MiniMax Privacy Policies: API, Agent, Consumer Products, and This Site

Reviewed and fact-checked: July 25, 2026. Official policy dates are shown separately because MiniMax does not publish one privacy policy for every product.

Independent guide — not an official MiniMax policy

MiniMax-AI.chat is an independent informational website. It is not owned, operated, sponsored, endorsed, or supported by MiniMax or Nanonoble Pte. Ltd. This article explains public documents; it is not legal advice and does not replace the policy, terms, data-processing agreement, or written enterprise commitments that apply to your account.

The rule that prevents most privacy mistakes is simple: identify the exact product and access path before relying on any statement about data use. The API, Agent, MiniMax Code, Hailuo, Audio, Talkie, and this independent website do not all share one policy.

Quick answer

MiniMax’s official privacy overview says its services differ in functionality, user type, and deployment model, and directs users to product-specific policies. For API users, the relevant public documents are the MiniMax API Privacy Policy and the MiniMax API Terms, both dated March 30, 2026.

  • The API policy names Nanonoble Pte. Ltd. and publishes the address 152 Beach Road, #14-02 Gateway East, Singapore (189721) and the privacy contact [email protected].
  • It says the personal data described in the API policy is stored in a data center in the United States and processed by MiniMax or third-party vendors under relevant legal requirements.
  • It does not publish one fixed retention period for every category of API data.
  • The API Terms permit MiniMax to use client input and generated content to provide, maintain, develop, and improve the services; comply with law; enforce terms and policies; and keep the services safe.
  • The public documents reviewed do not establish a universal promise of Zero Data Retention, no training, SOC 2 certification, ISO 27001 certification, HIPAA compliance, or “full GDPR compliance” for every product and integration.

Which MiniMax privacy document applies?

Use the policy linked by the exact service you use. A model name, shared login, or MiniMax branding does not prove that the same privacy terms apply across products.

Product or access pathDocument and date shownEntity/contactImportant scope point
MiniMax Open Platform / APIAPI Privacy Policy and API Terms
March 30, 2026
Nanonoble Pte. Ltd.
[email protected]
Applies to the developer platform. Includes the US data-center statement and API input/output terms.
MiniMax AgentAgent Privacy Policy
January 19, 2026
Nanonoble Pte. Ltd.
[email protected]
Addresses web/desktop services and permitted access to local-device and third-party application, browser, or system data.
MiniMax CodeCode documentation describes it as a desktop AI Agent app.
Relevant policy depends on route.
Check the Agent policy and the selected model provider.Using a MiniMax API key may add the API documents. BYOK may add the external provider’s policy. This is a layered access-path analysis, not a claim that one document governs every Code configuration.
Hailuo Video/ImageHailuo AI Video Privacy Policy
December 9, 2025
Nanonoble Pte. Ltd.
[email protected]
A narrow face-data clause applies to specified mobile features. It must not be generalized to all uploads, prompts, outputs, accounts, or logs.
MiniMax Audio consumer serviceAudio privacy policy
December 9, 2025
Nanonoble Pte. Ltd.
[email protected]
Consumer Audio use is different from speech or audio requests sent through the API.
Older/general MiniMax App and Web servicesApp and Web Privacy Policy
Page: November 23, 2024; version history: November 28, 2024
Nanonoble Pte. Ltd.
[email protected]
An older/general consumer document still linked from some public app surfaces. Newer product-specific policies should not be replaced by this page.
TalkieTalkie Privacy Policy
December 9, 2025
SUBSUP PTE. LTD.
[email protected]
Separately operated despite MiniMax technology/branding references. Do not merge Talkie’s data practices with Nanonoble’s API or Agent policies.
MiniMax-AI.chatThis site’s Privacy Policy
July 20, 2026
Independent site; use its own contact process.Governs this website, its public text demo, advertising/consent tools, and contact form—not official MiniMax accounts or products.
Every document in this table was rechecked on July 25, 2026. Policy dates are the dates displayed by the respective publishers.

MiniMax API Privacy Policy

Scope, legal entity, address, and contact

The current public API policy is titled “MiniMax API Privacy Policy,” shows Effective March 30, 2026, and says it was updated on that date. It identifies Nanonoble Pte. Ltd. and its affiliates. Its jurisdiction-specific section expressly identifies Nanonoble Pte. Ltd. as the controller for EEA, UK, and Swiss users.

