개인정보 처리방침

마지막 업데이트: April 17, 2026

1. 수집하는 정보

Smart AIPI를 사용할 때 다음 정보를 수집합니다:

  • 계정 정보: 회원가입 시 이메일 주소, 이름, 인증 자격 증명을 수집합니다.
  • 사용 데이터: 사용된 모델, token 수, 타임스탬프, IP 주소를 포함한 API 요청 메타데이터를 수집합니다. prompt나 completions의 내용은 저장하지 않습니다.
  • 결제 정보: 결제 정보는 결제 제공업체(Polar)가 처리합니다. 저희는 신용카드 번호를 저장하지 않습니다.
  • 쿠키: 인증용 세션 쿠키와 사이트 사용량 파악을 위한 분석 쿠키(Umami, self-hosted)를 사용합니다.

2. 정보 사용 방식

  • Smart AIPI 서비스를 제공하고 유지하기 위해
  • 과금 및 크레딧 거래를 처리하기 위해
  • 계정 관련 커뮤니케이션(인증, 결제 확인, 크레딧 만료 경고)을 보내기 위해
  • 서비스 상태를 모니터링하고 악용을 방지하기 위해
  • 집계된 사용 패턴을 기반으로 서비스를 개선하기 위해

3. 데이터 처리

Smart AIPI는 AI 모델 제공업체로의 프록시 역할을 합니다. API 요청은 응답 생성을 위해 upstream 제공업체(OpenAI)로 전달됩니다. 저희는 prompts나 completions의 내용을 저장, 기록, 학습에 사용하지 않습니다. 과금 목적상 메타데이터(token 수, 사용 모델, 비용)만 보관합니다.

4. 데이터 저장 및 보안

  • 계정 데이터는 Turso(분산 SQLite)에 호스팅된 암호화 데이터베이스에 저장됩니다.
  • API keys는 되돌릴 수 없는 해시로 저장됩니다. 평문 key는 생성 시 한 번만 표시되며 다시 조회할 수 없습니다.
  • 모든 연결은 TLS 암호화를 사용합니다.
  • 인프라는 Fly.io에서 호스팅되며 북미와 유럽에 데이터 센터가 있습니다.

5. 데이터 공유

저희는 개인 데이터를 판매하지 않습니다. 데이터는 다음과만 공유됩니다:

  • AI 모델 제공업체 (OpenAI) API 요청 처리를 위해
  • 결제 처리업체 (Polar) 과금 처리를 위해
  • 인프라 제공업체 (Fly.io, Turso, Cloudflare) 서비스 호스팅 및 제공을 위해

6. 사용자 권리

다음이 가능합니다:

  • Dashboard에서 계정 데이터에 접근
  • 지원팀에 문의하여 계정 및 관련 데이터 삭제
  • 사용 기록 내보내기
  • 언제든지 API keys 폐기

7. 쿠키

인증 세션을 위한 필수 쿠키와 사이트 간 추적을 하지 않고 개인 식별자를 사용하지 않는 선택적 분석 쿠키(self-hosted Umami)를 사용합니다.

8. 정책 변경

이 개인정보 처리방침은 수시로 업데이트될 수 있습니다. 중요한 변경 사항은 등록된 사용자에게 이메일로 알려드립니다.

9. Zero Retention of Prompts and Completions

Because this question is the single most important one for an API gateway, we restate it here in concrete, testable terms.

We never log, persist, cache to disk, or otherwise retain any of the following:

  • The text or JSON body of any chat completion or completion request, including system messages, user messages, assistant messages, and tool/function call arguments and results.
  • The text or JSON body of any chat completion or completion response, including streamed deltas.
  • Embedding inputs and embedding output vectors.
  • Image generation prompts, image edit prompts, input image bytes, output image bytes, or image URLs.
  • Audio bytes for speech-to-text or text-to-speech, transcripts, or generated audio.
  • Files uploaded to /v1/files, vector store contents, or any document content.

We do log the following per-request metadata, and only for the purposes listed in section 2:

  • Account ID (so we can bill the correct account).
  • API key fingerprint, never the key itself.
  • UTC timestamp.
  • Source IP address (for abuse detection and rate-limit enforcement).
  • Target endpoint and target model name.
  • Prompt token count and completion token count, returned by the upstream provider.
  • HTTP status code and total request duration in milliseconds.

If our policy ever changes such that any item in the first list begins to be retained, we will publish the change here, bump the Last Updated date, and notify registered users by email at least seven days before the change takes effect.

10. Retention Periods

Concrete retention windows for everything we do keep:

  • Per-request metadata rows (the fields in section 9): retained for 30 days for usage display and billing reconciliation, then automatically deleted.
  • Aggregated, non-identifying daily counters (total tokens per account per model per day): retained for the lifetime of the account for the user-facing usage dashboard.
  • Account profile (email, name, hashed password or OAuth identity): retained while your account is active. Deleted within 30 days of account deletion.
  • Billing records and invoices: retained for the period required by applicable tax and accounting law (typically 7 years), in accordance with our payment processor's policies.
  • Web access logs at the edge (Cloudflare): retained per Cloudflare's standard retention, generally less than 30 days.

11. No AI Training on Your Data

We do not train, fine-tune, evaluate, benchmark, distill, or otherwise use any of your requests, responses, embeddings, images, audio, files, or metadata to develop any machine learning model, our own or a third party's. We do not sell or share data with anyone for AI training. The OpenAI store=false parameter is forwarded on supported endpoints so that the upstream provider also does not retain your data for training under their default consumer terms; our agreement with OpenAI is on their API tier, which by OpenAI's published policy excludes API traffic from training by default.

연락처

개인정보 관련 문의는 다음으로 연락해 주세요 [email protected].

메시지가 전송되었습니다

영업일 기준 2일 이내에 답변드리겠습니다.

지원 문의

질문이 있거나 도움이 필요하신가요? 메시지를 보내주시면 영업일 기준 2일 이내에 답변드리겠습니다.