Privacy Policy
This Policy explains how the operator of this Platform ("we", "us") handles your information when you use the Platform.
-
Information we collect Account information: your email address, password, and language preference. Passwords are stored only as Argon2id hashes, never in plain text. Security information: for security purposes, server access logs and some security records include your IP address and browser identifier. The IP address and browser identifier in session and registration records are stored as hashes, used to detect self-referrals and manage risk, and never shown on any page. Usage records: the model, time, usage, cost, and result status of each call, as well as your orders, bills, tickets, and notifications. Invoice information: the invoice title and tax ID you enter.
-
Request content By default we do not store the prompts you send or the content models return. Call records keep only a digest (SHA-256) of the request content, and logs record only its length and digest. Requests pass through content moderation inside the Platform before they are sent on; they are not sent to any third-party moderation service. Enforcement records keep only the verdict, the violation category, and the action taken. Support staff and administrators cannot see your prompts, outputs, or full API keys. Input attachments and result files of image, video, and other media tasks are stored in the Platform's storage and deleted automatically, without further notice, when the retention period set by the Platform ends. Media tasks keep their request parameters, including prompts, with the task record; these are cleared when your account is deleted.
-
Third parties Model providers: to complete a call, your request content is sent to the upstream provider of that model. For media tasks, the provider fetches attachments from the Platform through short-lived links. Upstream providers may be located outside your country or region, and their handling of data is governed by their own terms. Payments: top-ups are completed on Stripe's hosted checkout page; we never see your card details. Email: verification and notification emails are sent through the email provider configured for the Platform. Files are stored in object storage that the Platform runs itself. We do not sell your personal information or use it for advertising.
-
Cookies and local storage The Platform uses only two sign-in session cookies: an access credential valid for 15 minutes and a refresh credential valid for 30 days. Neither can be read by page scripts. Browser local storage holds only your language and theme preferences. The Platform does not use analytics or advertising trackers.
-
Retention Call and usage records, and risk events: kept for 365 days. Media task input attachments and result files: kept for the retention period set by the Platform. Ticket attachments: deleted if not submitted with a ticket within 24 hours of upload; once submitted, including attachments that support staff upload to your tickets, kept until your account is deleted. Audit records: kept for the audit retention period set by the Platform, which is at least 180 days. Orders and ledger records: kept long-term for accounting and reconciliation.
-
Account deletion When the deletion period ends, we delete your notifications, media files, media task request parameters (including prompts), ticket attachments, invoice titles, favorite models, sign-in sessions and verification records, notification and low-balance alert settings, and the IP address and browser identifier hashes recorded at registration. Your invite code stops working. All API keys are revoked, and their secrets, names, and IP allowlists are cleared. Your email address is replaced with a random placeholder, and your password with a random value. The following records are not deleted with the account: orders, ledger records, and billing line items (for accounting and as the basis for charges); audit records (deleted on the schedule in section 5); invoice titles on issued invoices (the basis for invoicing); ticket subjects and messages, and appeal content (support and dispute records); and call and risk records (deleted after 365 days). To prevent the trial credit from being claimed again, we keep a non-reversible digest of your email address.
-
Your rights In the console you can view your usage, bills, orders, notifications, and account restrictions, and change your password, language, and invoice title. Your email address can be changed until it is verified. You can request account deletion at any time. If you have questions about how your personal information is handled, submit a ticket from the console.
-
Security and changes We take reasonable technical measures to protect your information, and sensitive actions such as viewing a full API key require you to re-enter your password, but no system can be guaranteed to be completely secure. An updated version of this Policy takes effect when it is published on this page.