Published companyNanonoble Pte. Ltd.
Registered address152 Beach Road, #14-02 Gateway East, Singapore (189721)
API privacy contact[email protected]
Policy effective/updatedMarch 30, 2026
Last independently checkedJuly 25, 2026

Use the contact listed in the policy that matches the product. An Audio, Agent, Talkie, or MiniMax-AI.chat request should not automatically be sent to the API address.

What the API policy says it processes

The API policy describes identification and account information, contact and support information, purchase and billing information, and data collected automatically about devices, networks, and service use. It also has a “Services Input & Output” category: input can include text, voice, or other content, and MiniMax says it processes input, output, other service information, and any personal information contained in that material.

This means a prompt should be treated as data sent to a service provider even when the interface feels like a private conversation. Removing names does not necessarily remove all personal or confidential information: source code, filenames, voice, images, document text, identifiers, and context can still disclose people or organizations.

US data-center statement and international transfers

The API policy says the personal data described in that policy is stored in a data center located in the United States and processed by MiniMax or third-party vendors in accordance with relevant laws and regulations, including the GDPR. It also says information may be transferred outside the user’s country and describes contractual or commercial safeguards for third parties.

Do not turn this product-specific sentence into “all MiniMax data is stored in the US.” The statement belongs to the API policy. Other products publish different documents and may describe transfers differently.

The EEA/UK/Switzerland supplement also refers to an unnamed cloud provider’s US data center, certification under the EU–US Data Privacy Framework, contractual measures including Standard Contractual Clauses where appropriate, and technical safeguards. That language should not be rewritten as a claim that MiniMax itself has a particular certification or that every customer integration is automatically compliant.

MiniMax API data retention

The policy does not give one fixed retention period for all API personal data. Its general rule is that personal data may be retained and used for as long as necessary or permitted by law or to fulfil the purpose for which it was collected.

The published criteria include:

  1. providing products or services and maintaining business records for inquiries or complaints;
  2. service safety and quality;
  3. a user’s agreement to a longer storage duration;
  4. applicable limitation periods; and
  5. other agreements, laws, or regulations concerning storage duration.

The policy says personal information will be deleted or anonymized after the applicable storage duration expires. This is a criteria-based retention statement, not a public Zero Data Retention promise. The API Terms also indicate that a purchased feature with storage can be subject to service-specific storage rules, so buyers should obtain the exact rule for their endpoint, plan, region, and contract.

How the API Terms allow input and output to be used

The API Terms say that, as between the customer and MiniMax and to the extent permitted by law, the customer retains ownership rights in client input and generated content. The same clause then says MiniMax may use input and generated content to:

  • provide, maintain, develop, and improve the services;
  • comply with applicable law;
  • enforce terms and policies; and
  • keep the services safe.

A separate Client Data clause allows access and processing to provide the service, perform routine maintenance, troubleshooting, and technical support, and comply with law. The confidentiality section also contains language concerning algorithm improvement or service enhancement. Read the full terms rather than relying only on the ownership sentence.

What this does and does not prove: the terms authorize specified uses for development and improvement. They do not, by themselves, explain the exact technical treatment of every request or prove that every prompt is used to train a foundation model. Conversely, they do not support a blanket claim that all API input is excluded from training or improvement.

The privacy policy contains a narrower statement that input personal data is not used to infer characteristics about an individual and personal data is not used for training to profile or target consumers. That limited statement must not be expanded into a universal “no training” promise.

Security language and user rights

The API policy describes examples of safeguards such as HTTPS, SSL, AES, information classification, encryption, and access permissions, while also saying that no system can guarantee 100% security. These descriptions are not substitutes for an independent audit report, certification, penetration-test evidence, a security addendum, or a customer risk assessment.

Depending on location and applicable law, the policy describes rights that can include access, correction, deletion, restriction, objection, withdrawal of consent, and portability. The exact scope is qualified by law. API privacy requests should be directed to [email protected]; users may also have a right to complain to a competent regulator.

Claims the public API documents do not establish

ClaimPublication decisionAccurate alternative
“Zero Data Retention”Do not publish as a platform-wide fact.The public policy uses purpose-, law-, safety-, quality-, limitation-, and agreement-based retention criteria. Verify any special ZDR commitment in writing for the exact plan and endpoint.
“MiniMax never trains on API data”Do not publish as a blanket claim.The Terms authorize input/output use for service development and improvement. The policy’s training statement is narrower and concerns profiling or targeting consumers.
“SOC 2 certified”Not established by the API policy or terms reviewed.Request a current report and confirm the legal entity, system scope, report period, and customer responsibilities.
“ISO 27001 certified”Not established by the API policy or terms reviewed.Request the current certificate, issuing body, entity, covered locations, products, and expiry date.
“HIPAA compliant”Not established.Do not submit protected health information without a product-specific written authorization, suitable contract, and BAA where required.
“Fully GDPR compliant”Too broad and not a certification.The policy describes GDPR-related roles, rights, transfers, and safeguards. Each customer must still assess legal basis, roles, DPA/SCCs, data categories, implementation, and local law.

