Legal
Privacy
Last updated 2 August 2026.
What we collect
An email address, so you can sign in and so we can tell you about a payment or an incident. If you sign in with Google we also receive the name and avatar on that Google account, because Google sends them with the sign-in.
A record of every request you make: which model, how many tokens in and out, what it cost, how long it took, and what we paid the supplier. This is what the usage page and your balance are built from. We also note the shape of the call: whether it was streamed, whether it used tools or asked for structured output, how many tokens you allowed it, and how much of your prompt the supplier served from cache. All of that is about the call, never about what was in it.
A record of every request we REFUSED, kept for ninety days: which model you asked for, the status we returned, and our own error code. Nothing else. We added this because we could not otherwise tell that somebody had hit the same wall a dozen times, which is the moment we would most want to help.
A record of every top-up and every movement in your balance, including the reference the payment processor gave us and, when you paid by card, the card's issuing country, so a payment can be traced if it goes missing.
Where you came from, recorded once when you create an account: the site that linked you here (the domain only, never the full address), any campaign tag in the link, the first page you landed on, and the country the request came from. We keep it to know which of the things we write is worth writing. It is stored in a cookie we set ourselves, it is recorded once and never updated, and it is never sold or shared.
Whether you arrived on a phone or a computer, as one of those two words. Not a device fingerprint, not a model number, not a screen size. We build for phones on unreliable connections and we would rather know whether that is right than assume it.
Nothing else. There is no analytics script, no advertising pixel, and no third-party tracker on this site. The two entries about where you came from and what you signed up on are recorded by our own server, at the moment you create your account, and never updated afterwards.
What we do not collect
Two things people reasonably assume we keep, and do not.
We do not store your prompts or the model's replies. The request passes through to the model and the reply passes back to you; what we write down is the token counts and the cost. There is no column in our database that could hold the text, which is a stronger guarantee than a policy promising not to look at it.
We do not build a profile of you from what you send. To decide which models to carry we count, across all traffic together, roughly what share of requests are written in which language and which country they come from. Those counts are never attached to you, your account or any request of yours. There is no column anywhere linking a language or a per-request location to a person, and there will not be. We chose it that way because the language somebody writes in says something about who they are, and that is not a thing we want a record of.
We do not store card numbers, and we never see them. Payment happens on the processor's own page — Flutterwave's or Polar's, whichever you choose — and what comes back to us is a reference, an amount, and, on a card payment, the two-letter country the card was issued in. There is no card on file to charge you later, which is also why every top-up is something you initiate.
Your API keys
A key is shown to you once, at the moment you create it, and only a cryptographic hash of it is stored. We cannot show it to you again, and we cannot recover it, because we do not have it. If you lose a key, revoke it and make another.
Revoking a key stops it working immediately, including clearing it from our cache. A key you have revoked cannot be used again even by us.
Who else processes your data
Running this service means other companies handle some of it. These are all of them.
Cloudflare hosts the service and stores the database, the session cache and uploaded files. No model runs on Cloudflare, and no prompt is sent to them.
DeepInfra runs every model. Your prompt is sent to them to be answered. They are the supplier whose terms and prices are recorded in our own documentation.
Flutterwave and Polar take payments and hold the payment details you enter on their pages. Which one you use is your choice at checkout.
Google, only if you choose to sign in with a Google account.
We do not sell data to anyone, and we do not share it with anyone not on this list.
Cookies
One cookie, named session, set when you sign in. It holds a random token that identifies your session and nothing else. It is HTTP-only, so scripts on the page cannot read it, and it expires after thirty days.
There is no cookie banner because there is nothing to consent to: we set no analytics or advertising cookies. Your currency preference is kept in your browser's local storage and never leaves it.
How long we keep things
Your account, balance and its history stay until you ask us to delete the account, because they are the record of money you have paid us.
Usage records stay for the same reason: they are what explains a charge. Refused requests are kept for ninety days and then deleted, because after that they explain nothing a total does not. Speed measurements are kept for ninety days; idempotency records for twenty-four hours.
Ask us to delete your account and we delete it, along with your keys and your usage history. We keep the minimum record of completed payments that we are required to keep once there is a registered company with tax obligations, and this page will say exactly what that is when it exists.
Your choices
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Write to the address below and a person will answer.
You can revoke any API key at any time from the dashboard, without asking us.
Questions about anything on this page go to support@dawnstackai.com.