Last updated: June 8, 2026

Privacy Policy

This policy explains how CodexZH processes personal information, request data, and necessary logs when providing AI model gateway, API key management, cost analytics, call auditing, and support services.

Complete inputs and outputs are not retained long-term by default. They are processed only as necessary to complete model calls, customer-authorized troubleshooting, or security review. Call metadata required for billing, troubleshooting, security audits, anomaly detection, abuse prevention, disputes, or lawful cooperation is retained under a data minimization principle.
01

Information we process

  • Account information: email, login status, subscription status, team relationships, and necessary notifications.
  • API call metadata: request_id, time, model, token usage, status code, cost, error code, latency, and security flags.
  • Payment and order information: order ID, amount, payment status, payment method, and invoice records.
  • Technical and security logs: IP address, user agent, access time, login events, abnormal calls, and security actions.
  • API inputs and outputs: processed only as necessary to complete model calls, customer-authorized troubleshooting, or security review; not retained long-term by default.
02

How API inputs and outputs are handled

To complete a model call, user input, request parameters, necessary context, and response content may be sent to the third-party model provider, cloud provider, network provider, or security provider selected by the user or connected by the platform.

  • We do not actively use customer inputs, outputs, code, or business data for general model training, fine-tuning, distillation, advertising, profiling, or public case studies.
  • We do not sell, rent, or trade customer data.
  • If content access is required for support, security incidents, or dispute review, access should be scoped, reasoned, and audited.
03

Third-party and overseas models

Calls involving third-party model providers, overseas models, overseas nodes, or overseas service providers may involve cross-border transfer or access by overseas entities. Users are responsible for confirming data legality, authorization, and any applicable personal information, data security, or cross-border compliance procedures.

04

Retention

Data typePurposeRetention approach
Account informationLogin, authentication, notices, billingRetained during account lifecycle and as legally required
API call metadataBilling, audit, troubleshooting, securityRetained as needed for business, audit, and compliance
Complete input contentModel call, troubleshooting, security reviewNot retained long-term by default; short-term processing only when necessary
Complete output contentResponse delivery, troubleshooting, security reviewNot retained long-term by default; short-term processing only when necessary
Payment recordsBilling, invoices, disputesRetained as required for tax and dispute handling
Security logsAnti-abuse, security audit, risk responseRetained as needed for security and compliance
05

User rights and security

  • You may request access, copy, correction, supplement, deletion, account closure, or withdrawal of consent where applicable.
  • CodexZH uses HTTPS, access control, permission separation, login protection, audit logs, and anomaly detection.
  • If a data security incident may affect legitimate rights, we will take remedial action and provide required notices after verification.

Privacy inquiries, data requests, or complaints: support@codexzh.com.