Patakaran sa Privacy

Huling na-update: April 17, 2026

1. Impormasyong Kinokolekta Namin

Kapag ginamit mo ang Smart AIPI, kinokolekta namin ang:

  • Impormasyon ng account: Email address, pangalan, at authentication credentials kapag nag-sign up ka.
  • Data ng paggamit: API request metadata kasama ang model na ginamit, token counts, timestamps, at IP addresses. Hindi namin ini-store ang content ng iyong prompts o completions.
  • Impormasyon sa pagbabayad: Pinoproseso ang mga detalye ng billing ng aming payment provider (Polar). Hindi namin ini-store ang mga credit card number.
  • Mga Cookie: Session cookies para sa authentication at analytics cookies (Umami, self-hosted) para maunawaan ang paggamit ng site.

2. Paano Namin Ginagamit ang Iyong Impormasyon

  • Para ibigay at panatilihin ang Smart AIPI service
  • Para iproseso ang billing at credit transactions
  • Para magpadala ng mga account-related communication (verification, payment confirmations, credit expiry warnings)
  • Para bantayan ang kalusugan ng service at pigilan ang pang-aabuso
  • Para pagandahin ang aming service batay sa aggregate usage patterns

3. Pagproseso ng Data

Ang Smart AIPI ay nagsisilbing proxy sa mga AI model provider. Ang iyong API requests ay ipinapasa sa upstream providers (OpenAI) para gumawa ng responses. Hindi namin ini-store, ini-log, o ginagamit sa training ang content ng iyong prompts o completions. Metadata lang (token counts, model na ginamit, cost) ang itinatago para sa billing purposes.

4. Data Storage at Security

  • Ang account data ay naka-store sa encrypted databases na naka-host sa Turso (distributed SQLite).
  • Ang API keys ay naka-store bilang irreversible hashes. Ang plain text keys ay ipinapakita lang minsan sa paglikha at hindi na mare-retrieve.
  • Lahat ng connection ay gumagamit ng TLS encryption.
  • Ang infrastructure ay naka-host sa Fly.io na may data centers sa North America at Europe.

5. Pagbabahagi ng Data

Hindi namin ibinebenta ang iyong personal data. Ibinabahagi lang namin ang data sa:

  • Mga AI model provider (OpenAI) para iproseso ang iyong API requests
  • Mga payment processor (Polar) para asikasuhin ang billing
  • Mga infrastructure provider (Fly.io, Turso, Cloudflare) para i-host at ihatid ang aming service

6. Iyong Mga Karapatan

Maaari mong:

  • I-access ang iyong account data sa pamamagitan ng dashboard
  • Burahin ang iyong account at kaugnay na data sa pamamagitan ng pakikipag-ugnayan sa support
  • I-export ang iyong usage history
  • I-revoke ang API keys anumang oras

7. Mga Cookie

Gumagamit kami ng essential cookies para sa authentication sessions at optional analytics cookies (self-hosted Umami) na hindi ka sinusubaybayan sa iba pang site at hindi gumagamit ng personal identifiers.

8. Mga Pagbabago sa Patakarang Ito

Maaari naming i-update ang privacy policy na ito paminsan-minsan. Aabisuhan namin ang mga rehistradong user ng malalaking pagbabago sa pamamagitan ng email.

9. Zero Retention of Prompts and Completions

Because this question is the single most important one for an API gateway, we restate it here in concrete, testable terms.

We never log, persist, cache to disk, or otherwise retain any of the following:

  • The text or JSON body of any chat completion or completion request, including system messages, user messages, assistant messages, and tool/function call arguments and results.
  • The text or JSON body of any chat completion or completion response, including streamed deltas.
  • Embedding inputs and embedding output vectors.
  • Image generation prompts, image edit prompts, input image bytes, output image bytes, or image URLs.
  • Audio bytes for speech-to-text or text-to-speech, transcripts, or generated audio.
  • Files uploaded to /v1/files, vector store contents, or any document content.

We do log the following per-request metadata, and only for the purposes listed in section 2:

  • Account ID (so we can bill the correct account).
  • API key fingerprint, never the key itself.
  • UTC timestamp.
  • Source IP address (for abuse detection and rate-limit enforcement).
  • Target endpoint and target model name.
  • Prompt token count and completion token count, returned by the upstream provider.
  • HTTP status code and total request duration in milliseconds.

If our policy ever changes such that any item in the first list begins to be retained, we will publish the change here, bump the Last Updated date, and notify registered users by email at least seven days before the change takes effect.

10. Retention Periods

Concrete retention windows for everything we do keep:

  • Per-request metadata rows (the fields in section 9): retained for 30 days for usage display and billing reconciliation, then automatically deleted.
  • Aggregated, non-identifying daily counters (total tokens per account per model per day): retained for the lifetime of the account for the user-facing usage dashboard.
  • Account profile (email, name, hashed password or OAuth identity): retained while your account is active. Deleted within 30 days of account deletion.
  • Billing records and invoices: retained for the period required by applicable tax and accounting law (typically 7 years), in accordance with our payment processor's policies.
  • Web access logs at the edge (Cloudflare): retained per Cloudflare's standard retention, generally less than 30 days.

11. No AI Training on Your Data

We do not train, fine-tune, evaluate, benchmark, distill, or otherwise use any of your requests, responses, embeddings, images, audio, files, or metadata to develop any machine learning model, our own or a third party's. We do not sell or share data with anyone for AI training. The OpenAI store=false parameter is forwarded on supported endpoints so that the upstream provider also does not retain your data for training under their default consumer terms; our agreement with OpenAI is on their API tier, which by OpenAI's published policy excludes API traffic from training by default.

Kontak

Para sa mga tanong tungkol sa privacy, makipag-ugnayan sa amin sa [email protected].

Naipadala ang mensahe

Babalikan ka namin sa loob ng 2 business days.

Makipag-ugnayan sa Support

May tanong ka ba o kailangan ng tulong? Padalhan kami ng mensahe at babalikan ka namin sa loob ng 2 business days.