Privacy & Data

Privacy Policy

How XiaoqilinAPI handles your data, protects your privacy, and maintains transparency.

Last Updated: August 2, 2026
01

Introduction

We take your privacy seriously. This Privacy Policy explains how XiaoqilinAPI collects, uses, and protects your information when you use our API gateway service.

Operator

The platform is operated by XiaoqilinAPI. For any questions about this Privacy Policy, your data, or your account, please contact us at [email protected].

02

Information We Collect

Account Information

  • Email address: For account creation and communication
  • Username: Your account identifier
  • Password: Stored encrypted using industry-standard hashing
  • Payment information: Processed through secure third-party payment providers

API Usage Data

  • API key IDs: To identify and authenticate your requests
  • Timestamps: When requests are made
  • Model names: Which AI models you use
  • Token counts: For billing and usage tracking
  • IP addresses: For security and rate limiting
  • User agent strings: To understand client applications
Important: API request content and model responses are transmitted to the third-party AI model provider you select in order to provide the service. Data handling for such content is governed by the respective provider's policies.

Payment Data

  • Payment processing: Payments are processed by our third-party payment platform. We do not collect or store your card numbers or other full payment credentials.
  • What we receive: We receive from our payment platform only the information needed to credit your account, such as the order number, amount, currency, and product identifier.
  • Payment platform's own handling: Our payment platform processes payment data in accordance with its own terms and privacy policy, which we encourage you to review before making a purchase.

Cookies & Local Storage

  • Essential cookies: Required for login and session management
  • Preference storage: localStorage for UI preferences (language, theme)
  • Analytics cookies: We currently do not use any analytics cookies or third-party statistics tools.
03

How We Use Your Information

We use the collected information for the following purposes:

  • Service delivery: To route your API requests to the appropriate AI models
  • Billing: To calculate usage charges and process payments
  • Service improvement: To analyze usage patterns and optimize performance
  • Communication: To send account notifications, updates, and support responses
  • Security: To detect and prevent fraud, abuse, and unauthorized access
04

Data Sharing

We share minimal information with third parties only when necessary:

  • AI model providers: We route your requests to upstream AI providers (OpenAI, Anthropic, etc.) according to the model you select. Each provider has its own privacy policy and data handling practices.
  • Payment processors: For handling billing and payments securely
  • Legal compliance: When required by law or to protect our rights

We do not sell your personal information. We do not share your data with advertisers or marketing companies for their own purposes. This policy applies to all users, including California residents under CCPA.

Cross-border data transfers: To provide our service, data (including API requests and responses, and account information necessary to operate the platform) may be transferred to and processed in countries other than your country of residence, such as the data centers of our hosting providers and those of the AI model providers and payment processors we work with. We rely on appropriate safeguards, contractual terms, and the privacy commitments of those providers. By using the service, you understand that your data may be processed across borders.

05

Data Retention

  • API and system logs: Stored for 90 days for debugging and security purposes, then deleted or anonymized
  • Billing records: Retained as required by legal and accounting regulations
  • Account data: Kept until you delete your account
06

Security

We implement industry-standard security measures to protect your information:

  • Encryption: All data in transit is encrypted using TLS
  • Access controls: Strict internal access policies limit who can view your data
  • Password security: Passwords are hashed and never stored in plain text
  • API key protection: Keys are stored securely and can be revoked instantly
07

Your Rights

You have the following rights regarding your data:

  • Access and update: View and modify your account data at any time in the Console
  • Account deletion: You can delete your account at any time through the Console
  • Data export: Email us at [email protected] to request a copy of your account data. Requests are handled manually and answered within 30 days.
  • API key management: Create, view, and revoke API keys at any time
  • Usage transparency: View detailed usage logs and billing information in real-time

European Users (GDPR)

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) and equivalent legislation, including the right to access, rectify, erase, restrict processing of, and port your personal data, and the right to object to processing based on legitimate interests. You may exercise these rights by contacting us at [email protected]. You also have the right to lodge a complaint with your local data protection authority. Our legal bases for processing personal data include performance of the contract with you, our legitimate interests in operating and improving the service, and compliance with legal obligations.

08

Cookies & Local Storage

We use minimal cookies and browser storage:

  • Essential cookies: Required for login and session management
  • Preference storage: localStorage for UI preferences (language, theme)
  • Analytics: We currently do not use analytics cookies or third-party statistics tools.

You can disable cookies in your browser settings, though this may limit some functionality.

09

Changes to This Policy

We may update this Privacy Policy from time to time. When we make significant changes, we will notify you via:

  • Email notification to your registered address
  • A notice in the Console dashboard
  • Updated "Last Updated" date at the top of this policy
10

California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information:

Your CCPA Rights

  • Right to Know: You can request information about the categories and specific pieces of personal information we have collected about you in the past 12 months.
  • Right to Delete: You can request deletion of your personal information, subject to certain exceptions under law.
  • Right to Opt-Out: You have the right to opt out of the "sale" of your personal information. We do not sell your personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

Categories of Personal Information

In the past 12 months, we have collected the following categories of personal information:

  • Identifiers: Email address, username, IP address
  • Commercial Information: API usage records, billing history
  • Internet Activity: API requests, access logs

Do Not Sell My Personal Information

We do not sell, rent, or share your personal information with third parties for their marketing purposes. We only share data with service providers necessary to operate our platform (AI model providers, payment processors) under strict contractual protections.

How to Exercise Your Rights

To exercise your CCPA rights, you can:

  • Access the Console to view, export, or delete your account data
  • Contact us through the support channels in the Console

We will respond to your request within 45 days. We may need to verify your identity before processing your request.

11

Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us at [email protected].

Need help? Email [email protected] for data access, correction, deletion, or export requests. Data export requests are answered within 30 days.