How data is handled.
This Policy is an information document. It does not replace a separate consent where the law requires one. Consent is given separately from the Offer.
1. General
1.1. This Policy does not replace a separate consent where the law requires one. Consent is given separately from the Offer.
2. Principles and grounds
2.1. The Operator processes data lawfully, fairly and in proportion to stated purposes.
2.2. Grounds: performance of a contract at the subject’s initiative; legal duties; consent where required; the Operator’s legitimate interests; protection of life and health.
2.3. For registration and contract performance, consent is not the sole ground if processing is objectively needed for the account, authentication, metering and security.
2.4. Optional data is voluntary. Refusal of it cannot be a ground to refuse a consumer contract.
3. Categories
3.1. Account: email, name, internal ID, registration date, settings, password hash.
3.2. Access: identifiers and hashes of API keys, prefixes, limits, dates of creation, revocation and last use.
3.3. Payment and contract: amount, currency, date, status and method, tariff and refund data. Full card details are not requested — they are processed by the payment provider.
3.4. Use: model, mode, request time, token counts, debit volume, error status.
3.5. Technical: IP, browser and device data, cookies, login events and suspicious activity.
3.6. Interaction content: request texts, files, AI answers — to the extent needed for routing and processing.
3.7. Support: the text of an appeal, attachments, account facts given to resolve it.
3.8. The Operator does not aim to process special categories of personal data. The User should not put them in requests without need.
4. Purposes
4.1. Registration, account, authentication, API-key management.
4.2. Contract performance: tariff activation, routing, delivery of an AI result, metering.
4.3. Taking payments, settlement documents, refunds, tax duties.
4.4. Information security, fraud and abuse prevention.
4.5. Technical diagnosis, quality control, feature development, anonymised statistics.
4.6. Support, claims, lawful requests of authorities and courts.
4.7. Marketing messages only with a separate consent where required. Refusal of ads does not affect service notices.
5. API requests and AI content
5.1. To fulfil a request its content is sent to an external AI provider or compute supplier.
5.2. The User decides the content. If a request contains third-party data, the User confirms a lawful basis to send it.
5.3. Do not send state secrets, unlawfully disclosed trade secrets, card data, passwords or other secrets unless that transfer is necessary and lawful.
5.4. An external provider may apply its own storage and security rules. The set of providers may change with the catalogue.
6. Recipients
6.1. Access is limited to persons who need it for a concrete purpose and who must keep confidentiality.
6.2. Data may be processed, as needed, by hosting and cloud suppliers; external AI providers; payment organisations; email services; support contractors.
6.3. An anti-bot service may receive IP and browser parameters. A move into a messenger is then governed by that messenger’s rules.
6.4. Authorities receive data only on a lawful demand.
7. Location and cross-border transfer
7.1. Recording, systematisation and storage of personal data are performed using databases in the Operator’s operating territory except where the law allows otherwise.
7.2. Routing a request to a foreign AI provider may entail a cross-border transfer of data in the request. Such transfer is made in compliance with applicable data-protection law.
8. Cookies and local storage
8.1. The Service uses technically necessary cookies and local storage for session, protection, settings and the interface.
8.2. Optional analytics or ads are introduced only after the required consent.
8.3. The User may limit cookies in the browser. Blocking necessary ones may make functions unavailable.
9. Retention
9.1. Account data is kept while the Service is used, then not more than three years unless a longer term is required by law.
9.2. Payment data is kept at least five years (tax-document term).
9.3. Detailed API-request logs are kept 24 hours, then deleted, with aggregated statistics retained.
9.4. Images are kept 12 hours. Chat history until the User deletes the chat or the account ends.
9.5. Support correspondence is kept until the issue is resolved and then up to three years.
9.6. Backups may hold deleted data up to six months.
9.7. After the purpose is reached, data is destroyed or anonymised.
10. Protection
10.1. Legal, organisational and technical measures: access control, hashing of passwords and API keys, encryption, logging, backups, incident response.
10.2. Transfer over the Internet cannot be absolutely risk-free. The Operator takes measures required by law but does not guarantee impossibility of every incident.
10.3. The User is responsible for the password and API keys and must revoke compromised keys.
11. Rights of the subject
11.1. The subject may obtain information on processing; demand rectification, blocking or destruction; withdraw consent; object; demand stop of ads.
11.2. Withdrawal of consent does not stop processing that has another lawful ground (contract, tax, security).
11.3. The subject may complain to a supervisory authority or a court.
12. Access, correction, deletion
12.1. A request is sent through the support channel on the contacts page, stating the account and the demand.
12.2. The Operator may ask for extra verification to prevent disclosure of another person’s data.
12.3. Data is provided, corrected or deleted in the terms set by law.
12.4. Account deletion ends access and revokes API keys. Data that must be kept by law is isolated.
13. Third parties and minors
13.1. A User who sends another person’s data must have a lawful basis.
13.2. The Service is not intended for a minor to conclude a paid contract on their own.
13.3. If data obtained without a proper basis is found, the Operator may restrict processing.
14. Changes
14.1. The Operator may update this Policy. A new edition applies from the stated date and does not legalise processing that was unlawful before the update.
14.2. If a change needs a new consent, the Operator asks for it separately.
14.3. The current edition is at privacy.html on this Site.
15. Contacts
15.1. Operator: NullRoute desk.
15.2. Channel: contacts page.