开发文档

开发文档

Privacy Policy / 隐私政策模板

隐私政策_Privacy_Policy.md

Privacy Policy / 隐私政策模板

版本:v0.1 日期:2026-05-11 状态:模板,需律师审阅后上线

---

1. Overview / 概述

[Company Legal Name] operates [Platform Name], an AI API gateway and developer platform. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data.

If you use the Services on behalf of an organization, your organization may be the controller of personal data submitted through its applications, and we may act as a processor or service provider depending on the context and agreement.

---

2. Data We Collect / 我们收集的数据

Account data:

  • Name.
  • Email.
  • Password hash.
  • Country/region.
  • Language preference.
  • Organization and team membership.

Authentication and security data:

  • Login time.
  • IP address.
  • Device/browser metadata.
  • Session identifiers.
  • 2FA status.

API usage metadata:

  • API key prefix.
  • Request ID.
  • Model requested and resolved.
  • Token counts.
  • Latency.
  • Status code and error code.
  • Provider route metadata.
  • Cost and charge.

Payment and billing data:

  • Payment order ID.
  • Payment method type.
  • Amount, currency, fees.
  • Payment processor references.
  • Billing name, address, tax ID if provided.
  • Refund and chargeback records.

Support data:

  • Tickets.
  • Messages.
  • Attachments.
  • Contact channels such as email, WhatsApp, Telegram, or Discord if provided.

Debug content:

  • Prompt, completion, files, or tool call content only when debug logging is enabled, required for a support case, or necessary for security, abuse, legal, or compliance review.

---

3. Data We Do Not Collect by Default / 默认不收集的数据

By default, we do not store full prompt/completion content for normal API traffic.

We do not intentionally collect sensitive personal data unless you submit it or enable features that process it. You should avoid submitting health, biometric, financial account, government ID, children’s data, or other sensitive data unless you have a lawful basis and appropriate safeguards.

---

4. How We Use Data / 数据用途

We use data to:

  • Provide and operate the Services.
  • Authenticate users and secure accounts.
  • Route API requests to model providers.
  • Calculate usage and billing.
  • Process payments, refunds, and disputes.
  • Provide support.
  • Detect abuse, fraud, and security incidents.
  • Monitor reliability and performance.
  • Comply with legal, tax, accounting, and regulatory obligations.
  • Enforce Terms and Acceptable Use Policy.

We do not use customer prompts or outputs to train our own AI models unless separately agreed in writing.

Third-party model providers may process API content according to their terms and data processing practices. We will document provider-specific data behavior in the model/provider documentation where commercially feasible.

---

5. Legal Bases / 处理依据

Depending on jurisdiction, we process personal data based on:

  • Contract performance.
  • Legitimate interests.
  • Consent.
  • Legal obligation.
  • Protection against fraud, abuse, and security threats.

For enterprise customers, processing roles and legal bases may be further specified in a Data Processing Addendum.

---

6. Sharing and Disclosure / 数据共享

We may share data with:

  • AI model providers required to fulfill API requests.
  • Payment processors.
  • Cloud hosting and infrastructure providers.
  • Email and notification providers.
  • Customer support tools.
  • Analytics and monitoring providers.
  • Professional advisors.
  • Government, courts, or regulators where required by law.
  • Acquirers or successors in business transactions.

We do not sell personal data.

---

7. International Transfers / 跨境传输

We may process and transfer data across countries where we, our infrastructure providers, payment processors, model providers, or support providers operate.

Where required, we use appropriate safeguards such as contractual clauses, data processing agreements, access controls, encryption, and vendor due diligence.

Target jurisdictions such as UAE, Saudi Arabia, Nigeria, Kenya, South Africa, Indonesia, Philippines, Malaysia, and Vietnam may impose additional requirements. These must be reviewed before targeted launch in each country.

---

8. Retention / 数据保留

Default retention:

  • Account data: while account is active, then as required for legal and audit purposes.
  • API usage metadata: at least 12 months or as needed for billing, security, and analytics.
  • Prompt/completion debug logs: default 7 days if enabled.
  • Payment and wallet records: retained as required for tax, accounting, disputes, AML, and audit.
  • Admin audit logs: at least 2 years.
  • Support tickets: retained as needed for support and audit.

Users may request deletion of certain data, but payment, wallet, security, legal, and audit records may be retained where required.

---

9. Security / 安全措施

We use technical and organizational measures such as:

  • Encryption in transit.
  • Encryption or hashing of sensitive credentials.
  • Provider key encryption.
  • Role-based access control.
  • Audit logging.
  • Rate limiting.
  • Monitoring and alerting.
  • Access reviews.
  • Backup and recovery controls.

No system is completely secure. Users are responsible for protecting their own API keys and account credentials.

---

10. User Rights / 用户权利

Depending on your jurisdiction, you may have rights to:

  • Access personal data.
  • Correct inaccurate data.
  • Delete data.
  • Object to processing.
  • Restrict processing.
  • Data portability.
  • Withdraw consent.
  • Complain to a supervisory authority.
  • Avoid certain automated decisions.

Submit requests to [Privacy Email]. We may verify identity before processing requests.

---

11. Cookies / Cookie

We use cookies and similar technologies as described in the Cookie Policy.

---

12. Children / 儿童

The Services are not directed to children under 18. Users must not submit children’s personal data unless they have legal authority and the use is permitted by applicable law and our policies.

---

13. Changes / 政策变更

We may update this Privacy Policy. Material changes will be notified through the platform, website, or email.

---

14. Contact / 联系方式

Privacy contact: [Privacy Email] Company: [Company Legal Name] Address: [Company Address]