15% off all models πŸŽ‰ Every model at 85% of the maker's official list price.Browse models β†’

ApiFlux Privacy Policy

Version: v0.2
Last updated: 2026-08-19
Website: https://apiflux.ai/

Important: This Privacy Policy describes ApiFlux's intended current data-processing practices. It is not legal advice.

Controller and key settings

  • Controller and operator for account, website, payment, security, and service-operation data: NovaSpan LLC
  • Company type and place of registration: Wyoming limited liability company, United States
  • Registered and mailing address: 30 N Gould St Ste R, Sheridan, WY 82801, United States
  • Privacy requests: [email protected] with Privacy Request at the start of the subject line
  • Security reports: [email protected] with Security Report or Urgent Security at the start of the subject line
  • General support: [email protected]
  • Enterprise and partnership inquiries: [email protected]
  • Data Protection Officer / EU or UK representative: none currently appointed; NovaSpan LLC handles privacy matters directly unless a separate written arrangement states otherwise
  • Primary storage region for account, billing, and service-operation data: United States
  • Upstream model and infrastructure providers may process information in their global operating regions, depending on the selected model, route, provider, and configuration
  • Full prompts, responses, and attachments are not stored by default. Optional prompt logging may retain full content for up to 30 days, subject to the rules below.

1. Scope and roles

This Privacy Policy explains how NovaSpan LLC ("ApiFlux," "we," "us," or "our") collects, uses, discloses, stores, and protects personal information when a person visits the ApiFlux website, creates an account, signs in, adds funds, creates or uses an API Key, calls the API, uses the console, joins a team, contacts support, or interacts with related services.

For account, payment, website-access, security, abuse-prevention, and service-operation data, NovaSpan LLC generally acts as the controller or equivalent decision-maker for the purposes and means of processing.

For personal information submitted through an enterprise customer's application or API integration, the enterprise customer may determine the purposes and means of processing and ApiFlux may act as a processor or service provider. The parties may enter into a separate Data Processing Agreement (DPA). Enterprise customers are responsible for providing required notices, obtaining required permissions, and establishing a lawful basis for their end-user processing.

This Policy does not govern independently operated third-party websites, models, APIs, payment providers, identity providers, cloud providers, or other services. Their own notices and terms govern their processing.

2. Information we collect

2.1 Account and identity information

We may collect:

  • Name, username, email address, password hash, verification status, and account identifiers;
  • Organization, team, role, permissions, language, and preference settings;
  • Login method, two-factor authentication, passkey, device, and third-party login identifiers;
  • Identity, company-verification, tax, or procurement information required for account security, risk control, compliance, or enterprise contracting;
  • Communications and information submitted to support, billing, privacy, legal, or security channels.

2.2 Payment, balance, and credit information

We may collect:

  • Order number, top-up amount, currency, balance, credit, redemption-code use, and billing records;
  • Payment status, transaction ID, payment channel, refunds, chargebacks, and risk-control results;
  • Invoice, tax, organization, and billing-contact information;
  • Referral, promotion, commission, withdrawal, and verification information where those features are available.

Full card numbers, wallet credentials, and payment-account passwords are processed by the payment provider shown at checkout. ApiFlux does not intentionally store full card numbers or payment-account passwords.

2.3 API, usage, and technical information

We may collect:

  • API Key identifier or non-secret prefix/suffix, request ID, request time, model, protocol, and upstream channel;
  • Input and output token counts, cached usage, charges, latency, error codes, retries, routing, and failover results;
  • IP address, User-Agent, device, browser, operating system, network information, and approximate location;
  • Login, action, policy-change, audit, security, diagnostic, and system-event logs;
  • Usage limits, rate-limit events, abuse signals, risk decisions, and account status.

2.4 User Content

User Content includes prompts, messages, context, parameters, files, images, audio, code, tool calls, model responses, and other content submitted to or received through ApiFlux.

ApiFlux does not store full prompts, responses, or attachments by default. They may be processed transiently to:

  • Forward a request to the selected or routed model channel;
  • Return a response;
  • Apply content-safety, abuse-prevention, fraud-prevention, and security checks;
  • Troubleshoot a request or security incident;
  • Calculate usage and charges;
  • Provide a support function requested by the user.

