Chính sách quyền riêng tư
Cập nhật lần cuối: April 17, 2026
1. Thông tin chúng tôi thu thập
Khi bạn sử dụng Smart AIPI, chúng tôi thu thập:
- Thông tin tài khoản: Địa chỉ email, tên và thông tin xác thực khi bạn đăng ký.
- Dữ liệu sử dụng: Metadata của API request bao gồm model được dùng, số lượng token, mốc thời gian và địa chỉ IP. Chúng tôi không lưu nội dung prompt hoặc completion của bạn.
- Thông tin thanh toán: Thông tin thanh toán được xử lý bởi nhà cung cấp thanh toán của chúng tôi (Polar). Chúng tôi không lưu số thẻ tín dụng.
- Cookie: Cookie phiên cho xác thực và cookie phân tích (Umami, tự host) để hiểu cách trang web được sử dụng.
2. Cách chúng tôi sử dụng thông tin của bạn
- Để cung cấp và duy trì dịch vụ Smart AIPI
- Để xử lý thanh toán và giao dịch credit
- Để gửi thông báo liên quan đến tài khoản (xác minh, xác nhận thanh toán, cảnh báo credit sắp hết hạn)
- Để giám sát tình trạng dịch vụ và ngăn chặn lạm dụng
- Để cải thiện dịch vụ dựa trên các mẫu sử dụng tổng hợp
3. Xử lý dữ liệu
Smart AIPI hoạt động như một proxy tới các nhà cung cấp AI model. API request của bạn được chuyển tiếp tới các nhà cung cấp upstream (OpenAI) để tạo phản hồi. Chúng tôi không lưu, ghi log hoặc huấn luyện trên nội dung prompt hay completion của bạn. Chỉ metadata (số token, model được dùng, chi phí) được giữ lại cho mục đích thanh toán.
4. Lưu trữ dữ liệu và bảo mật
- Dữ liệu tài khoản được lưu trong cơ sở dữ liệu mã hóa được host trên Turso (SQLite phân tán).
- API keys được lưu dưới dạng hash không thể đảo ngược. Key dạng plain text chỉ hiển thị một lần khi tạo và không thể lấy lại.
- Mọi kết nối đều sử dụng mã hóa TLS.
- Hạ tầng được host trên Fly.io với các trung tâm dữ liệu ở Bắc Mỹ và châu Âu.
5. Chia sẻ dữ liệu
Chúng tôi không bán dữ liệu cá nhân của bạn. Chúng tôi chỉ chia sẻ dữ liệu với:
- Nhà cung cấp AI model (OpenAI) để xử lý API request của bạn
- Bộ xử lý thanh toán (Polar) để xử lý thanh toán
- Nhà cung cấp hạ tầng (Fly.io, Turso, Cloudflare) để host và cung cấp dịch vụ của chúng tôi
6. Quyền của bạn
Bạn có thể:
- Truy cập dữ liệu tài khoản của bạn qua dashboard
- Xóa tài khoản và dữ liệu liên quan bằng cách liên hệ hỗ trợ
- Xuất lịch sử sử dụng của bạn
- Thu hồi API keys bất kỳ lúc nào
7. Cookie
Chúng tôi sử dụng cookie thiết yếu cho phiên xác thực và cookie phân tích tùy chọn (Umami tự host) không theo dõi bạn trên các trang khác và không sử dụng định danh cá nhân.
8. Thay đổi đối với chính sách này
Chúng tôi có thể cập nhật chính sách quyền riêng tư này theo thời gian. Chúng tôi sẽ thông báo cho người dùng đã đăng ký về các thay đổi quan trọng qua email.
9. Zero Retention of Prompts and Completions
Because this question is the single most important one for an API gateway, we restate it here in concrete, testable terms.
We never log, persist, cache to disk, or otherwise retain any of the following:
- The text or JSON body of any chat completion or completion request, including system messages, user messages, assistant messages, and tool/function call arguments and results.
- The text or JSON body of any chat completion or completion response, including streamed deltas.
- Embedding inputs and embedding output vectors.
- Image generation prompts, image edit prompts, input image bytes, output image bytes, or image URLs.
- Audio bytes for speech-to-text or text-to-speech, transcripts, or generated audio.
- Files uploaded to /v1/files, vector store contents, or any document content.
We do log the following per-request metadata, and only for the purposes listed in section 2:
- Account ID (so we can bill the correct account).
- API key fingerprint, never the key itself.
- UTC timestamp.
- Source IP address (for abuse detection and rate-limit enforcement).
- Target endpoint and target model name.
- Prompt token count and completion token count, returned by the upstream provider.
- HTTP status code and total request duration in milliseconds.
If our policy ever changes such that any item in the first list begins to be retained, we will publish the change here, bump the Last Updated date, and notify registered users by email at least seven days before the change takes effect.
10. Retention Periods
Concrete retention windows for everything we do keep:
- Per-request metadata rows (the fields in section 9): retained for 30 days for usage display and billing reconciliation, then automatically deleted.
- Aggregated, non-identifying daily counters (total tokens per account per model per day): retained for the lifetime of the account for the user-facing usage dashboard.
- Account profile (email, name, hashed password or OAuth identity): retained while your account is active. Deleted within 30 days of account deletion.
- Billing records and invoices: retained for the period required by applicable tax and accounting law (typically 7 years), in accordance with our payment processor's policies.
- Web access logs at the edge (Cloudflare): retained per Cloudflare's standard retention, generally less than 30 days.
11. No AI Training on Your Data
We do not train, fine-tune, evaluate, benchmark, distill, or otherwise use any of your requests, responses, embeddings, images, audio, files, or metadata to develop any machine learning model, our own or a third party's. We do not sell or share data with anyone for AI training. The OpenAI store=false parameter is forwarded on supported endpoints so that the upstream provider also does not retain your data for training under their default consumer terms; our agreement with OpenAI is on their API tier, which by OpenAI's published policy excludes API traffic from training by default.
Liên hệ
Nếu có câu hỏi liên quan đến quyền riêng tư, hãy liên hệ chúng tôi tại [email protected].