隐私政策
最后更新:April 17, 2026
1. 我们收集的信息
当你使用 Smart AIPI 时,我们会收集:
- 账户信息: 你注册时提供的邮箱地址、姓名和认证凭据。
- 使用数据: API 请求元数据,包括所用模型、token 计数、时间戳和 IP 地址。我们不存储你的 prompts 或 completions 内容。
- 支付信息: 账单信息由我们的支付服务商(Polar)处理。我们不存储信用卡号。
- Cookies: 用于认证的会话 cookies,以及用于了解站点使用情况的分析 cookies(Umami,自托管)。
2. 我们如何使用你的信息
- 提供并维护 Smart AIPI 服务
- 处理账单和 credit 交易
- 发送与账户相关的通知(验证、付款确认、credit 过期提醒)
- 监控服务健康状态并防止滥用
- 基于汇总使用模式改进我们的服务
3. 数据处理
Smart AIPI 作为 AI 模型提供商的代理。你的 API 请求会被转发给上游提供商(OpenAI)以生成响应。我们不会存储、记录或使用你的 prompts 或 completions 内容进行训练。仅会为计费目的保留元数据(token 数、所用模型、成本)。
4. 数据存储与安全
- 账户数据存储在托管于 Turso(分布式 SQLite)的加密数据库中。
- API keys 以不可逆哈希形式存储。明文 key 仅在创建时显示一次,之后无法找回。
- 所有连接都使用 TLS 加密。
- 基础设施托管在 Fly.io,数据中心位于北美和欧洲。
5. 数据共享
我们不会出售你的个人数据。我们仅会与以下对象共享数据:
- AI 模型提供商 (OpenAI)用于处理你的 API 请求
- 支付处理方 (Polar)用于处理账单
- 基础设施提供商 (Fly.io、Turso、Cloudflare)用于托管和交付我们的服务
6. 你的权利
你可以:
- 通过 dashboard 访问你的账户数据
- 通过联系支持删除你的账户及相关数据
- 导出你的使用历史
- 随时吊销 API keys
7. Cookie
我们使用必要 cookies 来维持认证会话,并使用可选的分析 cookies(自托管 Umami);这些 cookies 不会跨站追踪你,也不会使用个人标识符。
8. 本政策的变更
我们可能会不时更新本隐私政策。如有重大变更,我们会通过电子邮件通知已注册用户。
9. Zero Retention of Prompts and Completions
Because this question is the single most important one for an API gateway, we restate it here in concrete, testable terms.
We never log, persist, cache to disk, or otherwise retain any of the following:
- The text or JSON body of any chat completion or completion request, including system messages, user messages, assistant messages, and tool/function call arguments and results.
- The text or JSON body of any chat completion or completion response, including streamed deltas.
- Embedding inputs and embedding output vectors.
- Image generation prompts, image edit prompts, input image bytes, output image bytes, or image URLs.
- Audio bytes for speech-to-text or text-to-speech, transcripts, or generated audio.
- Files uploaded to /v1/files, vector store contents, or any document content.
We do log the following per-request metadata, and only for the purposes listed in section 2:
- Account ID (so we can bill the correct account).
- API key fingerprint, never the key itself.
- UTC timestamp.
- Source IP address (for abuse detection and rate-limit enforcement).
- Target endpoint and target model name.
- Prompt token count and completion token count, returned by the upstream provider.
- HTTP status code and total request duration in milliseconds.
If our policy ever changes such that any item in the first list begins to be retained, we will publish the change here, bump the Last Updated date, and notify registered users by email at least seven days before the change takes effect.
10. Retention Periods
Concrete retention windows for everything we do keep:
- Per-request metadata rows (the fields in section 9): retained for 30 days for usage display and billing reconciliation, then automatically deleted.
- Aggregated, non-identifying daily counters (total tokens per account per model per day): retained for the lifetime of the account for the user-facing usage dashboard.
- Account profile (email, name, hashed password or OAuth identity): retained while your account is active. Deleted within 30 days of account deletion.
- Billing records and invoices: retained for the period required by applicable tax and accounting law (typically 7 years), in accordance with our payment processor's policies.
- Web access logs at the edge (Cloudflare): retained per Cloudflare's standard retention, generally less than 30 days.
11. No AI Training on Your Data
We do not train, fine-tune, evaluate, benchmark, distill, or otherwise use any of your requests, responses, embeddings, images, audio, files, or metadata to develop any machine learning model, our own or a third party's. We do not sell or share data with anyone for AI training. The OpenAI store=false parameter is forwarded on supported endpoints so that the upstream provider also does not retain your data for training under their default consumer terms; our agreement with OpenAI is on their API tier, which by OpenAI's published policy excludes API traffic from training by default.
联系方式
如有与隐私相关的问题,请通过以下方式联系我们: [email protected].