If a user or organization administrator actively enables prompt logging, full prompts and responses may be stored for up to 30 days and may be deleted earlier through available console controls or an approved privacy request. We may retain limited content or evidence longer where reasonably necessary for an active security investigation, fraud investigation, legal hold, dispute, or legal obligation.

We do not use API User Content to train a general-purpose AI model owned by ApiFlux. Whether an upstream provider uses content for training depends on the selected provider, model channel, account configuration, and applicable upstream terms. Users must review the selected channel before sending sensitive content.

2.5 Website and support information

We may collect:

  • Essential cookies and local storage used for login sessions, security, language, theme, and service operation;
  • Page visits, referring pages, interactions, browser information, and performance information;
  • Names, contact details, messages, attachments, and correspondence submitted through email, support, billing, privacy, legal, security, or other channels;
  • Survey, feedback, referral, affiliate, or marketing-communication information.

3. Sources of information

We collect information from:

  • You and your organization;
  • Your device, browser, network, and use of the website, console, and API;
  • Authentication, payment, fraud-prevention, cloud-infrastructure, logging, monitoring, email, support, and security providers;
  • Upstream model, API, and routing providers involved in a request;
  • Referral, affiliate, enterprise, or business partners;
  • Public sources where necessary for security, fraud prevention, business verification, or compliance.

If you provide another person's personal information, you must have authority to provide it and must have given any required notice or obtained any required authorization.

4. Purposes and legal bases

We may use information to:

  • Create and manage accounts, authenticate users, and manage roles, permissions, and API Keys;
  • Receive, route, and return API requests and apply model selection, failover, limits, and policies;
  • Calculate token usage and charges and process top-ups, redemptions, billing, refunds, and chargebacks;
  • Provide request logs, cost, latency, error, audit, and observability features;
  • Maintain, debug, analyze, and improve service quality, performance, reliability, and user experience;
  • Respond to support, billing, privacy, legal, and security requests;
  • Detect, prevent, and investigate abuse, fraud, attacks, credential exposure, prohibited content, and security incidents;
  • Comply with legal, tax, accounting, sanctions, export-control, regulatory, judicial, and upstream-service requirements;
  • Send product, event, or marketing information where permitted by law and, where required, with consent.

Depending on the applicable law and context, our legal bases may include performance of a contract, compliance with legal obligations, legitimate interests in operating and protecting the service, consent, and other lawful bases recognized by applicable law.

Where we rely on consent, you may withdraw consent for future processing. Withdrawal does not affect processing lawfully performed before withdrawal and may make certain features unavailable.

5. Sharing and disclosure

We may disclose necessary information to:

  • The model, API, cloud-platform, routing, and other Upstream Services that process a selected or routed request;
  • Authentication, hosting, database, storage, CDN, network, security, fraud-prevention, logging, and monitoring providers;
  • Payment, invoicing, accounting, tax, email, customer-support, and communication providers;
  • Administrators and authorized members of your organization or team;
  • Professional advisers, auditors, insurers, financing or transaction parties, and service providers bound by appropriate confidentiality obligations;
  • Courts, regulators, law-enforcement bodies, or other persons where disclosure is reasonably necessary to comply with law, protect rights and safety, or respond to a lawful request.

Current principal provider categories may include Cloudflare for network, CDN, and security services; the model or API provider actually selected or routed to; the payment processor displayed at checkout; and suppliers providing authentication, hosting, databases, logging, email, and customer support.

Some Upstream Services or payment providers may independently determine their own processing purposes and may act as independent controllers under their own notices and terms.

We do not sell personal information. We do not currently share personal information for cross-context behavioral advertising. If that changes, we will update this Policy and provide legally required notice and choices.

6. International transfers and locations

ApiFlux's primary account, billing, and service-operation data is stored in the United States. ApiFlux, Cloudflare, payment processors, and Upstream Services may process information outside your country or region, including in locations where their global infrastructure operates.

The selected model and routing channel affect the actual processing location and applicable provider terms. Where required by applicable law, we will use appropriate transfer mechanisms and safeguards, which may include adequacy decisions, Standard Contractual Clauses, data-transfer agreements, contractual protections, and security assessments.

7. Data retention

We retain information only for as long as reasonably needed to provide the service, bill users, maintain security, meet legal obligations, resolve disputes, prevent fraud, or enforce agreements. We may delete, anonymize, or isolate information when it is no longer needed, subject to legal, security, backup, and dispute requirements.

