Legal

Privacy Policy

This policy explains what personal data NixAPI collects, why, what happens to your API requests as they pass through our gateway, and the choices you have.

Last updated:

1. Scope and acceptance

This Privacy Policy explains how NixAPI (“NixAPI”, “we”, “us”) collects, uses and discloses personal data when you visit nixapi.com and its pages (the “Website”), use the console at api.nixapi.com, call our API, or contact our support (together, the “Service”). Capitalized terms not defined here have the meanings given in our Terms of Service.

By using the Website or the Service, you consent to the collection and use of your personal data in accordance with this Privacy Policy and the Terms of Service. If you are uncomfortable with any part of them, please stop using the Website and the Service.

The Service is intended for developers and businesses. If you integrate the Service into your own product, you are responsible for your end users’ data, including giving them appropriate notices and obtaining any required consent.

2. Information we collect

Personal data means any information that can identify you directly or indirectly, such as your name, email address or IP address.

Information you provide

  • Account information: username, email address, password (stored hashed), and profile details from third-party sign-in providers such as GitHub or Google if you choose to use them.
  • Billing information: top-up amounts, order numbers, payment time and transaction status. Card and other payments are handled by third-party payment processors; we do not receive or store your full card or bank account details. For cryptocurrency payments, we record the paying wallet address, network and transaction hash, which are publicly visible on the blockchain.
  • Communications: messages and attachments you send to us by email, live chat or other channels, and your responses to any surveys.

Information collected automatically

  • Call logs: API key identifier, model name, routing group, token counts, cost, request time, latency, status code and IP address. Used for billing, usage statistics and abuse prevention.
  • Error logs: when a request fails, the error message and status returned by our gateway or the upstream provider. Used for troubleshooting and improving availability. Error messages are generated by the upstream and in rare cases may quote a small part of the request.
  • Device and usage data: IP address and approximate location inferred from it, browser and device type, operating system, time zone, referring pages, pages viewed and links clicked on the Website.

API request content — not stored

The prompts, files, images, audio and other data you send in API requests, and the responses returned by models (together, “Content”), pass through our gateway only so they can be forwarded to the upstream provider and returned to you. We do not write Content to our databases or logs; it is processed in memory and discarded once the request completes.

3. Cookies and analytics

We use cookies and similar technologies on the Website and console:

  • Strictly necessary cookies keep you signed in and secure the console. The Service cannot work without them.
  • Preference cookies and local storage remember choices such as language and theme.
  • Analytics cookies — where enabled — help us understand how the Website is used through third-party services such as Google Analytics, for example pages visited, time spent and device type.
  • Support widgets — where enabled — such as Tawk.to may set cookies to provide live chat.

You can block or delete cookies in your browser settings. Blocking strictly necessary cookies may prevent you from signing in or using parts of the Service.

4. How we use information

  • to provide, operate and maintain the Service, including routing requests to upstream providers;
  • to create and manage your account, process top-ups and calculate usage charges;
  • to monitor performance and availability, and to diagnose and fix problems;
  • to send account, billing, security and service notices, including changes to models, prices, policies or these terms;
  • to respond to your questions and support requests;
  • to send product updates and promotional messages, which you can opt out of at any time;
  • to compile statistics about use of the Service and improve it;
  • to detect, prevent and investigate fraud, abuse, security incidents and violations of our Terms, AUP or Model Terms;
  • to comply with legal obligations, enforce our terms and resolve disputes.

We do not sell your personal data, and we do not use your Content to train AI models.

5. Aggregated and de-identified data

We may aggregate or de-identify data derived from call logs — for example, request volume, model popularity, success rates and latency — to analyze and improve the Service and to publish statistics such as model rankings or status information. Such data does not identify you and never includes Content, because we do not store Content.

6. Upstream model providers

To fulfil each API request, we must forward its Content to a third-party upstream provider that serves the selected model. Depending on the model and routing channel, this may be the model developer, a cloud platform, a reseller, an aggregation platform or another API service provider, and the channel may change at any time.

