Legal
Privacy
Last updated 30 July 2026.
What we collect
An email address, so you can sign in and so we can tell you about a payment or an incident. If you sign in with Google we also receive the name and avatar on that Google account, because Google sends them with the sign-in.
A record of every request you make: which model, how many tokens in and out, what it cost, how long it took, and what we paid the supplier. This is what the usage page and your balance are built from.
A record of every top-up and every movement in your balance, including the reference the payment processor gave us, so a payment can be traced if it goes missing.
Nothing else. There is no analytics script, no advertising pixel, and no third-party tracker on this site.
What we do not collect
Two things people reasonably assume we keep, and do not.
We do not store your prompts or the model's replies. The request passes through to the model and the reply passes back to you; what we write down is the token counts and the cost. There is no column in our database that could hold the text, which is a stronger guarantee than a policy promising not to look at it.
We do not store card numbers, and we never see them. Payment happens on the processor's own page, and what comes back to us is a reference and an amount. There is no card on file to charge you later, which is also why every top-up is something you initiate.
Your API keys
A key is shown to you once, at the moment you create it, and only a cryptographic hash of it is stored. We cannot show it to you again, and we cannot recover it, because we do not have it. If you lose a key, revoke it and make another.
Revoking a key stops it working immediately, including clearing it from our cache. A key you have revoked cannot be used again even by us.
Who else processes your data
Running this service means other companies handle some of it. These are all of them.
Cloudflare hosts the service and stores the database, the session cache and uploaded files. Some models also run on Cloudflare's own inference platform.
DeepInfra runs most of the models. Your prompt is sent to them to be answered. They are the supplier whose terms and prices are recorded in our own documentation.
Flutterwave takes payments and holds the payment details you enter on their page.
Google, only if you choose to sign in with a Google account.
We do not sell data to anyone, and we do not share it with anyone not on this list.
Cookies
One cookie, named session, set when you sign in. It holds a random token that identifies your session and nothing else. It is HTTP-only, so scripts on the page cannot read it, and it expires after thirty days.
There is no cookie banner because there is nothing to consent to: we set no analytics or advertising cookies. Your currency preference is kept in your browser's local storage and never leaves it.
How long we keep things
Your account, balance and its history stay until you ask us to delete the account, because they are the record of money you have paid us.
Usage records stay for the same reason: they are what explains a charge. Speed measurements are kept for ninety days and then purged; idempotency records for twenty-four hours.
Ask us to delete your account and we delete it, along with your keys and your usage history. We keep the minimum record of completed payments that we are required to keep once there is a registered company with tax obligations, and this page will say exactly what that is when it exists.
Your choices
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to the address below and a person will answer.
You can revoke any API key at any time from the dashboard, without asking us.
Questions about anything on this page go to support@dawnstackai.com.