aai-api.cloud
Home

Privacy Policy

Last updated: 2026-06-20

This Privacy Policy explains what data ai-api.cloud ("we", "us", "the service") collects, how we use it, and the choices you have. By using the service you agree to this policy.

How the service works

ai-api.cloud is an LLM API gateway. You send requests to OpenAI- and Anthropic-compatible endpoints using your API key; we authenticate the request, route it to the upstream model provider you call, meter usage, and return the result. We bill a prepaid balance in USD based on token usage.

Information we collect

You provide:

  • Account data — your email, name, optional organization and account settings.
  • Authentication — password hash and, if enabled, two-factor (TOTP) secret; or your Google sign-in identifier.
  • API keys — stored only as a secure hash. The raw key is shown once at creation and never again.
  • Support messages — the contents of support tickets you open.

Collected automatically:

  • Usage metadata — for each request: the model, protocol, token counts (input / output / cache), the charge and the status. Used for billing, your usage history and abuse prevention.
  • Billing records — balance, top-ups, invoices and charges.
  • Technical data — IP address and basic request metadata used for security, rate limiting and diagnostics.
  • Cookies and analytics — see the Cookies & analytics section below.

We do not require passport data, identity documents or photos to use the service.

Request content

We process the prompts and responses you send only as needed to route your request to the upstream provider and return the result. We do not use your message content to train models. Operationally, content passes through our gateway and the upstream provider you call, which processes it under its own data policies.

How we use your information

  • Provide, operate and secure the service.
  • Authenticate you and manage your account, keys and balance.
  • Meter usage and bill your prepaid balance.
  • Prevent fraud and abuse, and enforce rate and spending limits.
  • Respond to support requests.
  • Understand aggregate site traffic to improve the product.

Information sharing

We do not sell your personal data. We share data only with:

  • Upstream model providers — your request payload is sent to the provider required to serve the model you call.
  • Infrastructure and analytics providers — including Google Analytics (see below), our hosting and our payment infrastructure, strictly to operate the service.
  • With your consent — in other cases where you have explicitly agreed to the sharing.
  • When required by law — to comply with a lawful request or to protect our rights, users and the service.

Cookies & analytics

We use a small number of cookies:

  • Essential — a session cookie (aiapi.sid) to keep you signed in, a language preference (aiapi_lang), and a consent cookie (aiapi_cookie_consent) that records your choice.
  • AnalyticsGoogle Analytics 4 (measurement ID G-WZG4WNN3EB) to measure aggregate, non-identifying site traffic. Analytics is not loaded on the admin area and is not used to profile individuals.

On your first visit we show a cookie banner. If you choose Accept, we store the aiapi_cookie_consent cookie for 12 months and enable analytics. If you do not agree, you are redirected away from the site and no analytics cookies are set. You can withdraw consent at any time by clearing the cookie in your browser, after which the banner will appear again on your next visit.

Data retention

Account, key, usage and billing records are retained while your account is active and for as long as required for accounting and legal obligations. Support tickets are kept until the matter is resolved and then archived or removed. You may request deletion of your account at any time.

Data security

API keys are stored hashed; upstream provider credentials are encrypted at rest. Access to operational data is restricted. Errors are surfaced explicitly — we do not silently reroute, substitute or alter your requests. No method of transmission or storage is completely secure, but we apply commercially appropriate safeguards. By using the Service, you understand and accept that any transmission of data over the internet always involves risks that cannot be fully eliminated. We are not liable for data loss caused by third-party actions or by your own negligence (for example, sharing your API key or password).

Your rights and choices

  • Rotate or disable API keys at any time in your cabinet.
  • Access, correct or delete your account data by contacting us.
  • Withdraw analytics consent by clearing the consent cookie.
  • Depending on your location, you may have additional rights (access, portability, erasure) under applicable law.

Children's privacy

The service is intended for users aged 18 and older. We do not knowingly collect data from children; if we learn we have, we will delete it.

Pricing and service changes

Prices, available models, model variants and their capabilities may change at any time at our discretion. We may offer the same model through different providers or configurations with different parameters and capabilities, and we may add, change or remove models, providers and prices without prior coordination with, or notice to, you. The price and configuration that apply to a request are those in effect at the moment the request is made; each request is metered and charged at that point, and your usage history shows the exact figures.

Changes to this policy

We may update this policy at any time. Updates are reflected by the "Last updated" date above. We do not notify you of changes — you are responsible for periodically reviewing this policy for updates. Continued use of the service after an update means you accept the updated policy.

Contact