LINCORELINK Privacy Policy

Last updated: 15 June 2026

This Privacy Policy explains how LINCORELINK AI PTE. LTD. collects, uses, discloses and protects personal data when you use the lincorelink AI API gateway. Please read it carefully, in particular Section 4 (How your prompts are processed), which describes the transfer of your request content overseas to a model provider located in China.

1. Who we are and how to contact us

lincorelink is an AI API gateway operated by LINCORELINK AI PTE. LTD., a private company limited by shares incorporated in Singapore ("we", "us", "our", or the "Company"). For the purposes of the Singapore Personal Data Protection Act 2012 (the "PDPA"), we are the organisation responsible for the personal data described in this policy.

We are an independent relay and reseller. We are not affiliated with, endorsed by, or sponsored by DeepSeek or any other model provider; provider names are used only to identify the upstream models we relay to. The availability, behaviour and outputs of those models are controlled by the provider, not by us.

For all privacy and data-protection matters — including requests to access or correct your data, to withdraw consent, or to raise a concern — you may contact our Data Protection Officer by email at support@lincorelink.ai. This is our single contact point for data requests; we do not operate a separate self-service privacy portal.

2. Personal data we collect

We collect and process the following categories of personal data:

Payment-card data is collected by Paddle, not by us. When you pay, your card details are entered into and handled by Paddle (see Section 5). We do not store full card numbers.

We collect personal data directly from you when you create an account, use the API, or contact us, and automatically through the operation of the service (for example, usage logs and security signals).

3. How and why we use your data (purposes and legal bases)

Under the PDPA, we notify you of the purposes for which we collect, use and disclose your personal data, and we limit our processing to purposes a reasonable person would consider appropriate in the circumstances. By creating an account and using the service after being given this notice, you consent to the processing described here. Where the EU/UK General Data Protection Regulation ("GDPR") applies to you, the corresponding legal bases are indicated in brackets.

We do not use your personal data for advertising, and we do not sell it.

4. How your prompts are processed (international transfer to China)

This section is important. Please read it before using the API.

When you call the API, the content of your request — your prompts and any data you include in them — is forwarded to the upstream model provider so that a response can be generated. The current provider is DeepSeek, whose infrastructure is located in the People's Republic of China.

This means your request content is transferred to and processed in China, where it is handled subject to DeepSeek's own privacy and data-handling policies, which we do not control. This is an overseas transfer of personal data for the purposes of the PDPA's Transfer Limitation Obligation. By using the API, you consent to this transfer.

You must not submit any data that you are not permitted to transfer internationally, or that you are not authorised to share with a third-party model provider located in China. You are responsible for ensuring you have the rights and permissions needed to send the data you include in your requests.

Requests are routed through Cloudflare AI Gateway, and request and response content may be logged for a limited period as described in Section 8. The model's behaviour and outputs are determined by the provider, not by us.

5. Payments

All payments are processed by Paddle (Paddle.com Market Limited) acting as the Merchant of Record and authorised reseller. Paddle is the seller of record for each transaction, is responsible for billing and for charging and remitting applicable taxes (such as VAT, GST or sales tax), and is the controller of your payment-card data.

Because Paddle is the merchant of record, your purchase is also subject to Paddle's own buyer terms and privacy notice. We receive transaction and subscription information from Paddle that we need to credit your balance and maintain your account, but we do not store full card numbers. For more on how billing and refunds work, see our Refund Policy and Terms.

6. Sub-processors and other third parties

We share personal data with the following service providers and recipients, each only to the extent needed for the purpose described:

We may also disclose personal data where required to comply with applicable law, legal process or a lawful request from a competent authority, or to establish, exercise or defend legal claims.

7. Cookies, Turnstile and similar technologies

We use cookies and similar technologies that are necessary to operate the service — for example, to keep you signed in and to maintain your session. We use Cloudflare Turnstile, a privacy-focused bot-detection tool, to distinguish genuine users from automated traffic; Turnstile may set its own challenge tokens and process limited technical signals (such as your IP address) for this purpose.

We do not use cookies or similar technologies for advertising or cross-context behavioural tracking.

