法律条款

隐私政策

APIArc 会处理哪些数据、保留哪些数据,以及请求发送至 AI 提供商时会发生什么。

生效日期
2026年8月2日

Your model content passes through APIArc. It does not stay here.

In the standard service, APIArc does not persist prompts, input files, or model outputs after a request is completed, and we do not use that content to train models. The selected AI provider still receives the content needed to fulfill your request under its own policies.

Scope

This Privacy Policy applies to APIArc websites, account console, APIs, and related services (the “Services”). It explains how APIArc (“we”, “us”, or “our”) handles information when you visit the site, create an account, purchase credits, or route model requests through APIArc.

This policy does not govern an independent AI provider’s handling of content. Provider processing is covered in AI providers.

Model content

To fulfill an API call, we transiently process the prompt, messages, files, tool inputs, and other content you submit, together with the model response (“Model Content”). We route that content to the provider serving the selected model and stream the response back to you.

  • We do not persist Model Content after the request completes as part of the standard APIArc gateway service.
  • We do not use Model Content to train our own or third-party models.
  • We may inspect content in memory only as needed to route the request, enforce technical limits, detect abuse, or provide an optional content-audit feature that your organization has expressly enabled.
  • The selected AI provider receives Model Content and may retain or use it according to the provider plan and policies that apply to the route.

Do not submit secrets, regulated data, or personal information unless you have confirmed that both APIArc and the selected provider are appropriate for your use case.

Data we collect

We collect the limited information needed to operate the Services:

  • Account data: name, email address, authentication details, preferences, and support communications.
  • Billing data: credit balance, purchases, invoices, transaction identifiers, and payment status. Payment processors handle full card or wallet credentials; APIArc does not store full card numbers.
  • Usage metadata: request time, selected model and provider route, API key identifier, token or unit counts, latency, response status, and calculated cost. Usage logs do not include your prompt or model output.
  • Technical and security data: IP address, device or browser information, authentication events, and diagnostic or abuse-prevention logs.
  • Local preferences: information stored in your browser for sign-in, theme, and essential product settings.

How we use data

  • Provide, route, meter, and bill for API requests.
  • Authenticate users and protect accounts and API keys.
  • Monitor reliability, investigate errors, and improve performance.
  • Prevent fraud, abuse, security incidents, and unlawful activity.
  • Provide support and send essential service communications.
  • Comply with legal obligations and enforce our Terms of Service.

We do not sell personal information or use Model Content for targeted advertising.

AI providers

APIArc is a multi-provider gateway. When you select a model, the content required to answer your request is sent to the provider shown for that model. Provider availability and routing can change as the catalog evolves; check the model catalog before using a model with sensitive content.

The provider’s data controls, retention periods, training settings, subprocessors, and geographic processing rules are determined by its own service plan and policies. The principal provider policy pages are linked below for convenience. If those pages conflict with a provider agreement, the provider agreement controls.

OpenAI
GPT, o-series, image, and audio models
Anthropic
Claude models
Google
Gemini models
xAI
Grok models
DeepSeek
DeepSeek models

How we share information

We disclose information only as needed to operate the Services:

  • To the AI provider selected to fulfill a model request.
  • To infrastructure, authentication, payment, monitoring, email, and support vendors acting on our behalf.
  • To professional advisers, regulators, courts, or law enforcement when required by law or reasonably necessary to protect rights, safety, and service integrity.
  • In connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality measures.

Retention

  • Model Content: not persisted by the standard APIArc gateway after request completion.
  • Account data: kept while your account is active and for a limited period afterward as needed for account closure, disputes, security, or legal obligations.
  • Usage and billing records: kept as needed to provide statements, resolve billing questions, prevent fraud, and meet accounting or tax requirements.
  • Security and diagnostic logs: kept for a limited operational period unless an incident or legal obligation requires longer retention.

AI providers set their own retention periods. Review the links above and the provider plan applicable to your request.

Security

We use administrative, technical, and organizational safeguards designed to protect information, including access controls and encryption in transit. No system is completely secure. You are responsible for keeping account credentials and API keys confidential, limiting key permissions, and rotating a key if you suspect exposure.

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or export personal information, or to object to certain processing. You may update available profile information in the console or contact us to submit a request. We may need to verify your identity before completing it.

You can stop future API processing by revoking your keys and closing your account. This does not delete records we must keep for security, billing, dispute resolution, or legal compliance.

International use

APIArc and its providers may process information in countries other than your own. Those countries may have different data-protection rules. By choosing a provider route, you direct us to transmit Model Content to that provider’s infrastructure. Review provider information before using a route that may be subject to geographic restrictions.

Children

The Services are intended for developers and organizations, not for children. You must be at least 18 years old or the minimum age required to enter a contract where you live. We do not knowingly collect personal information from children through the Services.

Changes to this policy

We may update this policy as the Services, providers, or law change. We will post the revised policy here and update the effective date. If a change materially affects your rights, we will provide additional notice where reasonably required.

Contact

Questions or privacy requests can be sent to contact@apiarc.ai. Include enough detail for us to understand your request, but do not email API keys, passwords, or sensitive Model Content.