| Category | Examples | Purpose |
|---|---|---|
| Account data | Email address, username, hashed password, registration date, language preference | Account creation and authentication |
| API usage data | API key identifiers, request timestamps, model invoked, token counts, prompt/output lengths, error codes | Metering, billing, abuse prevention, service monitoring |
| Request content | Prompts you submit and outputs returned, relayed to the upstream model provider you selected | Delivering the API service (routed to the provider; retained transiently in logs, see Section 6) |
| Payment data | Order ID, amount, payment status, billing email | Processing purchases and accounting (card details are handled solely by our payment processors) |
| Technical data | IP address, user agent, access times for console sessions | Security, fraud prevention, rate limiting |
We do not collect sensitive personal data, and you must not submit such data through prompts beyond what the service inherently requires.
We do not sell personal data. We do not use your request content to train our own models.
Where the EU/UK GDPR applies, we rely on: performance of a contract (delivering the service and billing), legitimate interests (security, fraud and abuse prevention, service improvement), consent where specifically obtained (optional communications), and legal obligation (tax and accounting records).
We use only strictly necessary cookies/local storage: a session token to keep you logged in, and a language preference key for site display. We do not use advertising or cross-site tracking cookies, so no consent banner is required under the ePrivacy framework.
All traffic is encrypted in transit with TLS. Passwords are stored only as salted hashes. API keys are shown once at creation and stored in encrypted form. Access to production systems is restricted and logged. No system is perfectly secure; if a breach affecting your data occurs, we will notify affected users and regulators as required by law.
Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, etc.), you may have rights to: access your personal data, correct it, delete it, export it in a portable format, restrict or object to certain processing, and withdraw consent for optional processing. California residents may also opt out of any "sale" or "sharing" of personal data — we do not sell personal data, so no opt-out applies.
The Services are not directed to children under 18 (or under 13 in jurisdictions where COPPA applies, in which case not under 13). We do not knowingly collect data from children. If you believe a child has provided us data, contact us and we will delete it.
We operate globally: your data may be processed in Singapore, mainland China, the United States, and other countries where our infrastructure and upstream model providers operate. Where required, transfers are safeguarded by appropriate mechanisms such as the EU Standard Contractual Clauses.
We may update this Privacy Policy from time to time. Material changes will be published here with an updated "Last updated" date. We encourage you to review this page periodically.