Privacy Policy

Last updated: April 17, 2026

1. Information We Collect

When you use Smart AIPI, we collect:

  • Account information: Email address, name, and authentication credentials when you sign up.
  • Usage data: Per-request metadata only: account ID, request timestamp, source IP, target model, prompt token count, completion token count, HTTP status code, and request latency. We never store the body of your request, the body of the model response, embedding inputs, image inputs or outputs, audio bytes, or uploaded file contents.
  • Payment information: Billing details are processed by our payment provider (Polar). We do not store credit card numbers.
  • Cookies: Session cookies for authentication and analytics cookies (Umami, self-hosted) for understanding site usage.

2. How We Use Your Information

  • To provide and maintain the Smart AIPI service
  • To process billing and credit transactions
  • To send account-related communications (verification, payment confirmations, credit expiry warnings)
  • To monitor service health and prevent abuse
  • To improve our service based on aggregate usage patterns

3. Data Processing

Smart AIPI is a stateless proxy to upstream AI model providers. When you call our API, your request is streamed to the upstream provider (such as OpenAI) and the response is streamed back to you. The request body and response body are held only in transient memory for the duration of that single HTTP transaction and are then discarded. They are never written to disk, never written to a database, never queued, never copied to a log line, never sent to any third party other than the upstream model provider you invoked, and never used to train, fine-tune, evaluate, or improve any model — ours or anyone else's. We additionally forward the OpenAI store=false parameter on supported endpoints so that upstream providers also do not retain conversation state on our behalf. The only artifact that persists from your API call is a metadata row containing the fields enumerated in section 1, used solely for billing reconciliation, abuse prevention, and your own usage dashboard.

4. Data Storage and Security

  • Account data is stored in encrypted databases hosted on Turso (distributed SQLite).
  • API keys are stored as irreversible hashes. Plain text keys are shown once at creation and cannot be retrieved.
  • All connections use TLS encryption.
  • Infrastructure is hosted on Fly.io with data centers in North America and Europe.

5. Data Sharing

We do not sell, rent, license, trade, or otherwise transfer your personal data to anyone for marketing, advertising, profiling, or any commercial purpose. The only parties that receive any portion of your data are the subprocessors strictly required to deliver the service you requested:

  • AI model providers (OpenAI) to process your API requests
  • Payment processors (Polar) to handle billing
  • Infrastructure providers (Fly.io, Turso, Cloudflare) to host and deliver our service

6. Your Rights

You can:

  • Access your account data through the dashboard
  • Delete your account and associated data by contacting support
  • Export your usage history
  • Revoke API keys at any time

7. Cookies

We use essential cookies for authentication sessions and optional analytics cookies (self-hosted Umami) that do not track you across sites and do not use personal identifiers.

8. Changes to This Policy

We may update this privacy policy from time to time. We will notify registered users of significant changes via email.

9. Zero Retention of Prompts and Completions

Because this question is the single most important one for an API gateway, we restate it here in concrete, testable terms.

We never log, persist, cache to disk, or otherwise retain any of the following:

  • The text or JSON body of any chat completion or completion request, including system messages, user messages, assistant messages, and tool/function call arguments and results.
  • The text or JSON body of any chat completion or completion response, including streamed deltas.
  • Embedding inputs and embedding output vectors.
  • Image generation prompts, image edit prompts, input image bytes, output image bytes, or image URLs.
  • Audio bytes for speech-to-text or text-to-speech, transcripts, or generated audio.
  • Files uploaded to /v1/files, vector store contents, or any document content.

We do log the following per-request metadata, and only for the purposes listed in section 2:

  • Account ID (so we can bill the correct account).
  • API key fingerprint, never the key itself.
  • UTC timestamp.
  • Source IP address (for abuse detection and rate-limit enforcement).
  • Target endpoint and target model name.
  • Prompt token count and completion token count, returned by the upstream provider.
  • HTTP status code and total request duration in milliseconds.

If our policy ever changes such that any item in the first list begins to be retained, we will publish the change here, bump the Last Updated date, and notify registered users by email at least seven days before the change takes effect.

10. Retention Periods

Concrete retention windows for everything we do keep:

  • Per-request metadata rows (the fields in section 9): retained for 30 days for usage display and billing reconciliation, then automatically deleted.
  • Aggregated, non-identifying daily counters (total tokens per account per model per day): retained for the lifetime of the account for the user-facing usage dashboard.
  • Account profile (email, name, hashed password or OAuth identity): retained while your account is active. Deleted within 30 days of account deletion.
  • Billing records and invoices: retained for the period required by applicable tax and accounting law (typically 7 years), in accordance with our payment processor's policies.
  • Web access logs at the edge (Cloudflare): retained per Cloudflare's standard retention, generally less than 30 days.

11. No AI Training on Your Data

We do not train, fine-tune, evaluate, benchmark, distill, or otherwise use any of your requests, responses, embeddings, images, audio, files, or metadata to develop any machine learning model, our own or a third party's. We do not sell or share data with anyone for AI training. The OpenAI store=false parameter is forwarded on supported endpoints so that the upstream provider also does not retain your data for training under their default consumer terms; our agreement with OpenAI is on their API tier, which by OpenAI's published policy excludes API traffic from training by default.

Contact

For privacy-related questions, contact us at [email protected].

Message sent

We'll get back to you within 2 business days.

Contact Support

Have a question or need help? Send us a message and we'll get back to you within 2 business days.