Privacy Policy
Last updated 2026-09-11
The one thing most people want to know first: we do not store the content of your prompts, code, or model outputs. Requests are forwarded to the upstream model provider and the response is returned to you; what we keep is metadata (token counts, model, timing, status) for billing.
1.Who we are
The data controller is West Sand Technology Co., Limited, Hong Kong. Contact: info@westsandtec.com.
2.What we collect
Account: your GitHub user ID, email address, display name and avatar URL, received from GitHub when you sign in.
Billing: handled by Stripe. We receive your email, the amount, currency and status of each payment and a Stripe reference. We never see or store card numbers.
Usage metadata: for each request through the gateway — model alias, upstream provider, token counts (input, output, cache read/write), latency, HTTP status, timestamp, and which of your API keys was used.
Device sign-in: a device label you (or the CLI) supply when authorising a key.
Server logs: our hosting provider records IP address and user agent for a short period for security and debugging.
Cookies: a session cookie (sign-in) and a language-preference cookie. No advertising or cross-site tracking.
3.What we do not collect
We do not log or store the text of your prompts, the code you send, or the model’s output. The gateway streams the upstream response through to you and records only the token counts and timing needed for billing.
4.Third parties who process your data
Upstream model providers receive the content of your requests in order to generate a response. The providers behind our aliases may change; the current routing is described on our models page. Providers may be located outside your country, including in China. They process content under their own terms and privacy policies.
Stripe (payments), GitHub (sign-in), Vercel (hosting), Neon (database), Upstash (rate limiting).
We do not sell personal data.
5.Why we process it
To provide and bill the Services, to prevent abuse and fraud, to debug and improve reliability, and to meet legal and accounting obligations.
6.Where data is processed
Our servers run in Singapore (Vercel). Stripe, GitHub, Neon and Upstash process data in the United States and/or the EU. Upstream model providers process request content in their own regions. By using the Services you consent to these transfers.
7.Retention
Usage metadata and billing records are retained while your account is active and for as long as required for accounting and tax purposes. Server logs are retained briefly. On request we delete your account and associated personal data, except records we must keep by law.
8.Your rights
You can access, correct, or ask us to delete your personal data, and revoke API keys at any time from the dashboard. Email info@westsandtec.com; we respond within 30 days. Depending on where you live you may have additional rights under local law (for example the GDPR or China’s PIPL).
9.Changes
We may update this policy; the “Last updated” date reflects the current version. See also our Terms of Service.