  • Upstream providers process Content under their own terms and privacy policies. Their practices — including data retention, abuse monitoring, human review and whether data is used for model training — are determined by them and are outside our control.
  • Some upstream providers retain request data for a period of time and may be required to disclose it to authorities in their jurisdiction.
  • We make no representation about, and are not responsible for, the privacy, security or data practices of upstream providers.

You should therefore avoid sending personal data, confidential business information, or special categories of sensitive data (such as health, financial, biometric or government ID information) through the Service unless you have assessed and accepted these risks and have a lawful basis to do so.

7. Other sharing and disclosure

Besides upstream model providers, we share personal data only as follows:

  • Service providers that help us operate the Service — such as hosting, CDN, database, email delivery, payment, analytics and customer support providers — solely to perform tasks on our behalf;
  • Corporate transactions: in a merger, acquisition, restructuring or sale of assets, personal data may be transferred as part of the transaction;
  • Legal requirements: where we reasonably believe disclosure is necessary to comply with law, regulation, legal process or a government request; to enforce our terms; to respond to claims of infringement; or to protect the rights, property or safety of NixAPI, our users or the public;
  • With your consent or at your direction.

8. International transfers

Our servers, service providers and upstream model providers may be located in different countries and regions. By using the Service, you understand that your personal data and Content may be transferred to, stored in and processed in jurisdictions other than your own, whose data protection laws may differ. Where required, we take reasonable measures to protect data during such transfers.

9. Data retention

  • Account information is kept while your account is active and deleted or anonymized within a reasonable period after account deletion.
  • Billing and transaction records are kept as long as required by accounting, tax and other legal obligations.
  • Call logs, error logs and access logs are kept as long as needed for billing, statistics, dispute handling, troubleshooting and security, and then deleted or aggregated.
  • Content is not stored, so there is nothing for us to retain.

When data is no longer needed, we delete, erase or anonymize it as permitted or required by applicable law.

10. Security

We use physical, technical and administrative measures designed to protect personal data from accidental loss and unauthorized access, use, alteration and disclosure, including encrypted transport (HTTPS/TLS), hashed passwords, access controls and monitoring.

The safety of your data also depends on you: keep your password and API keys confidential, do not share them, and rotate any key you believe may have been exposed. No transmission over the internet is completely secure, and we cannot guarantee absolute security; any transmission is at your own risk.

11. Your rights and choices

Depending on where you live and applicable law, you may have the right to:

  • know and access the personal data we process about you, and obtain a copy of it;
  • correct inaccurate personal data — most account details can be updated directly in the console;
  • delete your personal data, subject to legal exceptions;
  • object to or restrict certain processing;
  • withdraw consent where processing is based on consent, without affecting earlier processing;
  • export your data in certain circumstances.

Account deletion. You can request deletion of your account by emailing support@nixapi.com from your registered address. We may ask you to confirm the request; once confirmed, deletion cannot be undone, and remaining credits are handled under our Refund Policy. Associated personal data is then deleted, except where we must retain it for legal, regulatory or legitimate business reasons.

Marketing. You can opt out of promotional messages by following the unsubscribe link in them or by contacting us. Opt-out may take a reasonable time to take effect, and you will still receive essential account and service notices.

To exercise any of these rights, contact us at support@nixapi.com. We may need to verify your identity before acting on a request.

12. Third-party services

The Website and Service may link to or integrate with websites, tools and platforms operated by others, including sign-in providers, payment processors and upstream model providers. We are not responsible for their privacy practices. Please review their privacy policies before using them. This Privacy Policy applies only to data collected by NixAPI.

13. Age requirements

The Service is intended only for users aged 18 or over. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, please contact us and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time, and updates may apply to data we already hold. The revised version takes effect when posted on this page, as indicated by the “Last updated” date. For material changes we will try to give notice through the website, console or email. Continued use of the Service after changes take effect constitutes acceptance. This policy is provided in English and Chinese; if there is any inconsistency, the Chinese version prevails.

15. Contact

For privacy questions or requests, contact us at support@nixapi.com.