Last updated: June 8, 2026
Privacy Policy
This policy explains how CodexZH processes personal information, request data, and necessary logs when providing AI model gateway, API key management, cost analytics, call auditing, and support services.
Information we process
- Account information: email, login status, subscription status, team relationships, and necessary notifications.
- API call metadata: request_id, time, model, token usage, status code, cost, error code, latency, and security flags.
- Payment and order information: order ID, amount, payment status, payment method, and invoice records.
- Technical and security logs: IP address, user agent, access time, login events, abnormal calls, and security actions.
- API inputs and outputs: processed only as necessary to complete model calls, customer-authorized troubleshooting, or security review; not retained long-term by default.
How API inputs and outputs are handled
To complete a model call, user input, request parameters, necessary context, and response content may be sent to the third-party model provider, cloud provider, network provider, or security provider selected by the user or connected by the platform.
- We do not actively use customer inputs, outputs, code, or business data for general model training, fine-tuning, distillation, advertising, profiling, or public case studies.
- We do not sell, rent, or trade customer data.
- If content access is required for support, security incidents, or dispute review, access should be scoped, reasoned, and audited.
Third-party and overseas models
Calls involving third-party model providers, overseas models, overseas nodes, or overseas service providers may involve cross-border transfer or access by overseas entities. Users are responsible for confirming data legality, authorization, and any applicable personal information, data security, or cross-border compliance procedures.
Retention
| Data type | Purpose | Retention approach |
|---|---|---|
| Account information | Login, authentication, notices, billing | Retained during account lifecycle and as legally required |
| API call metadata | Billing, audit, troubleshooting, security | Retained as needed for business, audit, and compliance |
| Complete input content | Model call, troubleshooting, security review | Not retained long-term by default; short-term processing only when necessary |
| Complete output content | Response delivery, troubleshooting, security review | Not retained long-term by default; short-term processing only when necessary |
| Payment records | Billing, invoices, disputes | Retained as required for tax and dispute handling |
| Security logs | Anti-abuse, security audit, risk response | Retained as needed for security and compliance |
User rights and security
- You may request access, copy, correction, supplement, deletion, account closure, or withdrawal of consent where applicable.
- CodexZH uses HTTPS, access control, permission separation, login protection, audit logs, and anomaly detection.
- If a data security incident may affect legitimate rights, we will take remedial action and provide required notices after verification.
Privacy inquiries, data requests, or complaints: support@codexzh.com.