Privacy Policy
1. Who we are
ainetcafe is operated by Fedimoss (the Hong Kong company operating ainetcafe; legal name to be inserted on execution of any written agreement). We are the controller of your account data and the processor of the content you send through the API. Contact: [email protected].
2. What we collect
| Category | Examples | Why |
|---|---|---|
| Account data | Email, username, password hash, invite code, language preference | Create and secure your account, send verification and balance alerts |
| Billing data | Top-up amounts, payment provider references, receipts. We never see full card numbers; the payment provider holds them. | Charge you, prevent fraud, keep accounting records |
| Usage metadata | Timestamp, model, token counts, latency, status code, key name, request ID, client IP (only on error and consumption logs) | Bill accurately, enforce quotas and rate limits, debug failures, detect abuse |
| Request content | Prompts, tool definitions, images, and model outputs | Only to generate the response |
3. Request content
- Prompts and outputs pass through our gateway to the model and back. We do not store prompt or output content by default. Content may be held transiently in memory and in short-lived error diagnostics.
- Usage metadata (not content) is kept for 30 days for billing and audit, then deleted or aggregated.
- Committed and core customers can specify retention, logging and region terms in the Data Processing Addendum.
4. Where data is processed
Self-serve and trial traffic is served from our own clusters in China; account and billing systems run on infrastructure we operate or on the payment provider's systems. For committed and core tiers, the serving region is agreed at contract time and can be located to meet your requirements. By using the self-serve service you consent to processing in these locations.
5. Sharing
We share data only with: payment providers (Stripe, WeChat Pay) to take payment; email delivery providers to send account emails; and authorities when required by law. We do not sell personal data and do not share request content with advertisers.
6. Security
Traffic is encrypted in transit with TLS. API keys are stored hashed and shown once. Access to production systems is limited to staff who operate the service. If we learn of a breach affecting your data we will notify affected customers within 72 hours of confirming it.
7. Your rights
You can view and export your usage logs in the console, revoke keys, and close your account. To access, correct or delete account data, or to object to processing, email [email protected]. We answer within 30 days.
8. Cookies
The console uses a session cookie for login and local storage for preferences such as language. We do not run third-party advertising trackers.
9. Changes
Material changes to this policy are announced on the console at least 14 days before they take effect.