Privacy Policy
Effective date: July 1, 2026
Welcome to OrbitAI API (website: orbitaiapi.site, referred to as the "platform," "we," or "us"). We value your privacy and data security and process information under applicable data-protection laws and regulations.
Read this Policy in full before using the platform. When you use a specific feature, we may also explain its information-processing rules through page notices, dialogs, agreements, or other means. Those notices and this Policy together constitute our complete disclosure about the processing of your information.
01 Scope
This Policy applies when you use OrbitAI API through the platform website, console, API interfaces, and related services.
It does not apply to services independently provided by third-party model providers, payment institutions, network service providers, or other third parties; third-party websites, software, plugins, or services accessed through the platform; or information you collect and process from end users in your own products as a developer. Review the relevant third party's privacy policy and terms for information it processes independently.
02 Information we may collect
Depending on the features you use, we process the following information according to the principles of lawfulness, fairness, necessity, and good faith:
| Category | Information that may be collected |
|---|---|
| Account and identity | Username, email address, encrypted digest of sign-in credentials, account status, and profile details or contact information you provide. |
| Transactions and credit | Top-up amount, credit changes, order number, payment status, refunds, and billing information. Sensitive payment details such as full card numbers are generally processed directly by payment institutions and are not stored by us. |
| Device and network | IP address, browser type, operating system, device identifiers, access time, page history, referrer, unusual sign-ins, and security-event information. |
| API usage | API key identifier, model used, request time, token usage, charges, response status, latency, error codes, and necessary request-tracing information. |
| Request and response content | Prompts, text, images, files, parameters, and model responses submitted to complete a model call. See Section 04. |
| Support and feedback | Support tickets, questions, screenshots, communication records, and outcomes. |
| Information required by law | Information necessary for fraud prevention, cybersecurity, disputes, audits, or legal obligations. |
If you decline to provide information required for a feature, that feature may be unavailable. This generally does not affect other services that do not rely on that information.
03 How we use information
Based on contract performance, consent, legal obligations, legitimate interests, or another applicable legal basis, we may use information to:
- create, verify, and maintain accounts and provide sign-in, authentication, and account-security services;
- create and manage API keys, forward model requests, and return model responses;
- calculate token usage, credit consumption, bills, top-ups, and refunds;
- display usage records, spending details, system status, and service notices;
- troubleshoot issues, optimize performance, plan capacity, and analyze service quality;
- detect abuse, attacks, fraud, regional-restriction evasion, and other rule violations;
- handle support requests, complaints, disputes, and data-rights requests; and
- comply with applicable law, regulation, and valid judicial, administrative, or regulatory requests.
If we intend to use information for a new purpose not described here and not directly related to the original purpose, we will provide any notice and obtain any consent required by law.
04 API requests and model responses
4.1 Processing required to complete a call
When you call a model, the platform must receive and process the request, transmit it to the relevant model or upstream provider, and return the generated result. This processing is necessary to provide the API service.
4.2 Logging, auditing, and troubleshooting
We record necessary call metadata for accurate billing, troubleshooting, abuse prevention, and platform security. When request logging, content-safety review, manual troubleshooting, or legal requirements apply, we may also process some or all request and response content to the extent necessary.
4.3 Sensitive or confidential information
Do not submit identity documents, bank-card details, passwords, private keys, access tokens, trade secrets, medical information, or other unnecessary sensitive data in prompts, uploads, or other API content. You must have the right to process and transmit all data submitted through the platform.
4.4 Model training and product improvement
Selling API content is not our business model. Without your separate authorization, or unless data has been anonymized or de-identified in compliance with law, we do not use API content identifiable to you to train general-purpose public models.
Whether an upstream model provider uses data for service improvement, abuse monitoring, or model training depends on its service type, account settings, and privacy policy. Review the relevant provider's terms before submitting sensitive business data.
05 Sharing, processors, and disclosure
We do not disclose personal information to third parties without a valid reason. To provide services, necessary information may be processed with:
- Model and API providers: They receive request content, parameters, and technical information required for model inference.
