MsingiAI
Back to Homepage
Legal Documentation

Privacy Policy

Last updated: August 2026

PRIVACY POLICY

Effective Date: January 2026
Last Updated: July 2026

MsingiAI, Inc. ("MsingiAI," "we," "us," or "our") is an artificial intelligence research and platform company based in Nairobi, Kenya. We build Sauti, AkiliCode, and related speech and language model infrastructure for African enterprise applications. We respect your privacy and are dedicated to protecting your personal data in accordance with the Kenya Data Protection Act, 2019 (DPA), the General Data Protection Regulation (GDPR), and international data protection standards.

This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website (msingiai.com), access our developer API portals, use our speech playgrounds, or interact with our services.


1. Data Controller & DPO Information

MsingiAI, Inc. acts as the Data Controller for personal data collected through our website and account management systems. For enterprise API processing, MsingiAI acts as a Data Processor on behalf of our customer enterprise clients.

If you have any questions about this Privacy Policy or wish to exercise your data rights, contact our Data Protection Officer (DPO):

  • Email:

    privacy@msingiai.com |

    dpo@msingiai.com

  • Headquarters: MsingiAI Operations Center, Nairobi, Kenya

  • Regulatory Authority: Registered under the Office of the Data Protection Commissioner (ODPC), Kenya.


2. Categories of Data We Collect

We collect personal data that you provide directly to us, data generated automatically through platform usage, and data provided during API transactions:

  • Account & Registration Data: Full name, professional email address, organization name, phone number, billing address, and encrypted authentication credentials.

  • Customer Content (Inputs & Prompts): Audio files, voice recordings, text strings, and prompts submitted through Sauti ASR/TTS endpoints or AkiliCode developer interfaces.

  • Generated Outputs: Speech transcripts, synthesized voice audio, translated text, and code completions produced by our models in response to Customer Content.

  • Technical & Telemetry Data: IP address, device identifiers, browser type, request timestamps, response latency, token counts, and API diagnostic error logs.

  • Commercial & Communication Data: Contact form submissions, pilot partnership inquiries, support tickets, and newsletter preferences.


3. Customer Content Non-Training Guarantee

Crucial Enterprise Guarantee: MsingiAI does NOT use Customer Content (audio recordings, text prompts, or model outputs) submitted via our commercial APIs (Sauti Enterprise API, AkiliCode API) to train, post-train, or fine-tune our foundation models without your explicit, written opt-in consent.

Audio streams processed through the Sauti Speech API are evaluated in ephemeral memory for real-time speech recognition and acoustic synthesis, and raw audio files are purged immediately following inference execution.


4. Lawful Bases for Processing

We process personal data based on the following legal grounds under Section 30 of the Kenya Data Protection Act and Article 6 of the GDPR:

  • Performance of Contract: Providing platform APIs, fulfilling subscription terms, and processing billing transactions.

  • Legitimate Interests: Securing network systems, preventing fraud, monitoring API rate limits, and optimizing model latency.

  • Legal Obligation: Complying with tax laws, legal process requests, or regulatory disclosures mandated by Kenyan law.

  • Consent: Sending promotional research updates or processing voluntary survey feedback.


5. Data Sovereignty & International Transfers

MsingiAI prioritizes African data sovereignty. Where technically available, data is stored and processed within high-security African data center infrastructure or compliant cloud regions that guarantee equivalent or greater data protection standards.

All data in transit is protected using industry-standard TLS 1.3 encryption, and data at rest is encrypted using AES-256 encryption.


6. Data Retention Period

  • Account & Billing Data: Retained for the duration of your active account plus seven (7) years to comply with statutory accounting and tax regulations.

  • Transient Inference Audio: Purged immediately from RAM after ASR/TTS response generation.

  • Diagnostic & Telemetry Logs: Retained for up to thirty (30) days for security auditing and performance monitoring before automated deletion.


7. Data Subject Rights

Subject to applicable law under the Kenya DPA and GDPR, you possess the following rights regarding your personal data:

  • Right to Access: Request confirmation and copies of personal data held about you.

  • Right to Rectification: Request correction of inaccurate or incomplete personal records.

  • Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data where no legal basis overrides erasure.

  • Right to Object & Restrict: Object to processing based on legitimate interests or request processing restrictions.

  • Right to Data Portability: Receive a machine-readable export of data provided to us.

  • Right to Lodge a Complaint: File a formal complaint with the Kenya Office of the Data Protection Commissioner (ODPC) at odpc.go.ke.


8. Third-Party Sub-processors

We work with trusted third-party service providers who assist in operating our infrastructure (e.g., cloud compute providers, secure payment gateways, and error monitoring tools). All sub-processors are bound by strict Data Processing Agreements (DPAs) requiring equal or greater privacy protection standards.


9. Updates to This Policy

We may update this Privacy Policy periodically to reflect technological advancements, legal amendments, or operational changes. Material changes will be communicated via email or prominent platform banners prior to taking effect.