request or separate support process.

Some AtlasFlux AI export links or keys are intended to expire after 48 hours. Export scope is feature-dependent and an export may not contain every database record, stored object or record held by another product. Ask Support if a rights request requires information outside an available export.

ONeNas local files and local history are normally controlled by the user and the device. Managed ONeNas session and event records are subject to the retention of the connected AtlasFlux service. Billing, deletion-audit, fraud-prevention, security, support, backup and legal records may be retained longer where necessary or required.

10. Account closure, deletion and data rights

Depending on the product, you may request access, correction, deletion, restriction, objection, portability or withdrawal of consent, subject to applicable law and exceptions. We may need to verify your identity and authority. For a product or account request, use the AtlasFlux Help Center at https://support.atlasflux.my; for correspondence addressed directly to the data controller or company, use hello@rainspeedlabs.com. Do not send passwords, API keys or other secrets.

Support coordinates the centralized account-deletion workflow at https://support.atlasflux.my/dashboard/settings. The flow verifies the account email, sends a time-limited verification code, requires the confirmation text DELETE MY ACCOUNT and presents a final Yes/No confirmation before deletion begins. Once confirmed, Support coordinates eligible deletion across AtlasFlux AI, AtlasFlux API & Platform, AtlasFlux Support and the shared Clerk identity, signs the user out and sends a completion email where delivery is available. The workflow is intended to cover eligible account data across the connected services. It does not necessarily remove public community copies, provider-side copies or records that Rainspeed Labs must retain for billing, accounting, tax, consent, safety, support, fraud prevention, disputes, audit or legal compliance. Financial ledgers, payment transactions, Stripe event records, deletion-audit records and related legal or security records may therefore remain after account deletion.

Deleting a Support AI conversation or an eligible unattached attachment separately is different from deleting the account and does not by itself delete tickets, replies, email records or security records.

If a self-service control is unavailable, contact the AtlasFlux Help Center at https://support.atlasflux.my. We will assess the request under the law applicable to the requester, the product and the record concerned.

11. Security

We use measures appropriate to the relevant Service and risks, including Clerk authentication, API-key hashing, scoped access, wallet transaction controls, Stripe webhook signature verification, rate limiting, secret redaction, signed URLs and file validation for Support attachments, and security headers where configured.

These measures are not a guarantee of absolute security. Some AtlasFlux AI media and artifact URLs are public by design, ONeNas local execution is not sandboxed, and automated secret redaction cannot detect every sensitive value. Protect credentials, review provider settings and notify us promptly of suspected compromise.

12. International processing

Rainspeed Labs operates from Malaysia and uses providers and infrastructure that may process data in other countries. The location depends on the product, provider, deployment and account configuration. The current AtlasFlux API deployment uses Singapore as its Fly.io primary region; other provider and database regions can differ.

Where applicable law requires a safeguard for an international transfer, we will take a permitted step required by that law. We do not claim that every Service uses the same transfer mechanism; the relevant provider and agreement determine the applicable details.

13. Cookies and similar technologies

Hosted Services use authentication, security, preference and core-operation cookies or similar technologies. The Cookie Policy describes the confirmed product-specific technologies. The Services do not have one shared cookie banner or one universal consent implementation.

14. Children

AtlasFlux AI is intended for users aged thirteen (13) or older, or the higher digital-consent age that applies in the user's country. The other Services may have different age or organisational requirements stated in their product notice or documentation. Do not submit a child's personal data unless you are authorised and the relevant Service permits it. If you believe a child has provided personal data unlawfully, contact the AtlasFlux Help Center at https://support.atlasflux.my.

15. Changes and contact

We may update this Privacy Policy when our Services, providers or legal obligations change. The updated date identifies the current version. We will provide notice of a material change where required.

The data controller is Rainspeed Labs Solutions (business registration number 202603148143 (003857582-W)), Malaysia. Product privacy questions and rights requests may be submitted through the AtlasFlux Help Center at https://support.atlasflux.my. Corporate or controller correspondence may be sent to hello@rainspeedlabs.com.

For a privacy, data-protection or suspected personal-data breach concern, use the Help Center or email hello@rainspeedlabs.com with the subject "Privacy / Data Protection". Rainspeed Labs will route the request to the responsible privacy contact or Data Protection Officer where one is appointed. This contact channel does not replace any right to complain to the relevant regulator.

The privacy contact will coordinate the assessment, containment, investigation and documentation of a suspected personal-data breach. Where a breach meets a notification threshold under applicable law, Rainspeed Labs will notify the relevant regulator and affected individuals within the timeframe and in the manner required by that law. A security event, blocked request or attempted credential exposure is not necessarily a personal-data breach requiring notification.

<- Back to terms & policies