FinanceGadget
Provider dossier

Moonshot AI (Kimi)

What Moonshot AI (Kimi) commits to on training use, retention, data residency and API terms, with a model inventory keyed to AI Act deadlines.

Terms read 1 August 2026 · tier assessed: Kimi Web/App (consumer) and Moonshot Open Platform API · by Haileslassie Desalegn

Governance and contractual terms

Training use (default)
Consumer Kimi Chat (Web/App): yes, processed for service improvement by default. Moonshot API: no, off by default for paid commercial API calls per platform terms.
Retention
Consumer: retained until deleted by user; API: 30 rolling days for abuse monitoring unless custom retention terms apply.
Opt-out
Consumer: available via account privacy settings; API: default opt-out applies to paid commercial calls.
Data residency
Mainland China data centers for domestic infrastructure; Singapore / cloud nodes for international API traffic
Sub-processor list
Unverified — no public third-party sub-processor registry published
DPA available
Unverified — standard GDPR Art. 28 DPA not published for self-serve consumer or API tiers
Contracting entity
Beijing Moonshot AI Technology Co., Ltd. (Mainland China); Moonshot AI Pte. Ltd. (Singapore for international operations)
EU contracting entity
Unverified — no dedicated EU subsidiary or EU GDPR representative listed in primary terms
Governing law
Mainland China (Beijing courts) for domestic terms; Singapore law and courts for international API services
Certifications
Unverified
AI Act Code of Practice
no
Vulnerability disclosure
Unverified — security contact email published (security@moonshot.cn), no public bug bounty page found
Documented incidents
None confirmed in primary sources

Model inventory

Listed by the AI Act deadline each model falls under, which depends on when it was placed on the EU market rather than on its capability. No benchmark scores — why not.

Model API identifier EU availability AI Act deadline Covered by DPA
Kimi K3
Flagship long-context reasoning model series with multimodal capabilities.
kimi-k3 Unverified 2 Aug 2026 Unverified
Kimi K1.5
Multimodal and long-context inference model family.
kimi-k1.5 Unverified 2 Aug 2027 Unverified
Moonshot-v1
Base long-context model available in 8k, 32k, and 128k context windows.
moonshot-v1-128k Unverified 2 Aug 2027 Unverified

Who you are contracting with

Moonshot AI operates through Beijing Moonshot AI Technology Co., Ltd. (月之暗面) for services within Mainland China, and Moonshot AI Pte. Ltd. (Singapore) for international API and web services.

Unlike US and European providers operating in the EU market, Moonshot AI does not currently maintain a dedicated EU operating subsidiary or publish a named GDPR Article 27 representative. Contracts for international users are governed by Singapore law and subject to the jurisdiction of Singapore courts.

Training use and retention

The data usage terms follow a standard split between consumer interfaces and developer API infrastructure:

  • Kimi Web & App (Consumer Tiers): Prompts, uploaded documents, and chat interactions are processed to operate and improve the model by default. Users can request data deletion or adjust privacy controls in account settings, but consumer usage is subject to Chinese domestic internet regulations and algorithm filing requirements.
  • Moonshot Open Platform (API Tiers): Commercial API terms state that customer content submitted via paid API endpoints is not used to train public foundation models without explicit customer consent.

Standard API logs are retained for 30 rolling days to monitor platform security, prevent abuse, and satisfy legal compliance obligations.

Data residency and cross-border transfers

Domestic data infrastructure is hosted in Mainland China under the supervision of the Cyberspace Administration of China (CAC), in compliance with China’s Data Security Law and Personal Information Protection Law (PIPL).

International API traffic routed through Singapore endpoints undergoes cross-border data transfer safeguards where applicable, but Moonshot AI does not currently offer contractual EU-only data residency or in-region EU GPU inference guarantees.

Certifications and compliance posture

Moonshot AI has completed domestic regulatory filings in China under the Interim Measures for the Management of Generative AI Services. However, it does not currently publish Western compliance artifacts such as SOC 2 Type II reports or ISO/IEC 27001 certificates on an open trust portal.

Furthermore, Moonshot AI is not a signatory to the European Union’s General-Purpose AI Code of Practice under the EU AI Act.

Summary for enterprise evaluation

For European and international engineering teams working under strict GDPR, ISO 27001, or client NDA obligations:

  1. Conduct a Transfer Impact Assessment (TIA) before sending proprietary source code or personal data to non-EU/non-US jurisdictions.
  2. Utilize API endpoints exclusively rather than consumer web chats if testing Kimi models, ensuring paid API data non-training clauses apply.
  3. Redact PII and credentials upstream prior to API invocation, as formal GDPR Article 28 DPAs are not self-serve on the platform.

For a broader evaluation framework across global vendors, see our guide on how to judge an AI provider.