8. Logging and data retention

API requests are routed through Cloudflare AI Gateway. Request and response payloads and related metadata may be logged for debugging, billing and abuse prevention. These logs are retained for up to 30 days and are then deleted, unless a longer period is required to comply with applicable law or to establish, exercise or defend legal claims (for example, to resolve a dispute).

Account data is retained while your account is active and for a reasonable period afterwards, as required to meet our legal, tax and accounting obligations. We cease to retain personal data, or remove the means by which it can be associated with you, when it is no longer needed for the purposes for which it was collected and there is no remaining legal or business reason to keep it.

9. How we protect your data

We maintain reasonable security arrangements designed to protect personal data in our care against unauthorised access, collection, use, disclosure, copying, modification or disposal, including:

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If a data breach affecting your personal data occurs, we will assess and handle it in accordance with our obligations under the PDPA's Data Breach Notification Obligation, including notifying the Personal Data Protection Commission and affected individuals where the breach is notifiable and within the timeframes required by law.

10. International and overseas transfers

We are based in Singapore, but the service relies on providers located outside Singapore, including in the United States and the People's Republic of China. When we transfer personal data overseas, we do so in accordance with the PDPA's Transfer Limitation Obligation.

The principal overseas transfer is described in Section 4: the content of your API requests is transferred to and processed by DeepSeek in China, subject to DeepSeek's own policies, which we do not control. We rely on your informed consent to this transfer and on the fact that the transfer is necessary to perform the service you request. We do not claim that this transfer is covered by an adequacy decision or by standard contractual clauses, and we do not guarantee that the recipient applies a standard of protection comparable to the PDPA. You remain responsible for not submitting data you are not permitted to transfer internationally.

Other transfers (for example, to Cloudflare, Paddle and Resend) are made to providers that handle personal data under their own contractual commitments and applicable safeguards, for the limited purposes set out in this policy.

11. Your rights

Under the PDPA (all users). You may request access to the personal data we hold about you and information about how it has been used or disclosed within the year before your request, and you may request correction of any data that is inaccurate or incomplete. You may also withdraw your consent to our continued collection, use or disclosure of your personal data, on reasonable notice; if you do, we may be unable to continue providing the service. Certain statutory exceptions to access and correction may apply, and certain logs are automatically deleted on the cycle described in Section 8. To make a request, email support@lincorelink.ai.

For users in the EEA and the UK (GDPR). Where the GDPR applies to you, you also have the rights to access, rectification, erasure, restriction of processing, data portability, and to object to certain processing, as well as rights relating to automated decision-making. You may withdraw consent at any time (without affecting processing already carried out on the basis of consent before its withdrawal) and may lodge a complaint with your local supervisory authority (for UK users, the Information Commissioner's Office). The legal bases on which we rely are set out in Section 3.

For California residents (CCPA/CPRA). Where the CCPA/CPRA applies to you, you have the rights to know/access, delete, and correct your personal information, to opt out of the sale or sharing of personal information, to limit the use of sensitive personal information, and to non-discrimination for exercising your rights. We do not sell or "share" personal information for cross-context behavioural advertising. The categories of personal information we collect, the purposes for which we use them, and the service providers to whom we disclose them are described in Sections 2, 3 and 6.

To exercise any of these rights, contact us at support@lincorelink.ai. We will respond within the time required by applicable law and will not discriminate against you for exercising your rights. We may need to verify your identity before acting on a request.

12. Children

The service is intended for users who can form a legally binding contract. It is not directed to children, and we do not knowingly collect personal data from anyone under 18 years of age (or the age of majority in the user's jurisdiction). If you believe a child has provided us with personal data, please contact us at support@lincorelink.ai so that we can take appropriate action, including deleting the data.

13. Changes to this policy

We may update this Privacy Policy from time to time, for example to reflect changes in our service, our providers, or applicable law. When we make material changes, we will update the version available at /privacy and revise the "last updated" date shown with this policy, and we will take reasonable steps to notify you. Where applicable law requires your consent to a new or changed purpose, we will seek that consent before relying on it. Your continued use of the service after an updated policy takes effect indicates your acknowledgement of the changes.

14. Contact us

If you have any questions about this Privacy Policy or how we handle your personal data, or if you wish to exercise any of your rights, please contact our Data Protection Officer:

LINCORELINK AI PTE. LTD. (Singapore) — support@lincorelink.ai.