MiniMax Agent and MiniMax Code privacy

Agent policy: local and third-party data

The official Agent policy is dated January 19, 2026 and names Nanonoble Pte. Ltd. Its contact is [email protected]. In addition to account, contact, device, IP, usage, log, and cookie information, it says users may allow the service to access local data for particular features. That can include data stored on a device and in third-party software applications, browsers, or systems installed on the device. It says users can change that permission through applicable product settings.

The Agent Terms add context for authorized browser, third-party-account, and local-access features. Depending on the feature and permission, these workflows may interact with webpages, third-party account content, existing sessions, authentication tokens, cookies, or network connections. Therefore, “files always remain local” or “Agent cannot access logged-in sessions” would be unsafe claims.

The Agent policy uses a necessary/permitted/purpose-based retention approach rather than one universal number. Users should verify the exact feature permissions, connected accounts, deletion controls, logs, and retention rules before enabling an agent in a sensitive environment.

MiniMax Code has more than one privacy layer

MiniMax’s Code documentation describes MiniMax Code as a desktop AI Agent application. That makes the Agent policy relevant to the application layer. The model-request layer can differ:

  • MiniMax API key: the Agent/Code application policy remains relevant, and the MiniMax API policy and terms may also apply to requests sent through the Open Platform.
  • BYOK or custom provider: the Agent/Code application policy remains relevant, while the selected model provider’s privacy policy and terms can apply to model requests.
  • Web Agent versus desktop app: permissions, local access, browser context, and available controls can differ. Do not infer desktop behavior from a model capability or from the web experience.

This layered explanation is an access-path inference based on the official Code and account-configuration documentation; it is not a quotation saying that one document exclusively governs every Code setup. Businesses should ask MiniMax to identify the controlling documents for their exact account, region, endpoint, plan, and provider configuration.

Mobile users should also check the policy linked inside the installed app and on the exact app-store listing. Public store links can lag behind the current central product-policy directory, so the page reached from a store should not silently be assumed to override—or be overridden by—another policy without confirmation.

Consumer product policies

Hailuo Video and Image

The Hailuo AI Video Privacy Policy is dated December 9, 2025. It covers the Hailuo video/image website and associated applications described by that policy. It includes common consumer-service categories such as account/contact information, uploaded or posted material, correspondence, device and usage data, IP addresses, cookies, and service-provider disclosures.

Its face-data section is unusually specific but narrow. For certain mobile features, a user may upload a photo containing a face, and temporary facial features or landmarks may be derived to generate a video. The policy says that facial data is used for that task, is not used to identify or authenticate the user, is not shared with third parties, and is deleted with the uploaded photo after generation.

Do not rewrite that clause as “Hailuo deletes every upload after generation.” It does not establish immediate deletion for all prompts, images, videos, account records, logs, safety records, or other data. The policy’s general retention language remains purpose-, necessity-, and law-based.

MiniMax Audio

The consumer Audio policy is dated December 9, 2025 and names Nanonoble Pte. Ltd. It describes information such as account/contact data, uploaded or posted material, correspondence, device and usage data, IP addresses, cookies, and disclosures to affiliates or service providers. It does not publish a universal default promise of ZDR, no training, or automatic deletion of every voice sample.

The access path matters: speech or audio submitted through the developer API should be assessed under the API documents, not assumed to have the same treatment as the consumer Audio website or app.

Older/general MiniMax App and Web policy

The older App and Web policy displays “Last modified: November 23, 2024,” while its version history lists a November 28, 2024 update. Both dates are reported here rather than silently reconciled. The page names Nanonoble Pte. Ltd. and uses [email protected].

Some public app-store surfaces may still link to this document. However, MiniMax’s newer central privacy overview routes Open Platform, Agent, Audio, and Video users to separate product-specific policies. Treat the older page as a general/legacy consumer document, not as the sole current policy for every MiniMax service.

