Last updated 1 September 2026.
Baibursai provides AI agents billed per run. We are the data controller for the account and billing information below, and a data processor for the content you send through agents. Contact us about privacy at support@baibursai.shop.
Your email address, a hashed password and your display name. We require an email so we can reach you about billing and so you can recover the account. We do not verify it at signup and we do not send marketing to it.
Records of credit purchases and per-run consumption. Card details are handled entirely by Stripe and never reach our servers; we store only Stripe's transaction identifier and the last four digits it returns for display.
The inputs you send agents and the outputs they return. Retained 30 days by default so you can review your history, then deleted. Set retention to zero and we keep only metadata.
Agent, timestamp, duration, token count, cost and status. Retained 24 months because billing records must be reconcilable.
Server logs with IP address, user agent and requested path, kept 30 days for security and abuse investigation.
| Data | Purpose | Lawful basis |
|---|---|---|
| Account data | Providing the service | Performance of a contract |
| Billing data | Charging you, tax records | Contract, legal obligation |
| Run content | Executing the run you asked for | Contract |
| Run metadata | Billing, capacity planning | Contract, legitimate interests |
| Technical logs | Security and abuse prevention | Legitimate interests |
The current subprocessor list with locations is available on request, and we give 30 days' notice before adding one. We disclose data to law enforcement only on a valid legal instrument, and we will tell you unless prohibited.
Account data is stored in the EU. Run processing happens in the EU and the US depending on the agent. Where data leaves the EEA we rely on Standard Contractual Clauses. Enterprise accounts can pin processing to one region.
Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and complain to a supervisory authority. Email us and we will respond within 30 days. We do not charge for this and there is no process designed to wear you down.
Passwords are hashed with bcrypt, API tokens are stored hashed, all traffic is TLS 1.3 and data at rest is encrypted. Access to production requires hardware-backed multi-factor authentication and is logged. The security page has the detail, including what we do not claim.
The service is not directed at anyone under 16 and we do not knowingly collect their data.
We will email account holders at least 30 days before a material change. The date at the top always reflects the current version.