Skip to content

Privacy Policy

Effective date: July 29, 2026 · Version 1.0

The most important principle: we do NOT store your prompts or responses. System logs contain only metadata (token counts, cost, timing, model) — never conversation content.

1. Data we collect

TypeWhatRetention
AccountEmail, display name, password (hashed)Until account deletion
Usage metadataModel, token counts (input/cached/output/reasoning), cost, latency, status, error code — NO contentDetailed: 6 months; aggregates: long-term
BillingTop-up/charge history (ledger)Long-term (accounting obligations)
Technical logsIP address, user-agent at the edge/server layer (abuse prevention, security)7 days
Prompt/response contentNOT stored (processed in memory then discarded; temporary cache entries for the caching feature are scoped to your account and expire automatically)Cache: up to 24 hours

2. How we use data

  • Operating the Service: authentication, request routing, billing per actual tokens used;
  • Showing usage, cost and savings on your dashboard;
  • Security and abuse prevention (detecting brute-force, fraud, abnormal key sharing);
  • Service communications: top-up confirmations, low-balance alerts, notices of material changes.

We do NOT sell your data, do NOT use your content to train models, and do NOT run ads based on your data.

3. Third-party processors

PartyRoleData involved
CloudflareAI inference infrastructure (Workers AI), CDN, DDoS protectionPrompts/responses transit for processing under Cloudflare's Data Usage policy (not used for training); IP at the edge
Dodo PaymentsCard payment processing (Merchant of Record)Your payment details — we never see card numbers
payOSBank transfer confirmation (VN)Transfer transaction details (amount, order code)

4. Where data lives

Account data and metadata are stored on servers we operate in Southeast Asia, with encrypted backups. Inference requests are processed on Cloudflare's global network.

5. Security

  • All connections over HTTPS/TLS; API keys stored only as hashes (unrecoverable);
  • Sensitive system credentials are AES-256 encrypted at rest;
  • Administrative access requires multi-factor authentication and is IP-restricted;
  • If a breach affecting you occurs, we notify you by email within 72 hours of confirmation.

6. Cookies

The website and dashboard use only login-session cookies and a language preference. No advertising or third-party tracking cookies.

7. Your rights

  • View and export your usage/billing data directly on the dashboard (CSV);
  • Correct your account information at any time;
  • Request account deletion: personal data is deleted/anonymized within 30 days, except transaction ledgers kept for accounting obligations;
  • Data complaints: contact the email below; we respond within 7 business days.

8. Changes & contact

Material changes to this policy are announced as described in the Terms of Service. Privacy questions:

[email protected]