15% off all models 🎉 Every model at 85% of OpenRouter list price.Browse models →

ApiFlux Privacy Policy

Version: v0.1
Last updated: 2026-07-16
Website: https://apiflux.ai/

Translation notice: This English version is a working translation pending professional review.

Important: This policy describes ApiFlux's current data-processing rules and does not constitute legal advice to any user.

Controller and key settings

  • Controller and operator: NovaSpan LLC
  • Company type and place of registration: Wyoming limited liability company, United States
  • Registered and mailing address: 30 N Gould St Ste R, Sheridan, WY 82801, United States
  • Privacy contact: https://apiflux.ai/contact (mark the request “Privacy Request”)
  • Data Protection Officer / EU or UK representative: none currently appointed; NovaSpan LLC handles privacy matters directly
  • Cookies and analytics: only essential technologies for login, sessions, security, language, and theme; no cross-site targeted advertising cookies are currently used
  • Authentication: handled by the ApiFlux account system; where third-party login options are displayed, required authentication data is sent to that provider only when the user actively selects it
  • Upstream models/APIs: depending on user choice and routing policy, these may include OpenAI, Anthropic, Google Gemini, AWS Bedrock, Microsoft Azure OpenAI, Mistral, Cohere, Hugging Face, Groq, and other channels identified on model pages
  • Infrastructure and network security: Cloudflare provides network transport, CDN, and security protection; other cloud hosting, database, logging, email, and customer-support providers process data as needed to provide their services
  • Payments: payment credentials are processed directly by the third-party payment processor shown at checkout; ApiFlux receives transaction identifiers, amount, currency, and status and does not store full card numbers
  • Primary data-storage region: United States; upstream model and infrastructure providers may process requests in their global operating regions
  • Prompts/responses: full content is not stored by default and is processed transiently to fulfill a request; when prompt logging is enabled by the user, content is stored for 30 days and may be deleted earlier
  • Specific retention periods: see Section 7

1. Scope and roles

This Privacy Policy explains how NovaSpan LLC (“ApiFlux,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal information when a user visits the ApiFlux website, creates an account, adds funds, creates an API Key, calls the API, uses the console, or contacts us.

For account, payment, website-access, security, and service-operation data, we generally act as the controller or in the equivalent role that determines the purposes and means of processing. For personal information submitted through the API by an enterprise customer that determines those purposes and means, we may act as a processor or service provider. The parties may enter into a separate Data Processing Agreement (DPA). Enterprise customers are responsible for giving required notices to their end users and establishing a lawful basis for processing.

This policy does not apply to independently operated third-party websites, models, or services. Their own policies govern their processing.

2. Information we collect

We may collect the following information.

2.1 Account and identity information

  • Username, email address, password hash, and verification status;
  • Organization, team, role, permissions, language, and preference settings;
  • Login method, two-factor authentication, Passkey, or third-party login identifier;
  • Identity or company-verification information lawfully required for risk control or enterprise procurement.

2.2 Payment and credit information

  • Order number, top-up amount, currency, balance, redemption-code use, and billing records;
  • Payment status, transaction ID, payment channel, refunds, chargebacks, and risk-control results;
  • Invoicing, tax, or billing-contact information.

Full card or wallet credentials are processed directly by the payment provider shown at checkout. ApiFlux does not store full card numbers or payment-account passwords.

2.3 API, usage, and technical information

  • API Key identifier or prefix/suffix, request ID, request time, model, and upstream channel;
  • Input/output tokens, cached usage, charges, latency, error codes, retries, routing, and failover results;
  • IP address, User-Agent, device, browser, operating system, network, and approximate location;
  • Login, action, policy-change, audit, security, diagnostic, and system-event logs.

2.4 User content

User content includes prompts, messages, context, parameters, files, images, audio, code, tool calls, model responses, and other content submitted to or received through ApiFlux.

ApiFlux does not store full prompts, responses, or attachments by default. They are processed transiently to perform real-time forwarding, content-safety and security checks, troubleshooting, and billing. When a user or organization administrator actively enables prompt logging, full prompts and responses are retained for 30 days and then deleted from online systems. A user may request earlier deletion through available console features or a privacy request. We may retain only relevant records for longer when necessary for an active security investigation or legal hold.

