Polityka prywatności

Ostatnia aktualizacja: April 17, 2026

1. Informacje, które zbieramy

Kiedy korzystasz ze Smart AIPI, zbieramy:

  • Informacje o koncie: Adres email, imię oraz dane uwierzytelniające podczas rejestracji.
  • Dane o użyciu: Metadane żądań API, w tym użyty model, liczby tokenów, znaczniki czasu i adresy IP. Nie przechowujemy treści Twoich prompts ani completions.
  • Informacje o płatnościach: Dane rozliczeniowe są przetwarzane przez naszego dostawcę płatności (Polar). Nie przechowujemy numerów kart kredytowych.
  • Cookies: Session cookies do uwierzytelniania oraz analytics cookies (Umami, self-hosted) do analizy korzystania ze strony.

2. Jak wykorzystujemy Twoje informacje

  • Aby świadczyć i utrzymywać usługę Smart AIPI
  • Aby przetwarzać rozliczenia i transakcje kredytowe
  • Aby wysyłać komunikację związaną z kontem (weryfikacja, potwierdzenia płatności, ostrzeżenia o wygaśnięciu kredytów)
  • Aby monitorować stan usługi i zapobiegać nadużyciom
  • Aby ulepszać naszą usługę na podstawie zagregowanych wzorców użycia

3. Przetwarzanie danych

Smart AIPI działa jako proxy do dostawców modeli AI. Twoje żądania API są przekazywane do dostawców upstream (OpenAI) w celu wygenerowania odpowiedzi. Nie przechowujemy, nie logujemy ani nie trenujemy na treści Twoich prompts ani completions. Dla celów rozliczeniowych zachowywane są wyłącznie metadane (liczba tokenów, użyty model, koszt).

4. Przechowywanie danych i bezpieczeństwo

  • Dane konta są przechowywane w szyfrowanych bazach danych hostowanych w Turso (rozproszony SQLite).
  • API keys są przechowywane jako nieodwracalne hashe. Klucze w postaci jawnego tekstu są pokazywane tylko raz przy tworzeniu i nie można ich później odzyskać.
  • Wszystkie połączenia używają szyfrowania TLS.
  • Infrastruktura jest hostowana na Fly.io z centrami danych w Ameryce Północnej i Europie.

5. Udostępnianie danych

Nie sprzedajemy Twoich danych osobowych. Udostępniamy dane wyłącznie:

  • Dostawcom modeli AI (OpenAI) w celu przetwarzania Twoich żądań API
  • Operatorom płatności (Polar) w celu obsługi rozliczeń
  • Dostawcom infrastruktury (Fly.io, Turso, Cloudflare) w celu hostowania i dostarczania naszej usługi

6. Twoje prawa

Możesz:

  • Uzyskać dostęp do danych swojego konta przez dashboard
  • Usunąć konto i powiązane dane, kontaktując się z supportem
  • Wyeksportować historię użycia
  • Unieważnić API keys w dowolnym momencie

7. Pliki cookie

Używamy niezbędnych cookies do sesji uwierzytelniających oraz opcjonalnych analytics cookies (self-hosted Umami), które nie śledzą Cię między stronami i nie używają identyfikatorów osobowych.

8. Zmiany w tej polityce

Od czasu do czasu możemy aktualizować tę politykę prywatności. O istotnych zmianach poinformujemy zarejestrowanych użytkowników emailem.

9. Zero Retention of Prompts and Completions

Because this question is the single most important one for an API gateway, we restate it here in concrete, testable terms.

We never log, persist, cache to disk, or otherwise retain any of the following:

  • The text or JSON body of any chat completion or completion request, including system messages, user messages, assistant messages, and tool/function call arguments and results.
  • The text or JSON body of any chat completion or completion response, including streamed deltas.
  • Embedding inputs and embedding output vectors.
  • Image generation prompts, image edit prompts, input image bytes, output image bytes, or image URLs.
  • Audio bytes for speech-to-text or text-to-speech, transcripts, or generated audio.
  • Files uploaded to /v1/files, vector store contents, or any document content.

We do log the following per-request metadata, and only for the purposes listed in section 2:

  • Account ID (so we can bill the correct account).
  • API key fingerprint, never the key itself.
  • UTC timestamp.
  • Source IP address (for abuse detection and rate-limit enforcement).
  • Target endpoint and target model name.
  • Prompt token count and completion token count, returned by the upstream provider.
  • HTTP status code and total request duration in milliseconds.

If our policy ever changes such that any item in the first list begins to be retained, we will publish the change here, bump the Last Updated date, and notify registered users by email at least seven days before the change takes effect.

10. Retention Periods

Concrete retention windows for everything we do keep:

  • Per-request metadata rows (the fields in section 9): retained for 30 days for usage display and billing reconciliation, then automatically deleted.
  • Aggregated, non-identifying daily counters (total tokens per account per model per day): retained for the lifetime of the account for the user-facing usage dashboard.
  • Account profile (email, name, hashed password or OAuth identity): retained while your account is active. Deleted within 30 days of account deletion.
  • Billing records and invoices: retained for the period required by applicable tax and accounting law (typically 7 years), in accordance with our payment processor's policies.
  • Web access logs at the edge (Cloudflare): retained per Cloudflare's standard retention, generally less than 30 days.

11. No AI Training on Your Data

We do not train, fine-tune, evaluate, benchmark, distill, or otherwise use any of your requests, responses, embeddings, images, audio, files, or metadata to develop any machine learning model, our own or a third party's. We do not sell or share data with anyone for AI training. The OpenAI store=false parameter is forwarded on supported endpoints so that the upstream provider also does not retain your data for training under their default consumer terms; our agreement with OpenAI is on their API tier, which by OpenAI's published policy excludes API traffic from training by default.

Kontakt

W przypadku pytań związanych z prywatnością skontaktuj się z nami pod adresem [email protected].

Wiadomość wysłana

Odpowiemy w ciągu 2 dni roboczych.

Kontakt z supportem

Masz pytanie albo potrzebujesz pomocy? Wyślij nam wiadomość, a odpowiemy w ciągu 2 dni roboczych.