Privacy Policy
Last updated: September 15, 2026
Information we collect
- Account data: your email address and authentication records.
- Usage records: time, model, endpoint, token counts, credits charged and job status for each request.
- Payment records: order ID, amount and currency provided by Polar. We never receive or store card details.
- Technical data: IP address and user agent in server logs, kept for security and abuse prevention.
Prompts and outputs
The content of your requests is sent to the relevant AI model provider solely to produce your result. We do not use your prompts or outputs to train models, and we do not store prompt or completion text in usage records. Generated media files are stored temporarily so you can download them and are deleted automatically.
How we use data
To provide and bill the Service, prevent fraud and abuse, provide support, and communicate important account notices. We do not sell personal data.
Sub-processors
- Supabase — authentication and database.
- Polar — payments, tax and invoicing (merchant of record).
- AI model providers — process requests to generate outputs.
- Hosting provider — servers that run the API.
Retention
Usage records are kept for up to 30 days in the dashboard and longer in aggregated billing records as required for accounting. Account data is kept while your account is active and deleted on request, except where retention is legally required.
Your rights
Depending on where you live (including under the GDPR and CCPA) you may request access to, correction, export or deletion of your personal data, or object to certain processing. Contact support@apillms.com and we will respond within 30 days.
Security
Data is encrypted in transit (TLS). Access to production systems is restricted. API keys can be rotated at any time from the dashboard.