Privacy

What we collect, why we collect it, and what happens to your prompts.

Last updated 4 August 2026

What we collect

Account details you give us: your email address, and optionally a display name and company.

Usage records for each API request: timestamp, the model requested, token counts, computed cost, the API key used, and the response status. We record these because they are what your bill and your dashboard are built from.

Operational data needed to run the service: IP address and request metadata, used for rate limiting, abuse prevention, and debugging.

Prompt and response content

We do not store the content of your prompts or model responses as part of normal operation. Requests are relayed to the upstream provider and the response is streamed back to you.

Usage records retain metadata about a request — model, token counts, cost, latency — not the text of the request or reply.

Upstream providers

To serve a request we forward it to the model provider you selected. That provider receives the content of your request and handles it under their own terms and privacy policy.

Which provider receives a request depends on the model you name and on routing and failover. If your data must stay with a specific provider or in a specific region, tell us before you send production traffic and we will confirm what we can support.

How we use it

To operate the service: authenticate keys, route requests, meter usage, and bill you.

To keep the service working and secure: investigate errors, prevent abuse, and enforce limits.

To contact you about your account and material changes to the service.

We do not sell your data, and we do not use your prompts or responses to train models.

Retention

Usage records are retained while your account is open, because they are your billing history.

If you close your account we delete account details and usage records, except where we must keep records to meet a legal, tax, or accounting obligation.

Your rights

You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. Write to privacy@unifyapi.ai and we will respond.

Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA. We will honour them.

Security

Traffic to the API and the console is encrypted in transit. API keys are stored so that they can be verified but not recovered — if you lose a key, create a new one and revoke the old one.

You can scope each key to specific models and give it its own spend limit, so a leaked key has a bounded blast radius.

Changes and contact

If we make a material change to this policy we will tell account holders before it takes effect.

Questions: privacy@unifyapi.ai