Privacy Policy Effective: June 16, 2026
APIFlux respects your privacy. This policy explains what data we collect, how we use it, and your rights.
In short: We collect minimal data necessary to operate our service. We do not sell, share, or train AI models on your personal data or API request content. Your prompts, responses, and API keys are never stored after processing completes.
1. Information We Collect
1.1 Data You Provide
- Account information: Email address (when you register), optional profile details.
- API requests: We process your API requests in real-time but do not store the content of your prompts, completions, or uploaded files after the request is completed and delivered to you.
- Payment information: Processed securely through third-party payment providers (e.g., Stripe). We never store full credit card numbers on our servers.
1.2 Automatically Collected Data
- Server logs: IP address, timestamp, request method, endpoint URL, HTTP status code, user agent, and response time for security and operational purposes only.
- Usage metrics: Aggregated token counts, model names accessed, and response latency metrics — used solely for billing accuracy and infrastructure optimization.
| Data Category | Purpose | Retention |
| API Request Content | Fulfilling your request in real-time | Not retained after delivery |
| Email Address | Account management & support | Until account deletion |
| Server Logs (IP, etc.) | Security, abuse prevention, debugging | 30 days |
| Usage / Billing Metrics | Billing accuracy, capacity planning | 24 months |
| Payment Records | Transaction verification | 7 years (legal requirement) |
2. How We Use Your Data
- To provide, maintain, and improve the APIFlux gateway service.
- To accurately calculate usage-based billing and generate invoices.
- To detect and prevent abuse, fraud, or security threats.
- To respond to your inquiries and provide customer support.
- To comply with applicable laws and legal obligations.
3. What We Do Not Do
This is important:
- We do not sell your personal data to any third party.
- We do not use your API request content (prompts, responses) to train any AI model — ours or anyone else's.
- We do not share your data with advertisers or data brokers.
- We do not retain your prompt/response content beyond the time needed to deliver it back to you.
- We do not track you across other websites or applications using cookies or similar technologies for advertising purposes.
4. Data Sharing & Third Parties
We may share limited data only in these circumstances:
- Upstream AI providers: Your API requests are forwarded to upstream model providers (e.g., OpenAI, Anthropic, Google) to fulfill your requests. These providers' own privacy policies apply when they process your requests. APIFlux does not add additional data sharing on top of this required forwarding.
- Service providers: We use trusted third-party services for payments (Stripe), cloud infrastructure (AWS/GCP/Vercel), and email delivery. These providers process data under strict data processing agreements and only as necessary for their services.
- Legal requirements: When required by law, court order, or government regulation — we will notify users unless legally prohibited from doing so.
5. BYOK (Bring Your Own Key)
If you use APIFlux's BYOK mode with your own provider API keys:
- Your API keys are encrypted at rest using AES-256 encryption.
- APIFlux routes your requests using your key directly to the specified upstream provider.
- We do not log, inspect, or retain the content of BYOK requests beyond what is needed for routing.
- You remain responsible for compliance with the upstream provider's terms of service when using BYOK.
6. Data Security
- All data in transit is protected using TLS 1.3 encryption.
- Sensitive data at rest (API keys, account credentials) is encrypted using AES-256.
- We follow industry-standard security practices including regular vulnerability assessments, access controls, and audit logging.
- Access to personal data is restricted to authorized personnel who need it for their job functions.
7. Your Rights (GDPR / Applicable Law)
Depending on your jurisdiction, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate personal data.
- Deletion: Request deletion of your personal data ("right to be forgotten").
- Portability: Receive your data in a structured, machine-readable format.
- Object: Object to certain types of data processing.
- Withdraw consent: Withdraw previously given consent where processing is based on consent.
To exercise any of these rights, contact us at mingyuany96@gmail.com. We aim to respond within 30 days.
8. International Data Transfers
APIFlux operates infrastructure primarily in the Asia-Pacific region. Your data may be transferred to and processed in countries outside your country of residence when:
- Your API requests are routed through global CDN networks for optimal latency.
- Upstream AI providers you choose to access are hosted in other jurisdictions.
When such transfers occur, we ensure appropriate safeguards are in place (e.g., Standard Contractual Clauses, reliance on adequacy decisions).
9. Children's Privacy
APIFlux's services are not directed to individuals under the age of 16. We do not knowingly collect personal data from children. If we learn we have collected such data, we will delete it promptly.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email to registered users at least 30 days before taking effect. The "Effective" date at the top of this page indicates the most recent version.
Contact Us