Privacy Policy

What Y-API collects, what it does not collect, how that information is used and shared, and how you can exercise your rights.

Effective date: 2026-09-11

1. Information we collect

We collect only the minimum needed to provide and bill the service:

  • Account information: the email address, display name, and avatar returned by Google or GitHub when you sign in. Signing in completes registration — no extra forms.
  • Call metadata: for each API request, the time, model name, input and output token counts, response latency, credit deducted, and the name of the key used.
  • Top-up records: the amount paid, the credit granted at the conversion rate, and the time, used for reconciliation.

2. Information we do not collect

  • We do not store request or response content. The prompts you send and the text the model returns are forwarded in memory only, and are never written to any database or log.
  • We do not store passwords. Sign-in happens entirely through Google and GitHub OAuth; with no passwords on the site, there is no password-leak attack surface.
  • We run no ad tracking, and we sell no information to data brokers.

3. How information is used

  • Providing and maintaining the service: identification, credit deduction, billing reconciliation, and troubleshooting.
  • Security and abuse prevention: spotting anomalous traffic and protecting keys and accounts.
  • Product improvement: adjusting capacity and the model catalog based on aggregate call volume and model distribution — never individual profiling.
  • Understanding site usage: page views and aggregated traffic via Google Analytics 4, used to improve the site — never individual profiling.
  • Measuring conversion at key steps: sign-up, key provisioning, and credited top-ups are reported from our server to Google Analytics 4, along with your account identifier (a random id, never your email) and the top-up amount, so we can calculate the sign-up-to-paid conversion rate.
  • Product and campaign emails: occasional announcements — such as new models added to the catalog — sent to your account email. They are on by default, and can be turned off anytime via the preferences link in every email footer; turning them off never turns off account notices like balance alerts.

Your request content is never used to train any model — we simply do not keep it.

4. How information is shared

Data is exchanged with third parties only where strictly necessary:

  • Upstream model providers: to answer your request, its content is forwarded in real time to the provider of the model you selected (such as DeepSeek, Qwen, Z.ai, Moonshot AI, Tencent, and Xiaomi). Forwarding is essential to providing the service; how those providers handle data is governed by their own privacy policies, which we encourage you to review.
  • Sign-in providers: Google and GitHub, used only to complete OAuth sign-in.
  • Payment processors: top-ups run through third-party payment services on pages they provide. We never touch or store your card number or payment account password.
  • Google Analytics: we use Google Analytics 4 to record page views and aggregated traffic. In addition, three conversion moments — sign-up, key provisioning, and credited top-ups — are sent directly from our server, carrying your account identifier (a random id, never your email), the top-up amount, and your browser's Analytics cookie identifier. Google may set its own cookies; see Google's privacy policy for how that data is handled.

5. Cookies

We use a single first-party cookie strictly necessary for keeping you signed in (HttpOnly, SameSite=Lax). Google Analytics may set additional cookies to measure site usage; those are not used for advertising.

6. Data retention

  • Account information is kept for as long as the account exists.
  • Call metadata and top-up records are kept for the life of the account, as needed for reconciliation and dispute handling.
  • Request and response content never reaches storage, so there is nothing to retain or delete.

7. Data security

The site is served over HTTPS only; session credentials are stored encrypted; API keys can be revoked in the console at any time, effective immediately. No system can guarantee absolute security, though — keep your keys safe, and if one leaks, revoke it and contact us right away.

8. Your rights

You may access, correct, or request deletion of your account information at any time. The console request log and billing pages already show every record tied to your account; to export data or delete the account, email us.

Users in the EU and EEA should also see the GDPR Notice, which lists a fuller set of rights.

9. Changes to this policy

If this policy changes, the effective date at the top of this page changes with it. Material changes that broaden the scope of collection will be announced on-site or by email before they take effect.

10. Contact us

Questions about this policy, or requests to exercise the rights above: email support@bestvirtualgoods.com. We usually reply within 1 business day.