Privacy Policy
Data collected
We store account identity, workspace membership, API-key hashes, payment references, request metadata, token counts, latency, errors, and audit events.
Prompt content
ApiSoul does not intentionally persist prompt or response bodies in the application database. Requests are forwarded to the configured upstream provider, whose privacy terms also apply.
Security
Passwords use scrypt. Sessions are HTTP-only. Customer API keys are stored as one-way hashes. Provider credentials remain server-side.
Retention
Usage, billing, and audit records are retained for operational, fraud prevention, tax, and legal requirements. Account deletion requests may be sent to the configured support address.
Processors
Infrastructure, payment, email, monitoring, and AI providers process limited information needed to deliver the service.