Privacy Policy
Last updated: 2026-10-06
This Privacy Policy explains what personal data Muke Labs ("we") collects when you use the Muke Labs website, developer portal, and APIs, why we collect it, and the rights you have. As a Malaysia-based business, our handling of personal data is guided by the Malaysian Personal Data Protection Act 2010 ("PDPA").
Data controller: Muke Labs. Contact: support@mukelabs.com.
1. Data we collect
- Account data: email address and password credentials when you register in the portal.
- Billing data: top-up amount, currency, transaction references, and balance history. Card details are processed by our payment processor — we never see or store full card numbers.
- API usage data: request metadata (timestamps, toolId, model tier, status, error codes), the subjectId you attach, and idempotency keys.
- Content data: prompts, reference media URLs or uploads, and generated outputs stored for the retention window you select or the default policy.
- Technical data: IP address, user agent, and a small set of cookies/localStorage described in the Cookie Policy.
- Support data: messages you send us by email or through the contact form.
2. Why we process data
- To operate the Service: authenticate you, route tasks to models, charge your balance, and return results.
- To secure the Service: abuse prevention, rate limiting, fraud detection, and audit logging.
- To comply with law: accounting, tax, and responding to lawful requests.
- To communicate: service notices, security alerts, and — only if you opt in — product updates.
3. Legal bases
Where the PDPA applies we process personal data to perform our contract with you, to comply with legal obligations, and for our legitimate interests in a secure and reliable Service. Where the GDPR/UK GDPR applies to you, the equivalent bases are Art. 6(1)(b), (c), and (f).
4. Sub-processors and disclosures
We use a small set of service providers to run the Service, and disclose personal data only as needed for them to perform their function.
- Cloudflare — hosting, CDN, DDoS protection (global, incl. the EU/US).
- Supabase — authentication and database hosting (AWS ap-southeast-1, Singapore).
- Stripe — payment processing for balance top-ups.
- Resend — transactional email delivery.
- The model vendors that fulfill generation requests receive your prompts and reference inputs. Inputs are disclosed to vendors only at the moment a task is dispatched; vendors are not authorized to use them for their own purposes beyond fulfilling the task.
5. Retention
- Account and billing records are kept while your account is active and for up to 7 years afterward where required by accounting and tax law.
- Generated outputs and associated inputs are stored for the retention window you select at task creation (default 30 days) and then deleted.
- Security and abuse logs are retained for up to 12 months.
- Support correspondence is retained for up to 24 months.
6. Your rights
Depending on the law that applies to you, you may have rights to access, correct, delete, or port your personal data, to object to or restrict processing, and to withdraw consent where processing is based on consent. To exercise any right, email us at the address below. We respond within the time required by applicable law — no longer than 30 days under the GDPR and without undue delay under the PDPA.
If you are in the EU/UK you may also complain to your local supervisory authority; in Malaysia, to the Personal Data Protection Commissioner.
7. Security
We use encryption in transit (TLS), access controls, and audit logging to protect personal data. No method of transmission or storage is perfectly secure — if we learn of a breach that affects your rights we will notify you and the relevant authority as required by law.
8. International transfers
Your data may be processed in Singapore and other countries where our sub-processors operate. We rely on contractual safeguards to ensure an adequate level of protection for cross-border transfers.
9. Changes
We may update this policy and will post changes here with a new "Last updated" date. Contact: support@mukelabs.com.