HomePrivacy Policy
Data Protection & Privacy Standards
Privacy Policy
Our commitment to safeguarding your account data, API credentials, and ensuring zero model training on your private prompt inputs.
Effective date: 18/08/2026•GDPR & ISO 27001 Aligned
1
1. Data We Collect
To operate the Gateway and calculate metered usage, we only collect minimal essential information:
Account Identity
Email, display name, Bcrypt-hashed password, active API keys.
Transaction History
VietQR top-ups, USD transfer receipts (PingPong/Payoneer), promo giftcodes.
Usage Telemetry
Model IDs invoked, prompt tokens, completion tokens, and metered billing deductions.
2
2. Zero Data Training Guarantee
Absolute Prompt Privacy
- ✓No Model Training: Your input prompts and generated responses are NEVER used to train or fine-tune BytePlus, Doubao, or Z.AI models.
- ✓End-to-End Encryption: All API requests and data streams are encrypted in transit using industry-standard TLS 1.3.
3
3. Infrastructure & Database Security
Apidy operates on Vercel Global Edge Network with Singapore Supabase PostgreSQL cluster adhering to enterprise security standards:
- API Keys are generated with cryptographically secure high-entropy random strings.
- User passwords are one-way hashed with salted Bcrypt.
- Role-based access controls and dual-factor admin verification prevent unauthorized data access.
4
4. Payment Security & PCI-DSS Compliance
Zero Card Data Storage Policy
- ✓Zero Card Storage: APIDY NEVER collects, processes, or stores your credit card numbers, expiration dates, or CVV/CVC security codes on our servers. Card inputs are tokenized and processed directly by PayPal.
- ✓PCI-DSS Level 1 Processor: Our payment processor (PayPal Pte. Ltd) is certified to PCI-DSS Level 1, the highest grade of security in the payment industry.
- ✓Minimal Transaction Records: APIDY only retains external transaction references (Order ID, Capture ID), timestamps, and credited USD amounts for ledger reconciliation.
5
5. Your Privacy Rights
You have full autonomy over your personal data via the Console:
- Create, disable, or delete API keys at will.
- Inspect real-time token telemetry and itemized usage history.
- Request account closure or ledger statement exports.
6. Data Protection Officer Contact
For privacy inquiries or data requests, reach our team at:

