1. Information we collect
We do not use third-party content retrieved through the API to build an EveryInfra advertising profile. That content passes through the Service only as needed to process and return your request.
- Account information: the email address you provide and a salted PBKDF2 password hash. We do not store the password in plaintext.
- Call records: request time, capability, platform or action, status code, latency, and amount charged. We use these records for billing, troubleshooting, and abuse prevention.
- Request metadata: source IP, User-Agent, Accept-Language, Referer, Origin, content-negotiation headers, proxy-chain headers such as X-Forwarded-For and Via, CDN-derived country and edge location, browser Client Hints, device and system attributes provided by those hints, and HTTP protocol version. These values arrive with a request and are stored with the call record.
- Raw request parameters: we retain request parameters for troubleshooting and abuse investigation. For text model calls, this includes submitted message content. Oversized values may be truncated while retaining the original length.
- Invite and redemption records: codes applied to the account and the resulting balance event.
2. How we use information
We use this information to operate and maintain the Service, measure and bill usage, enforce rate limits, prevent abuse, troubleshoot failures, protect accounts and systems, and communicate about the account or Service when necessary.
4. Data retention
Call records are retained for approximately 90 days for billing and troubleshooting. Account-level financial and security events may be retained longer for reconciliation and legal obligations. After account closure, we delete or anonymize personal information within a reasonable period unless retention is required by law.
5. Request processing and disclosures
Requests may be processed across infrastructure used to operate EveryInfra. We do not sell account information. Public responses remove internal operational source identifiers.
6. Security
We use technical and organizational safeguards such as salted password hashing, hash-only storage for API key verification, and encrypted transport. No system can guarantee absolute security. Keep API keys and account credentials confidential.
7. Your rights
You may request access to, correction of, or deletion of account information, or close the account. Contact us using the details below to exercise these rights, subject to applicable law and records we must retain.
8. Contact
Questions about this Privacy Policy may be sent to [email protected] or through the official EveryInfra WeChat account.