Privacy Policy
Last updated:
1. Information we collect
We collect the following categories of data:
- Account information: the email address and username provided at registration, plus the encrypted password.
- Usage data: API request logs such as request time, model, token count, and status code. We do not log the actual content of requests or responses.
- Billing data: funding records, account balance, and usage charges.
- Technical data: access logs such as IP address, user agent, and timestamp for fraud prevention and security.
2. Information we do not collect or use
- We do not record the text of API requests or responses, including your prompts and AI replies.
- We do not collect sensitive identity documents or full bank-card details.
- We do not sell user data to third parties.
- We do not use your data for cross-site tracking or advertising profiles.
3. How we use data
- To provide the API gateway, including billing, routing, and operational logs.
- To protect the Service through risk controls, anomaly detection, and abuse prevention.
- To improve service quality through performance monitoring and incident troubleshooting.
- To comply with legal obligations and valid law-enforcement requests.
4. Data storage and protection
- Data is stored in databases on servers located in Hong Kong.
- Passwords are stored using bcrypt hashing, and API keys are stored in hashed form.
- All data in transit is encrypted with HTTPS.
- API usage logs are retained for 90 days and then automatically deleted after billing reconciliation.
5. Sharing with third parties
We do not share your data with third parties except in the following circumstances:
- Upstream AI providers: to complete an API request, the request content is sent to the selected upstream provider, such as OpenAI or Anthropic. That data is governed by the upstream provider’s privacy policy.
- Payment processors: payment-related data is handled by the payment processor when you fund your account. We do not receive full payment credentials.
- Legal requirements: we may disclose relevant data when required to respond to a valid law-enforcement or legal request.
6. Your rights
- Access: you can review your usage history and account data in the console.
- Correction: you can update account information or contact us to correct inaccurate data.
- Deletion: you can request account closure, after which we will delete personal data within a reasonable period.
- Export: you can request an export of your account data.
7. Cookies
The Service uses necessary cookies to maintain login sessions. We do not use tracking cookies for advertising.
8. Children’s privacy
The Service is not intended for children under 13. If we discover that a child has registered, we will delete the account.
9. Contact us
For privacy questions, contact support@qionggeme.com.