Planned retention periods are:

  • Account and organization records: for the life of the account; normally deleted from online systems within 30 days after closure, except for information required by law or a dispute;
  • Login, security, and audit logs: 180 days;
  • Order, top-up, payment, tax, and accounting records: 7 years after the transaction, or longer where required by law;
  • API usage, token, charge, and request metadata: 180 days; aggregated records relevant to tax, billing, or disputes may be retained longer;
  • Full prompts, responses, and attachments: not stored by default; retained for up to 30 days when prompt logging is enabled;
  • Customer-support and complaint records: 3 years after the request is closed;
  • Security-incident records: 3 years after closure, or longer where necessary for legal, security, or regulatory purposes;
  • Essential cookies and local storage: for the session or up to 12 months, depending on the login, language, and security function;
  • Backups: rolling 30-day retention and deletion through the normal backup-overwrite cycle.

We may extend retention where necessary for a pending dispute, fraud matter, security incident, legal hold, regulatory requirement, or exercise or defense of legal claims.

8. Cookies and similar technologies

We use essential cookies and local storage for login sessions, account security, language, theme, and service operation. Cloudflare or another security provider may set short-lived security cookies to identify abnormal traffic and protect the website.

We do not currently use cross-site targeted-advertising cookies. If we introduce non-essential analytics or marketing cookies, we will update this Policy and obtain consent or provide controls where required by law.

Disabling essential technologies may prevent login or make some functions unavailable.

9. Information security

We use technical and organizational measures appropriate to the risk, including encryption in transit, access control, least privilege, key management, audit logs, security monitoring, backups, vulnerability management, and incident response.

No system can guarantee absolute security. Users should use unique strong passwords, enable available two-factor authentication or a passkey, restrict API Key permissions, rotate credentials, and avoid sending passwords, private keys, full API Keys, card information, or unnecessary sensitive data in prompts, logs, or support requests.

To report a security issue, email [email protected] with Security Report or Urgent Security at the start of the subject line. Do not include a full API Key, password, private key, or payment credential.

10. User rights and choices

Depending on local law, you may have the right to:

  • Access or obtain a copy of personal information;
  • Correct inaccurate or incomplete information;
  • Delete personal information;
  • Restrict or object to certain processing;
  • Obtain portable data;
  • Withdraw consent or opt out of marketing communications;
  • Request an explanation or human review of automated decisions, where applicable;
  • Complain to a competent data-protection authority;
  • Exercise privacy rights without unlawful discrimination.

Submit a request by emailing [email protected] with Privacy Request at the start of the subject line. We may verify identity and authority to protect the account and other persons. We generally respond within 30 days and will explain any legally permitted extension.

A request may be limited by billing, tax, security, fraud-prevention, legal-hold, third-party-rights, or other legal requirements. An enterprise customer's end user should generally contact the enterprise customer first for data controlled by that enterprise customer. We will assist the enterprise customer as required by contract and applicable law.

11. Minors

The service is not directed to anyone under 18, and we do not knowingly collect personal information from children. If you believe a minor has provided information, email [email protected] with Minor Privacy at the start of the subject line and provide only the minimum information necessary to locate the account.

12. Changes to this Policy

We may update this Policy because of changes in the product, law, suppliers, model channels, security practices, or operations. We will state the update date on the page. Where reasonably practicable, we will notify users of changes that materially affect processing through the website, console, or registered email address, and will obtain renewed consent where legally required.

13. Contact

  • Controller and operator: NovaSpan LLC
  • Address: 30 N Gould St Ste R, Sheridan, WY 82801, United States
  • Privacy requests: [email protected], subject prefix Privacy Request
  • Security incidents: [email protected], subject prefix Security Report or Urgent Security
  • General support: [email protected]
  • Enterprise and partnership inquiries: [email protected]
  • Formal legal notices: [email protected], subject prefix Legal Notice, plus mail to NovaSpan LLC, c/o Registered Agents Inc., 30 N Gould St Ste R, Sheridan, WY 82801, United States

Do not send full API Keys, passwords, private keys, card numbers, CVV codes, or unrelated sensitive information by email.


Copyright 2026 NovaSpan LLC. All rights reserved.

Enterprise AI Gateway for routing, securing, and observing every model call.