Talkie is separately operated

Talkie’s policy is dated December 9, 2025 and names SUBSUP PTE. LTD., not Nanonoble Pte. Ltd., with [email protected] as its contact. Its policy addresses text/voice messages, preferences, personalization, safety, advertising-related data, international processing, and a 14-or-local-minimum age threshold. Those statements belong to Talkie and must not be generalized to the MiniMax API, Agent, Hailuo, or Audio.

MiniMax-AI.chat’s own privacy policy

The policy governing a visit to this independent website is MiniMax-AI.chat’s Privacy Policy, last updated July 20, 2026. It does not govern an official MiniMax account, subscription, API console, Agent app, Code app, Hailuo account, Audio account, or Talkie account.

The current site notice says the public text demo sends messages through this website’s server to the MiniMax API, can keep limited recent context in browser-session memory, and does not provide a site account or account-based conversation archive. It also says the interface accepts text only and does not expose an upload control or visitor-facing model selector.

That does not prove immediate deletion across the web server, network/security logs, MiniMax API, advertising systems, consent systems, email, or form infrastructure. The site notice currently describes itself as an interim transparency notice and says the verified legal operator/controller identity, legal address, jurisdiction-specific disclosures, and exact retention periods have not yet been supplied for publication. Until that legal disclosure is completed, users should not submit personal, confidential, regulated, or security-sensitive information through this site.

Publisher action required: this article can accurately explain the current interim notice, but it cannot repair missing controller, jurisdiction, address, retention, and data-flow disclosures. Those facts must be verified against the actual site operation and contracts, then added to the legal privacy policy by the responsible party.

What to verify before sending data

For personal, confidential, customer, employee, source-code, or regulated data, a public privacy page is only the start. Record the answers to these questions before production use:

  1. Exact service and route: API endpoint, Agent web, Agent desktop, MiniMax Code, Hailuo, Audio, Talkie, or an independent third-party interface?
  2. Legal entity and role: who is the controller, processor, service provider, or independent controller for this workflow?
  3. Documents and dates: which privacy policy, product terms, order form, DPA, service rules, and enterprise addenda govern the account today?
  4. Input/output use: can prompts, files, voice, images, outputs, metadata, or de-identified data be used for maintenance, safety, support, development, improvement, algorithm improvement, analytics, or commercial research?
  5. Retention: what is retained, for how long, in which systems and backups, and what changes after deletion, account closure, or contract termination?
  6. Location and transfers: where are content and metadata stored or accessed, and what transfer mechanism applies?
  7. Subprocessors: which hosting, safety, support, analytics, payment, identity, and model providers receive data?
  8. Security evidence: obtain current, scope-specific audit reports or certificates rather than relying on marketing language.
  9. Regulated data: confirm in writing whether health, financial, biometric, children’s, employment, education, or government-identifier data is permitted and which contracts are required.
  10. Rights and deletion: identify the correct contact, request process, response period, appeal route, and technical deletion controls.
  11. Agent permissions: list local folders, apps, browser profiles, third-party accounts, sessions, cookies, tokens, tools, and network resources the agent can access.
  12. BYOK layering: verify both the application policy and the selected model provider’s documents. BYOK does not automatically remove the app’s own data handling.

Minimum-risk operating practices

  • Remove names, email addresses, IDs, customer numbers, secrets, credentials, and unnecessary context from prompts.
  • Never paste API keys, passwords, session tokens, private certificates, or recovery codes into a prompt.
  • Use synthetic or redacted data for testing and separate development from production credentials.
  • Restrict Agent and Code permissions to the smallest required folder, app, account, browser profile, and time window.
  • Do not connect legal, health, payroll, HR, banking, customer, or security systems without organizational approval and suitable written terms.
  • Verify model outputs before use; privacy terms do not guarantee output accuracy, confidentiality, ownership clearance, or fitness for a regulated decision.

Privacy policy, terms, DPA, and enterprise commitments are different

DocumentWhat it usually answersWhy it matters here
Privacy policyPersonal-data categories, purposes, disclosures, transfers, retention criteria, rights, and contacts.The API policy contains the US data-center statement and criteria-based retention language.
Terms of serviceContent rights, permitted uses, responsibilities, restrictions, service rules, and liability.The API Terms contain the important permission to use input and generated content for service, development, improvement, law, enforcement, and safety.
DPA / SCCsController/processor roles, processing instructions, security, subprocessors, international transfers, assistance, deletion, and audit provisions.A public privacy page does not prove that a suitable DPA or transfer mechanism applies to your company.
Order form / enterprise addendumPlan-specific regions, retention, support, service scope, negotiated restrictions, and commercial commitments.A written, account-specific commitment may differ from public defaults; verify its priority and scope.
Security evidenceAudited control scope, certificate entity, dates, systems, exclusions, and customer responsibilities.Marketing terms such as “enterprise-grade” do not establish SOC 2, ISO 27001, HIPAA, or another assurance.