2.5 Website and support information

  • Cookies, local storage, page visits, referring pages, interactions, and performance data;
  • Names, contact details, messages, attachments, and correspondence submitted through contact forms, email, tickets, chat, or other channels;
  • Survey, feedback, referral-program, or marketing-communication information.

3. Sources of information

We collect information directly from users, their organizations, their devices, and API requests. We may also receive necessary information from authentication, payment, fraud-prevention, cloud-infrastructure, logging and monitoring, upstream model/API, referral-program, or public sources.

If a user provides another person's personal information, the user must ensure that they have authority to do so and have provided any required notice or obtained required authorization.

4. Purposes and legal bases

We may use information to:

  • Create and manage accounts, authenticate users, and manage roles, permissions, and API Keys;
  • Receive, route, and return API requests and apply model selection, failover, limits, and policies;
  • Calculate token usage and charges and process top-ups, redemptions, billing, refunds, and chargebacks;
  • Provide call logs, cost, latency, error, audit, and observability functions;
  • Maintain, debug, analyze, and improve service quality, performance, and user experience;
  • Respond to inquiries, provide technical support, and send service or security notices;
  • Detect, prevent, and investigate abuse, fraud, attacks, credential exposure, prohibited content, and security incidents;
  • Comply with legal, tax, accounting, sanctions, export-control, regulatory, judicial, and upstream-service requirements;
  • Send product, event, or marketing information with consent or where otherwise permitted by law.

Where applicable law requires us to identify a legal basis, we rely on performance of a contract, compliance with legal obligations, legitimate interests in protecting users and the platform, consent, and other bases recognized by applicable law. A user may withdraw consent-based processing without affecting processing lawfully performed before withdrawal.

We do not use API user content to train a general-purpose AI model owned by ApiFlux, and we do not manually review user content for advertising profiles. Authorized personnel may access relevant content only to the minimum extent needed for a user support request, security incident, legal requirement, or the user's express authorization. Whether an upstream provider uses content for training depends on the applicable channel terms and account configuration. Where commercially reasonable, ApiFlux prioritizes enterprise or API data terms under which API content is not used for training, but users should still review the selected model channel before submitting sensitive content.

5. Sharing and disclosure

We may disclose necessary information to:

  • Upstream model, API, cloud-platform, and routing channels that process the selected or routed model request;
  • Authentication, hosting, database, storage, CDN, network, security, fraud-prevention, logging, and monitoring providers;
  • Payment, invoicing, accounting, tax, email, customer-support, and analytics providers;
  • Administrators or authorized members of the user's organization;
  • Professional advisers, auditors, insurers, and prospective transaction parties;
  • Courts, regulators, law-enforcement bodies, or others where necessary to protect the rights and safety of ApiFlux, users, or the public.

Current principal processor categories include Cloudflare for network, CDN, and security services; the model/API provider actually selected or routed to; the payment processor displayed at checkout; and suppliers providing authentication, hosting, databases, logging, email, and customer support. We require processors to handle necessary data only under contract and our instructions. Upstream model or payment providers that independently determine processing purposes may act as independent controllers under their own policies.

We do not sell personal information or “share” it for cross-context behavioral advertising. We currently do not conduct activities that require a “Do Not Sell or Share My Personal Information” link. If that changes, we will first update this policy and provide legally required opt-out mechanisms, including recognition of applicable Global Privacy Control signals.

6. International transfers

ApiFlux's primary account, billing, and service-operation data is stored in the United States. ApiFlux, Cloudflare, payment processors, and upstream model/API providers may process information outside the user's country or region, including in locations where their global infrastructure operates. The selected model and routing channel affect the actual processing location.

Where required by applicable law, we will use mechanisms such as adequacy decisions, Standard Contractual Clauses, data-transfer agreements, contracts, and security assessments, together with appropriate technical and organizational measures. Selecting a particular upstream model or channel may affect the processing region.

