Singularby Mattom
ArchitectureBenchmarksPricingDocumentationFAQ
Join waitlist

On this page

  1. 1. Overview
  2. 2. Information We Collect
  3. 3. Legal Bases for Processing (GDPR)
  4. 4. How We Use Your Information
  5. 5. Sub-processors and Third Parties
  6. 6. International Data Transfers
  7. 7. Data Retention
  8. 8. Your Rights
  9. 9. Security
  10. 10. Cookies and Similar Technologies
  11. 11. Children's Privacy
  12. 12. Changes to This Policy
  13. 13. Contact Us

Last updated: July 2026

Privacy Policy

1. Overview

This Privacy Policy explains how Singular ("we", "us"), a Mattom product, collects, uses, and protects your information when you use our website and the Singular context-optimization service (the "Service"). We operate globally and design our practices to meet the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA).

Singular is a Mattom product. For any privacy question, contact us at privacy@mattom.io.

2. Information We Collect

  • Account data: name, email, organization, and authentication credentials

(passwords are hashed; never stored in plain text).

  • Usage data: API key identifiers, request metadata, token counts, model routes,

latency, and billing events. This data is privacy-safe: it describes what happened, not what was sent.

  • Content you process: prompts and context sent through the Service. Singular does

not store the content of your requests beyond what is strictly required to deliver the Service and the retention period you configure. We never use your prompts or context to train or improve models.

3. Legal Bases for Processing (GDPR)

For users in the EU and UK, we process personal data under the following Article 6 bases:

  • Performance of a contract — to deliver the Service you signed up for.
  • Legal obligation — to keep tax and billing records as required by law.
  • Legitimate interests — for security logging, abuse prevention, and service

integrity.

  • Consent — for any non-essential analytics or marketing, where you have opted in.

4. How We Use Your Information

We use your information to deliver and operate the Service, to secure and monitor it, to bill you accurately, to comply with legal obligations, and to improve the Service's reliability and performance. We do not sell your personal information, and we do not use your customer content to train models.

5. Sub-processors and Third Parties

We work with a limited set of sub-processors to run the Service:

  • Cloud infrastructure — hosting, databases, and object storage.
  • LLM providers — to which your optimized context is routed. Your request reaches

the provider you choose; the provider's own terms and retention may apply to outputs.

  • Analytics — self-hosted, cookieless analytics (no cross-site tracking).
  • Transactional email and payment processing — for account and billing

communications.

We disclose LLM provider routing because it matters: if a provider may use inputs for its own purposes, that use is governed by the provider's policy, not ours. We will notify customers of material changes to our sub-processor list.

6. International Data Transfers

Because we serve a global audience, personal data may be processed in countries other than your own. Where data is transferred from the EU or UK to a country without an adequacy decision, we rely on Standard Contractual Clauses or another lawful transfer mechanism.

7. Data Retention

We keep each category of data only as long as necessary:

  • Request metadata and logs: retained for a configurable period (default 90 days)

for security, debugging, and audit, then deleted.

  • Billing records: retained as required by tax law (typically 7 years).
  • Customer content (prompts/context): handled per your retention configuration and

deleted on a rolling basis. Deleted data is removed from active systems and purged from backups within a defined window.

8. Your Rights

Under GDPR (EU/UK), you have the right to access, rectify, erase, restrict, port, and object to the processing of your personal data, plus rights related to automated decision-making and the right to lodge a complaint with your supervisory authority.

Under CCPA/CPRA (California), you have the right to know, delete, correct, and opt out of the sale or sharing of personal information, and to limit the use of sensitive personal information. We do not sell personal information.

To exercise any of these rights, email privacy@mattom.io. We respond to verified requests within one month (GDPR) or 45 days (CCPA), as applicable.

9. Security

We protect data with encryption in transit and at rest, least-privilege access controls, managed secrets, and continuous security monitoring. See our /security page for the full overview of technical and organizational measures.

10. Cookies and Similar Technologies

We use self-hosted, cookieless analytics that does not set cross-site tracking cookies. Any strictly-necessary cookies (for example, to keep you signed in) are limited to that purpose. No consent banner is required for our current configuration.

11. Children's Privacy

The Service is not directed to children under 16, and we do not knowingly collect their personal information. If you believe a child has provided us with personal data, contact us and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notice and update the "Last updated" date at the top of the page. Continued use after a change takes effect constitutes acceptance.

13. Contact Us

For privacy questions or to exercise your rights, contact us at privacy@mattom.io.

Singularby Mattom
ArchitectureBenchmarksPricingDocumentationFAQJoin waitlistBack to Mattom
PrivacyTermsSecurity & DPA

© 2026 Singular, a Mattom product.