- Cloud, network, and security providers: They provide servers, databases, content delivery, logging, security, and incident monitoring.
- Payment and settlement providers: They process top-ups, refunds, reconciliation, fraud prevention, and payment-status notifications.
- Support or messaging providers: They send verification codes, account notifications, service notices, and support messages.
- Professional advisers: They provide auditing, legal, financial, or security services subject to confidentiality obligations.
We require processors to use information only for the agreed purposes and to take reasonable confidentiality and security measures. When a third party acts as an independent controller or processor, its own privacy policy also applies.
We may disclose or transfer necessary information with your explicit authorization; to meet legal obligations or valid judicial, administrative, or regulatory requests; to protect personal, property, or network security; or in connection with a merger, separation, acquisition, asset transfer, or insolvency, with legally required notice and safeguards.
06 Cross-border processing and regional restrictions
Some models, network nodes, or service providers may be outside your country or region. Your request content, account information, or technical logs may therefore be processed abroad, where data-protection standards may differ.
Where applicable law requires notice, separate consent, a security assessment, certification, standard contracts, or other safeguards for cross-border transfers, we will take measures appropriate to the actual business scenario.
Some models are unavailable to users in mainland China or other specified regions. You may not use proxies, VPNs, overseas servers, false identities, or other methods to bypass provider regional restrictions.
07 Retention and security
7.1 Retention periods
We retain information only for the shortest period necessary for the purposes described in this Policy. Account information is generally retained until a reasonable period after account deletion or service termination. Transaction, settlement, and security logs may be kept longer to meet legal, audit, dispute-resolution, and cybersecurity requirements.
After the retention period, we delete, anonymize, or otherwise process information as required by law, unless law requires retention or immediate deletion is technically infeasible.
7.2 Security measures
We take reasonable technical and organizational measures appropriate to risk, including:
- encryption in transit, access controls, privilege levels, and authentication;
- masked API-key display, hashed password storage, and unusual sign-in detection;
- log auditing, rate limits, backup and recovery, and incident response; and
- restricted staff access and confidentiality obligations.
No internet service can guarantee absolute security. Protect your account, password, and API keys. Do not put keys in public repositories, frontend pages, or publicly shared files. If a key is exposed, disable or regenerate it in the console immediately.
08 Cookies and local storage
The platform may use cookies, LocalStorage, or similar technologies to maintain sessions, save interface preferences, provide security, and improve the user experience.
- Essential technologies: Used for sign-in, sessions, security checks, load balancing, and basic features. They generally cannot be disabled through platform controls.
- Preference technologies: Save language, theme, page settings, and other preferences.
- Analytics technologies: Used only when enabled to understand page visits and feature usage, with aggregated or de-identified data where possible.
You can delete or restrict cookies in your browser settings, but disabling essential cookies may prevent sign-in or use of some services.
09 Your personal-information rights
Subject to applicable law, you may request access and copies, correction and completion, deletion, withdrawal of consent, restriction of or objection to certain processing, account deletion, data portability, and review or explanation of a response to your complaint or rights request.
We may verify your identity to protect account security. Where permitted by law, we may decline a request that is manifestly unfounded, repetitive, beyond reasonable technical capability, harmful to another person's lawful rights, or otherwise legally excludable, and will explain the reason.
10 Children
The platform is primarily for developers and organizations with the required legal capacity and is not directed specifically to children under 14. If you are a minor, use the platform only after your guardian has read and accepted this Policy and the relevant service terms.
If we discover that a child's personal information was collected without valid guardian consent, we will verify the situation and take legally required deletion or other measures.
11 Updates to this Policy
We may revise this Policy because of business, technical, or legal changes. The revised Policy will be published on this page with an updated date.
If a change materially affects your rights, we will provide prominent notice through the website, console, email, or another reasonable method and obtain renewed consent when required by law.
12 Contact us
For questions, feedback, or complaints about this Policy, our processing of personal information, or a rights request, contact us through the support, ticket, or other contact channel published on the website.
Operator: The operator of the OrbitAI API website, as identified in applicable registration records and current platform disclosures
Website: orbitaiapi.site