7. Data retention

We retain information only for as long as needed to provide the service, bill users, maintain security, meet legal obligations, and resolve disputes. It is then deleted, anonymized, or lawfully isolated. Planned specific periods are:

  • Account and organization records: for the life of the account; deleted from online systems within 30 days after closure, except for data required by law or a dispute
  • Login, security, and audit logs: 180 days
  • Order, top-up, payment, and tax records: 7 years after the transaction
  • API usage, token, charge, and request metadata: 180 days; aggregated records relevant to tax or billing disputes may be retained for 7 years
  • Full prompts, responses, and attachments: not stored by default; retained for 30 days when prompt logging is enabled
  • Customer-support and complaint records: 3 years after the request is closed
  • Security-incident records: 3 years after closure; material incidents may be retained for the applicable limitation or regulatory period
  • Essential cookies and local storage: for the session or up to 12 months, depending on the login, language, and security function
  • Backups: rolling 30-day retention and deletion through the normal backup-overwrite cycle

We may extend retention of necessary data for a pending dispute, fraud matter, security incident, legal hold, or regulatory requirement.

8. Cookies and similar technologies

We use essential cookies and local storage for login sessions, account security, language, theme, and service operation, for the current session or up to 12 months. Cloudflare may also set short-lived security cookies to identify abnormal traffic and protect the website. We currently do not use cross-site targeted-advertising cookies or sell or share personal information through cookies. If we introduce non-essential analytics or marketing cookies, we will first update this policy and provide consent and withdrawal tools where required.

In jurisdictions where consent is required, we will obtain it before setting non-essential cookies. Users may manage cookies through cookie settings, browsers, or device settings. Disabling essential technologies may make some functions unavailable.

9. Information security

We use technical and organizational measures appropriate to the risk, including encryption in transit, access control, least privilege, key management, audit logs, security monitoring, backups, vulnerability management, and incident response. Enterprise features or specific certifications apply only where stated on the website or in a contract.

No system can guarantee absolute security. Users should use a unique strong password, enable available two-factor authentication, restrict API Key permissions, rotate credentials, and avoid sending passwords, private keys, full API Keys, card information, or unnecessary sensitive data in prompts, logs, or support requests.

To report a security issue, contact https://apiflux.ai/contact and place “Security” at the start of the subject or message.

10. User rights and choices

Depending on local law, a user may have the right to:

  • Access or obtain a copy of personal information;
  • Correct inaccurate or incomplete information;
  • Delete personal information;
  • Restrict or object to certain processing;
  • Obtain portable data;
  • Withdraw consent or opt out of marketing;
  • Request an explanation or human review of automated decisions, where applicable;
  • Complain to a competent data-protection authority;
  • Exercise privacy rights without discrimination prohibited by law.

Users may submit a request through https://apiflux.ai/contact and mark it “Privacy Request.” We may verify identity and authority to protect the account. We generally respond within 30 days and will explain any extension permitted by applicable law. A request may be limited by billing, tax, security, fraud-prevention, legal-hold, or third-party-rights requirements.

An enterprise customer's end user should generally contact that enterprise customer first regarding data it controls. We will assist the enterprise customer as required by contract.

11. Minors

The service is not directed to anyone under 18, and we do not knowingly collect their personal information. If you believe a minor has provided information, contact https://apiflux.ai/contact and mark the request “Minor Privacy.”

12. Policy updates

We may update this policy because of changes in the product, law, suppliers, or operations and will state the update date on the page. Where reasonably practicable, we will notify users of changes that materially affect processing through the website, console, or registered email address, and will obtain renewed consent where legally required.

13. Contact us

  • Controller and operator: NovaSpan LLC
  • Address: 30 N Gould St Ste R, Sheridan, WY 82801, United States
  • Privacy requests: https://apiflux.ai/contact (mark “Privacy Request”)
  • Security incidents: https://apiflux.ai/contact (mark “Security”)
  • Data Protection Officer / EU or UK representative: none currently appointed; NovaSpan LLC handles all privacy matters directly

Enterprise AI Gateway for routing, securing, and observing every model call.