Frequently asked questions

Which MiniMax privacy policy applies to API use?

Use the MiniMax API Privacy Policy and API Terms for the Open Platform, plus any service-specific rules, DPA, order form, or enterprise terms that apply to the account. Do not substitute the Agent, Audio, Hailuo, or older App/Web policy.

Where does the MiniMax API policy say personal data is stored?

The March 30, 2026 API policy says the personal data described in that policy is stored in a data center in the United States and processed by MiniMax or third-party vendors. This is an API-specific statement, not proof that every MiniMax product stores all data in the same country.

Does MiniMax offer blanket Zero Data Retention?

Not in the public API policy reviewed. The policy uses flexible retention criteria based on purpose, law, service safety and quality, limitation periods, user agreement, and other applicable agreements. Verify any special ZDR option in a written, account-specific commitment for the exact endpoint and data category.

Does MiniMax say API inputs are never used for training or improvement?

No blanket statement of that kind appears in the reviewed public documents. The API Terms allow input and generated content to be used to provide, maintain, develop, and improve services and for law, enforcement, and safety. The privacy policy’s narrower training language concerns using personal data to profile or target consumers and should not be expanded into a universal no-training promise.

How long does MiniMax retain API personal data?

The policy does not publish one fixed period for every data type. It describes criteria used to determine duration and says data will be deleted or anonymized after the applicable period expires. Ask for endpoint-, feature-, account-, region-, and backup-specific details before processing sensitive data.

Is MiniMax SOC 2 certified, ISO 27001 certified, HIPAA compliant, or fully GDPR compliant?

The API Privacy Policy and Terms reviewed do not establish those blanket claims. GDPR-related language describes legal obligations and safeguards, not a universal certification. For any assurance or regulated workload, obtain current, direct evidence for the exact legal entity, product, deployment, region, and customer use case.

Does the API policy also cover MiniMax Agent and MiniMax Code?

Not automatically. Agent has a separate policy. MiniMax Code is described as a desktop AI Agent app, so the Agent layer is relevant; the selected model provider adds another layer. If Code uses a MiniMax API key, API documents may also apply. If it uses BYOK, the external provider’s policy may apply to model requests.

Which policy governs visitors to MiniMax-AI.chat?

This independent site’s own Privacy Policy governs browsing, the text demo, consent/advertising systems, and the contact form. The MiniMax API policy separately describes MiniMax’s handling of content relayed to its API. Neither document should be presented as replacing the other.

Official sources and verification dates

SourceDate displayed by publisherChecked
MiniMax central privacy overviewNo clear update date displayed in the page reviewedJuly 25, 2026
MiniMax API Privacy PolicyEffective/updated March 30, 2026July 25, 2026
MiniMax API TermsEffective March 30, 2026July 25, 2026
MiniMax Agent Privacy PolicyUpdated January 19, 2026July 25, 2026
MiniMax Agent TermsUpdated January 19, 2026July 25, 2026
MiniMax Audio privacy policyUpdated December 9, 2025July 25, 2026
Hailuo AI Video Privacy PolicyUpdated December 9, 2025July 25, 2026
Older/general MiniMax App and Web Privacy PolicyPage: November 23, 2024; version history: November 28, 2024July 25, 2026
Talkie Privacy PolicyUpdated December 9, 2025July 25, 2026
MiniMax-AI.chat Privacy PolicyLast updated July 20, 2026July 25, 2026

Editorial method: material claims in this guide were checked against the public documents linked above. Where a document did not publish a fixed number, certification, universal commitment, or clear date, this article says so rather than inferring one. Public policies can change; recheck the exact service documents before sending sensitive data or entering a contract.

Bottom line

There is no reliable one-sentence “MiniMax privacy policy” for every use. The API policy identifies Nanonoble Pte. Ltd., publishes its Singapore address and API contact, states that covered personal data is stored in a US data center, and uses criteria-based retention. The API Terms also authorize specified input/output uses for service operation, development, improvement, compliance, enforcement, and safety. Agent, Code, Hailuo, Audio, Talkie, and MiniMax-AI.chat introduce different entities, permissions, data types, and policy layers. Verify the product, route, document date, contract, and technical configuration before sharing personal, confidential, or regulated information.