Privacy policy
Privacy
1API Clubhandles account, API metadata, billing, support, and security data needed to operate a model access service. Routed API prompts and responses are not written to 1api's application databases or long-term logs. Gateway API keys are verified with a one-way digest rather than stored as plaintext.
Last updated: August 13, 2026.
- API content
- Not written to 1api application databases or long-term logs; a private continuation cache is the limited exception.
- Usage metadata
- Token counts, request status, timing, latency, and charge details stay auditable.
- Cold archive
- Eligible API metadata is archived in monthly batches after day 90 and retained for 2 years.
API content boundary
Routed API prompts and responses are not written to 1api's application databases or long-term logs. To support response continuation and one bounded recovery attempt, 1api may temporarily retain the minimum required conversation content in an isolated, idle-expiring continuation cache. Each successful cache write starts a rolling one-hour retention period. A successful continuation refreshes that period; cache reads, failed requests, and retries do not. The one-hour period can continue to refresh for an active conversation; there is no separate maximum lifetime. One hour after the last successful cache write, the content becomes unavailable to the Gateway and is scheduled for automatic deletion.
The cache is operationally separate from 1api's application databases and long-term logging systems. It is not exposed through customer or administrator consoles, is not a customer-accessible response archive, and is not used for training, analytics, or debugging. Usage, billing, security, and audit records may retain metadata that does not include prompt or response content. Upstream AI and infrastructure providers process and may retain content under their own terms, retention settings, and data controls. The boundary does not cover content a customer chooses to put into support tickets, customer-side logs, screenshots, or documentation.
Roles and scope
We act as a controller for account administration, authentication, billing, fraud prevention, security, support, compliance, and our own service operations.
We act as a processor or service provider when a customer sends personal data through a routed API request, to the extent required by the customer relationship and applicable law. The customer remains responsible for its application, instructions, notices, and controller role where applicable.
Upstream AI, payment, identity, hosting, and other service providers may act as independent controllers, processors, or subprocessors for their own processing. Our platform commitments do not change their independent terms, retention settings, abuse controls, or data practices.
Data we process
- Account identity, workspace membership, authentication state, and role metadata.
- API key metadata, delivery lane preferences, model preference settings, and key lifecycle records.
- Usage metadata such as token counts, request time, success or failure status, latency, public model id, delivery lane, and charge details.
- Billing records, credits, refunds, disputes, receipts, support tickets, and security signals.
Gateway API key handling
Gateway API keys are verified with a one-way digest. We do not retain the plaintext key, and it cannot be retrieved after creation. The complete key is shown only when it is created; customers must rotate or revoke it through the available controls.
How we use data
We use data to provide the service, authenticate users, meter usage, calculate credits, create billing records, prevent fraud and abuse, debug incidents, answer support requests, maintain auditability, provide archive downloads, and meet legal or payment obligations.
Where GDPR or UK GDPR applies, the legal basis may be performance of a contract, legitimate interests in operating and securing the Service, compliance with a legal obligation, consent where required, or the establishment, exercise, or defence of legal claims. Where CCPA/CPRA applies, we process personal information for the business and commercial purposes described in this policy and provide the rights required by applicable law.
Providers, subprocessors, and international transfers
Sign-in, payments, hosting, database, email, security, analytics, and AI model providers may process data for their parts of the service. We do not sell customer prompts, responses, usage, or billing data. We do not use routed customer content to train our own general-purpose AI models.
AI model providers receive the request content needed to serve each routed API call. Their API terms, retention settings, abuse controls, and data processing behavior apply to that provider-side processing.
Personal data may be processed outside the country where you or a data subject is located. Where a transfer mechanism is required, we use the contractual, statutory, or other lawful safeguard applicable to that transfer. Read the Subprocessor List for the public processing categories and objection path.
Retention
- Routed API prompts and responses
- Not written to 1api application databases or long-term logs. The isolated continuation cache is the limited exception described above.
- Hot API metadata
- Generally available for about 90-120 days for billing, audit, support, and abuse prevention.
- Cold archive metadata
- Eligible API metadata is archived in monthly batches after day 90, retained for 2 years, and downloadable by users with required workspace permissions.
- Account, billing, support, and security records
- Retained as needed to operate the service, resolve disputes, meet legal obligations, and protect the platform.
| Routed API prompts and responses | Not written to 1api application databases or long-term logs. The isolated continuation cache is the limited exception described above. |
|---|---|
| Hot API metadata | Generally available for about 90-120 days for billing, audit, support, and abuse prevention. |
| Cold archive metadata | Eligible API metadata is archived in monthly batches after day 90, retained for 2 years, and downloadable by users with required workspace permissions. |
| Account, billing, support, and security records | Retained as needed to operate the service, resolve disputes, meet legal obligations, and protect the platform. |
Platform cold archives exclude raw request and response bodies, messages, tool payloads, and file contents.
Retention may be extended where necessary for a legal claim, investigation, security incident, payment dispute, or other lawful obligation. We apply deletion or anonymization when the applicable purpose and retention period end.
Cookies and analytics
We use authentication, security, session, preference, and product analytics tools to operate and improve the service. These tools should be used for account, security, and product diagnostics, not for selling customer API content or billing data.
Your rights
Depending on where you live, you may have rights to access, correct, export, delete, object to, or restrict certain personal data. Some records may need to be retained for billing, fraud prevention, legal, security, audit, or dispute reasons.
Legal framework and rights
GDPR, UK GDPR, and CCPA/CPRA rights may apply depending on the person, customer, and processing activity. We support applicable access, correction, deletion, restriction, objection, portability, and consent-withdrawal requests, subject to lawful exceptions and the customer's role as controller where relevant.
California residents may have the right to know, access, correct, delete, opt out of sale or sharing where applicable, and receive equal treatment. We do not sell or share customer prompts or responses for cross-context behavioural advertising.
We may need to verify a request and retain information needed to meet legal, security, billing, fraud-prevention, or dispute obligations. When we process data for a customer as a processor or service provider, we may direct the request to that customer or assist the customer as required by the applicable agreement and law.
This Privacy Policy, the Data Processing Addendum, and the Subprocessor List describe the applicable processing boundaries. They do not change the independent terms, retention settings, or data controls of an upstream AI provider that receives content needed to fulfil a routed request.
Security and incidents
We use access controls, least-privilege practices, credential lifecycle controls, operational monitoring, and other technical and organizational measures appropriate to the Service. No service can eliminate every risk.
We handle a confirmed personal-data incident and communicate with affected customers or authorities as required by applicable law and the applicable agreement.
Changes and contact
We may update this policy when the Service, processing purposes, providers, or legal requirements change. We publish material changes to this page and update the date above.
For privacy questions, email [email protected] or legal questions, email [email protected] or open a support ticket from the dashboard. These privacy terms work together with the Terms and Refunds.