Privacy Policy
Template — have counsel review before selling commercially.
What we store
- Account: email address and a bcrypt hash of your password.
- API keys: a SHA-256 hash and a display prefix — never the key itself.
- Usage records: model, token counts, cost, latency, status, and timestamps per request.
- Billing ledger: credit grants and deductions, with Stripe session references.
What we do not store
Prompt and completion content is proxied to the inference backend and not persisted by the gateway. Card details are handled entirely by Stripe Checkout and never touch our servers.
Why we process it
To operate the service: authentication, metering, billing, abuse prevention, and support. We do not sell personal data or use it for advertising.
Subprocessors
Hosting and database: Railway. Payments: Stripe. Inference runs on operator-owned GPUs.
Your rights
From the dashboard you can export all data we hold about you as JSON, and delete your account. Deletion revokes access immediately and anonymizes personal data; financial records are retained in anonymized form as required for accounting.
Retention
Usage and ledger records are retained for as long as the account exists, and in anonymized form afterwards. Session cookies expire after 30 days.