Moonshot AI (Kimi)
What Moonshot AI (Kimi) commits to on training use, retention, data residency and API terms, with a model inventory keyed to AI Act deadlines.
Governance and contractual terms
- Training use (default)
- Consumer Kimi Chat (Web/App): yes, processed for service improvement by default. Moonshot API: no, off by default for paid commercial API calls per platform terms.
- Retention
- Consumer: retained until deleted by user; API: 30 rolling days for abuse monitoring unless custom retention terms apply.
- Opt-out
- Consumer: available via account privacy settings; API: default opt-out applies to paid commercial calls.
- Data residency
- Mainland China data centers for domestic infrastructure; Singapore / cloud nodes for international API traffic
- Sub-processor list
- Unverified — no public third-party sub-processor registry published
- DPA available
- Unverified — standard GDPR Art. 28 DPA not published for self-serve consumer or API tiers
- Contracting entity
- Beijing Moonshot AI Technology Co., Ltd. (Mainland China); Moonshot AI Pte. Ltd. (Singapore for international operations)
- EU contracting entity
- Unverified — no dedicated EU subsidiary or EU GDPR representative listed in primary terms
- Governing law
- Mainland China (Beijing courts) for domestic terms; Singapore law and courts for international API services
- Certifications
- Unverified
- AI Act Code of Practice
- no
- Vulnerability disclosure
- Unverified — security contact email published (security@moonshot.cn), no public bug bounty page found
- Documented incidents
- None confirmed in primary sources
Model inventory
Listed by the AI Act deadline each model falls under, which depends on when it was placed on the EU market rather than on its capability. No benchmark scores — why not.
| Model | API identifier | EU availability | AI Act deadline | Covered by DPA |
|---|---|---|---|---|
| Kimi K3 Flagship long-context reasoning model series with multimodal capabilities. | kimi-k3 | Unverified | 2 Aug 2026 | Unverified |
| Kimi K1.5 Multimodal and long-context inference model family. | kimi-k1.5 | Unverified | 2 Aug 2027 | Unverified |
| Moonshot-v1 Base long-context model available in 8k, 32k, and 128k context windows. | moonshot-v1-128k | Unverified | 2 Aug 2027 | Unverified |
Who you are contracting with
Moonshot AI operates through Beijing Moonshot AI Technology Co., Ltd. (月之暗面) for services within Mainland China, and Moonshot AI Pte. Ltd. (Singapore) for international API and web services.
Unlike US and European providers operating in the EU market, Moonshot AI does not currently maintain a dedicated EU operating subsidiary or publish a named GDPR Article 27 representative. Contracts for international users are governed by Singapore law and subject to the jurisdiction of Singapore courts.
Training use and retention
The data usage terms follow a standard split between consumer interfaces and developer API infrastructure:
- Kimi Web & App (Consumer Tiers): Prompts, uploaded documents, and chat interactions are processed to operate and improve the model by default. Users can request data deletion or adjust privacy controls in account settings, but consumer usage is subject to Chinese domestic internet regulations and algorithm filing requirements.
- Moonshot Open Platform (API Tiers): Commercial API terms state that customer content submitted via paid API endpoints is not used to train public foundation models without explicit customer consent.
Standard API logs are retained for 30 rolling days to monitor platform security, prevent abuse, and satisfy legal compliance obligations.
Data residency and cross-border transfers
Domestic data infrastructure is hosted in Mainland China under the supervision of the Cyberspace Administration of China (CAC), in compliance with China’s Data Security Law and Personal Information Protection Law (PIPL).
International API traffic routed through Singapore endpoints undergoes cross-border data transfer safeguards where applicable, but Moonshot AI does not currently offer contractual EU-only data residency or in-region EU GPU inference guarantees.
Certifications and compliance posture
Moonshot AI has completed domestic regulatory filings in China under the Interim Measures for the Management of Generative AI Services. However, it does not currently publish Western compliance artifacts such as SOC 2 Type II reports or ISO/IEC 27001 certificates on an open trust portal.
Furthermore, Moonshot AI is not a signatory to the European Union’s General-Purpose AI Code of Practice under the EU AI Act.
Summary for enterprise evaluation
For European and international engineering teams working under strict GDPR, ISO 27001, or client NDA obligations:
- Conduct a Transfer Impact Assessment (TIA) before sending proprietary source code or personal data to non-EU/non-US jurisdictions.
- Utilize API endpoints exclusively rather than consumer web chats if testing Kimi models, ensuring paid API data non-training clauses apply.
- Redact PII and credentials upstream prior to API invocation, as formal GDPR Article 28 DPAs are not self-serve on the platform.
For a broader evaluation framework across global vendors, see our guide on how to judge an AI provider.
This record describes contractual and governance terms as read on the date shown, for the tier shown. Providers revise terms without notice — verify against the provider's own documentation before relying on any of it. Nothing here is legal advice.