Політика конфіденційності

Останнє оновлення: April 17, 2026

1. Інформація, яку ми збираємо

Коли ви користуєтеся Smart AIPI, ми збираємо:

  • Інформація акаунта: Email адреса, ім’я та облікові дані автентифікації під час реєстрації.
  • Дані використання: Метадані API запитів, включно з використаною моделлю, кількістю token, часовими мітками та IP адресами. Ми не зберігаємо вміст ваших prompts або completions.
  • Платіжна інформація: Платіжні дані обробляються нашим платіжним провайдером (Polar). Ми не зберігаємо номери банківських карток.
  • Cookies: Session cookies для автентифікації та analytics cookies (Umami, self-hosted) для розуміння використання сайту.

2. Як ми використовуємо вашу інформацію

  • Щоб надавати та підтримувати сервіс Smart AIPI
  • Щоб обробляти платежі та кредитні транзакції
  • Щоб надсилати повідомлення, пов’язані з акаунтом (підтвердження, підтвердження платежів, попередження про закінчення кредитів)
  • Щоб відстежувати стан сервісу та запобігати зловживанням
  • Щоб покращувати наш сервіс на основі сукупних патернів використання

3. Обробка даних

Smart AIPI діє як proxy до провайдерів AI моделей. Ваші API запити пересилаються upstream провайдерам (OpenAI) для генерації відповідей. Ми не зберігаємо, не логгуємо і не навчаємося на вмісті ваших prompts або completions. Для цілей білінгу зберігаються лише метадані (кількість token, використана модель, вартість).

4. Зберігання даних і безпека

  • Дані акаунтів зберігаються в зашифрованих базах даних, розміщених у Turso (distributed SQLite).
  • API keys зберігаються як необоротні hashes. Ключі у відкритому вигляді показуються один раз під час створення і не можуть бути відновлені.
  • Усі з’єднання використовують TLS encryption.
  • Інфраструктура розміщена на Fly.io з дата-центрами в Північній Америці та Європі.

5. Передача даних

Ми не продаємо ваші персональні дані. Ми ділимося даними лише з:

  • Провайдери AI моделей (OpenAI) для обробки ваших API запитів
  • Платіжні процесори (Polar) для обробки платежів
  • Інфраструктурні провайдери (Fly.io, Turso, Cloudflare) для хостингу й доставки нашого сервісу

6. Ваші права

Ви можете:

  • Отримати доступ до даних свого акаунта через dashboard
  • Видалити свій акаунт і пов’язані дані, звернувшись у підтримку
  • Експортувати свою історію використання
  • Відкликати API keys у будь-який момент

7. Файли cookie

Ми використовуємо essential cookies для сесій автентифікації та optional analytics cookies (self-hosted Umami), які не відстежують вас між сайтами й не використовують персональні ідентифікатори.

8. Зміни до цієї політики

Ми можемо час від часу оновлювати цю політику конфіденційності. Ми повідомлятимемо зареєстрованих користувачів про суттєві зміни електронною поштою.

9. Zero Retention of Prompts and Completions

Because this question is the single most important one for an API gateway, we restate it here in concrete, testable terms.

We never log, persist, cache to disk, or otherwise retain any of the following:

  • The text or JSON body of any chat completion or completion request, including system messages, user messages, assistant messages, and tool/function call arguments and results.
  • The text or JSON body of any chat completion or completion response, including streamed deltas.
  • Embedding inputs and embedding output vectors.
  • Image generation prompts, image edit prompts, input image bytes, output image bytes, or image URLs.
  • Audio bytes for speech-to-text or text-to-speech, transcripts, or generated audio.
  • Files uploaded to /v1/files, vector store contents, or any document content.

We do log the following per-request metadata, and only for the purposes listed in section 2:

  • Account ID (so we can bill the correct account).
  • API key fingerprint, never the key itself.
  • UTC timestamp.
  • Source IP address (for abuse detection and rate-limit enforcement).
  • Target endpoint and target model name.
  • Prompt token count and completion token count, returned by the upstream provider.
  • HTTP status code and total request duration in milliseconds.

If our policy ever changes such that any item in the first list begins to be retained, we will publish the change here, bump the Last Updated date, and notify registered users by email at least seven days before the change takes effect.

10. Retention Periods

Concrete retention windows for everything we do keep:

  • Per-request metadata rows (the fields in section 9): retained for 30 days for usage display and billing reconciliation, then automatically deleted.
  • Aggregated, non-identifying daily counters (total tokens per account per model per day): retained for the lifetime of the account for the user-facing usage dashboard.
  • Account profile (email, name, hashed password or OAuth identity): retained while your account is active. Deleted within 30 days of account deletion.
  • Billing records and invoices: retained for the period required by applicable tax and accounting law (typically 7 years), in accordance with our payment processor's policies.
  • Web access logs at the edge (Cloudflare): retained per Cloudflare's standard retention, generally less than 30 days.

11. No AI Training on Your Data

We do not train, fine-tune, evaluate, benchmark, distill, or otherwise use any of your requests, responses, embeddings, images, audio, files, or metadata to develop any machine learning model, our own or a third party's. We do not sell or share data with anyone for AI training. The OpenAI store=false parameter is forwarded on supported endpoints so that the upstream provider also does not retain your data for training under their default consumer terms; our agreement with OpenAI is on their API tier, which by OpenAI's published policy excludes API traffic from training by default.

Контакти

З питаннями щодо конфіденційності зв’яжіться з нами за адресою [email protected].

Повідомлення надіслано

Ми відповімо вам протягом 2 робочих днів.

Зв’язатися з підтримкою

Маєте запитання або потрібна допомога? Надішліть нам повідомлення, і ми відповімо вам протягом 2 робочих днів.