سياسة الخصوصية
آخر تحديث: April 17, 2026
1. المعلومات التي نجمعها
عند استخدام Smart AIPI، نجمع:
- معلومات الحساب: عنوان البريد الإلكتروني والاسم وبيانات اعتماد المصادقة عند إنشاء الحساب.
- بيانات الاستخدام: بيانات تعريف طلبات API بما في ذلك النموذج المستخدم وعدد tokens والطوابع الزمنية وعناوين IP. نحن لا نخزن محتوى prompts أو completions الخاصة بك.
- معلومات الدفع: تتم معالجة تفاصيل الفوترة بواسطة مزود الدفع الخاص بنا (Polar). نحن لا نخزن أرقام بطاقات الائتمان.
- ملفات تعريف الارتباط: ملفات تعريف ارتباط الجلسة للمصادقة وملفات تعريف ارتباط التحليلات (Umami، مستضاف ذاتيًا) لفهم استخدام الموقع.
2. كيف نستخدم معلوماتك
- لتقديم خدمة Smart AIPI وصيانتها
- لمعالجة الفوترة ومعاملات الاعتمادات
- لإرسال المراسلات المتعلقة بالحساب (التحقق، تأكيدات الدفع، تحذيرات انتهاء صلاحية الاعتمادات)
- لمراقبة صحة الخدمة ومنع إساءة الاستخدام
- لتحسين خدمتنا بناءً على أنماط الاستخدام المجمّعة
3. معالجة البيانات
يعمل Smart AIPI كوكيل لمزودي نماذج AI. يتم تمرير طلبات API الخاصة بك إلى المزودين الأساسيين (OpenAI) لإنشاء الاستجابات. نحن لا نخزن أو نسجل أو ندرّب على محتوى prompts أو completions الخاصة بك. يتم الاحتفاظ بالبيانات الوصفية فقط (عدد tokens، النموذج المستخدم، التكلفة) لأغراض الفوترة.
4. تخزين البيانات والأمان
- يتم تخزين بيانات الحساب في قواعد بيانات مشفرة مستضافة على Turso (SQLite موزعة).
- يتم تخزين API keys على شكل hashes غير قابلة للعكس. تُعرض المفاتيح النصية مرة واحدة عند الإنشاء ولا يمكن استرجاعها.
- تستخدم جميع الاتصالات تشفير TLS.
- تتم استضافة البنية التحتية على Fly.io مع مراكز بيانات في أمريكا الشمالية وأوروبا.
5. مشاركة البيانات
نحن لا نبيع بياناتك الشخصية. نشارك البيانات فقط مع:
- مزودو نماذج AI (OpenAI) لمعالجة طلبات API الخاصة بك
- معالجو الدفع (Polar) لمعالجة الفوترة
- مزودو البنية التحتية (Fly.io، Turso، Cloudflare) لاستضافة خدمتنا وتقديمها
6. حقوقك
يمكنك:
- الوصول إلى بيانات حسابك عبر لوحة التحكم
- حذف حسابك والبيانات المرتبطة به عبر التواصل مع الدعم
- تصدير سجل الاستخدام الخاص بك
- إبطال API keys في أي وقت
7. ملفات تعريف الارتباط
نستخدم ملفات تعريف ارتباط أساسية لجلسات المصادقة وملفات تعريف ارتباط تحليلية اختيارية (Umami مستضاف ذاتيًا) لا تتعقبك عبر المواقع ولا تستخدم معرفات شخصية.
8. التغييرات على هذه السياسة
قد نقوم بتحديث سياسة الخصوصية هذه من وقت لآخر. سنقوم بإخطار المستخدمين المسجلين بالتغييرات المهمة عبر البريد الإلكتروني.
9. Zero Retention of Prompts and Completions
Because this question is the single most important one for an API gateway, we restate it here in concrete, testable terms.
We never log, persist, cache to disk, or otherwise retain any of the following:
- The text or JSON body of any chat completion or completion request, including system messages, user messages, assistant messages, and tool/function call arguments and results.
- The text or JSON body of any chat completion or completion response, including streamed deltas.
- Embedding inputs and embedding output vectors.
- Image generation prompts, image edit prompts, input image bytes, output image bytes, or image URLs.
- Audio bytes for speech-to-text or text-to-speech, transcripts, or generated audio.
- Files uploaded to /v1/files, vector store contents, or any document content.
We do log the following per-request metadata, and only for the purposes listed in section 2:
- Account ID (so we can bill the correct account).
- API key fingerprint, never the key itself.
- UTC timestamp.
- Source IP address (for abuse detection and rate-limit enforcement).
- Target endpoint and target model name.
- Prompt token count and completion token count, returned by the upstream provider.
- HTTP status code and total request duration in milliseconds.
If our policy ever changes such that any item in the first list begins to be retained, we will publish the change here, bump the Last Updated date, and notify registered users by email at least seven days before the change takes effect.
10. Retention Periods
Concrete retention windows for everything we do keep:
- Per-request metadata rows (the fields in section 9): retained for 30 days for usage display and billing reconciliation, then automatically deleted.
- Aggregated, non-identifying daily counters (total tokens per account per model per day): retained for the lifetime of the account for the user-facing usage dashboard.
- Account profile (email, name, hashed password or OAuth identity): retained while your account is active. Deleted within 30 days of account deletion.
- Billing records and invoices: retained for the period required by applicable tax and accounting law (typically 7 years), in accordance with our payment processor's policies.
- Web access logs at the edge (Cloudflare): retained per Cloudflare's standard retention, generally less than 30 days.
11. No AI Training on Your Data
We do not train, fine-tune, evaluate, benchmark, distill, or otherwise use any of your requests, responses, embeddings, images, audio, files, or metadata to develop any machine learning model, our own or a third party's. We do not sell or share data with anyone for AI training. The OpenAI store=false parameter is forwarded on supported endpoints so that the upstream provider also does not retain your data for training under their default consumer terms; our agreement with OpenAI is on their API tier, which by OpenAI's published policy excludes API traffic from training by default.
التواصل
للاستفسارات المتعلقة بالخصوصية، تواصل معنا على [email protected].