MEGARIDER

Privacy notice.

How information moves through the MegaRider service.

Effective 7 September 2026. Contact: hello@megarider.pro.

Scope and operator

This notice covers the MegaRider website and API. The contracting operator and applicable business details are identified in your service agreement before paid onboarding. Contact us for the identity and contact details relevant to your engagement.

Website

The website uses locally hosted fonts and assets. We do not use advertising trackers, analytics cookies or a third-party chat widget. Network providers may process connection metadata to deliver this website. Email links open your own mail application. Our online access form stores your name, email, optional company, use case, expected volume and consent acknowledgment so we can review your application. It does not create an API key automatically. Application notifications are delivered to our own hosted mailbox. Our fallback contact, independ.app@proton.me, is handled by Proton.

API processing

Prompts and completions pass through our gateway in memory to deliver the requested inference. Our application does not persist their text and does not use them to train models. The gateway stores request IDs, timestamps, model IDs, integration identifiers, token usage, timing, outcome, errors and billing metadata. API keys are used for authentication and are not included in request logs.

Infrastructure partners

MegaRider operates its API gateway on a rented virtual server. Model inference is supplied through OpenBroker and the Gonka network. Request content is transmitted to those services for processing. Their operators and network participants may apply separate logging, retention and processing practices. We have not established an end-to-end zero-retention or training exclusion commitment across that infrastructure. Do not submit data requiring such a commitment without a separate written agreement.

Account administration and mail

API keys created in the control panel are stored as cryptographic hashes; the complete key is shown only when it is created. We store key names, permissions, quotas, usage and expiry for access control. Admin and Roundcube webmail sessions use secure HTTP-only cookies, which are necessary for those private interfaces. Roundcube stores mailbox preferences, contacts and session data on our server. Application records and internal review notes are visible only to authorized administrators. Our own mail server stores received messages and mail delivery metadata; messages are processed by Postfix, Dovecot, Rspamd and antivirus services. A copy of an application notification may therefore exist in the operator mailbox.

Retention and purposes

Operational request metadata is kept for up to 90 days for support, abuse investigation and usage reconciliation. Local backup copies expire within 7 days after creation. Separately finalized accounting records may be retained where required by the applicable agreement or law. Access applications and admin audit records are retained for up to 365 days. Email is kept while needed for the correspondence, account relationship or a legitimate recordkeeping obligation. Key records and unresolved usage reservations are retained while needed for active access or reconciliation.

International processing

Inference may be processed in multiple countries. A specific processing region is not guaranteed. Contact us before sending regulated, confidential or sensitive personal data so the required terms and safeguards can be assessed.

Choices and requests

You may contact us to ask about access, correction, deletion, retention or an objection to processing. We may need to verify your identity and account authority. We respond according to the laws applicable to your relationship with us; billing and legal obligations may limit deletion. Where applicable, you may contact your data protection authority.

Updates

Material changes will be reflected here with a new effective date and, for active partners, communicated through the agreed contact channel.