01
Scope and controller
This Privacy Policy applies to the OK-API website, account console, API gateway, support channels, and related services. The operator of OK-API determines how personal information is processed for these services and can be contacted at the address above.
02
Information we collect
We collect information you provide, information generated when you use the service, and limited information received from service providers.
- Account and contact data, such as email address, display name, authentication identifiers, and security settings.
- API key metadata, model identifiers, token counts, request status, duration, quota use, and timestamps. Standard text request logs are designed around usage metadata; video tasks may retain prompts, request parameters, status, and result references so the asynchronous task can be managed.
- Payment order identifiers, purchased credit amounts, currency, and payment status. Stripe processes payment-card details; OK-API does not store full card numbers.
- Device, browser, network, cookie, authentication, fraud-prevention, and support information needed to operate and secure the service.
- Acquisition attribution such as UTM source, medium, campaign, first landing page, and timestamps for first API-key creation and first successful API use. This measurement does not add prompt or response content to analytics records.
03
How and why we use information
We use personal information to provide the service, authenticate users, route API requests, calculate usage and credits, process payments, prevent abuse, troubleshoot incidents, communicate about accounts, comply with law, and improve reliability.
- Contract: to create and administer your account and deliver requested API services.
- Legitimate interests: to secure, debug, measure, and improve the service and prevent fraud or abuse.
- Legal obligation: to keep records or respond to lawful requests where required.
- Consent: for optional processing where applicable; consent may be withdrawn at any time.
04
AI request content and providers
API inputs and outputs are transmitted to the model provider or infrastructure selected for the request. Do not submit personal information, confidential material, regulated data, or content you are not authorized to process. Provider terms and privacy practices may also apply. We may temporarily process request content in memory to route, transform, stream, secure, and bill the request.
05
Sharing and international transfers
We share information only as needed with infrastructure, authentication, payment, communications, security, analytics, support, and AI model providers; with professional advisers; during a corporate transaction; or when legally required. These providers may process information in other countries. Where required, we use recognized transfer mechanisms and contractual safeguards.
06
Retention and security
We retain information only for as long as needed for the purposes above, legal obligations, dispute resolution, security, and enforcement. Retention varies by data type: active account and transaction records may be retained for the account lifecycle and applicable statutory period; operational logs are retained for a limited period; asynchronous task records remain until deleted under our operating schedule or a valid request. We use access controls, encryption where appropriate, credential isolation, monitoring, and other reasonable safeguards, but no system is completely secure.
07
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, withdraw consent, and complain to a data-protection authority. California residents may also have rights to know, correct, delete, limit certain uses, and opt out of sale or sharing. OK-API does not currently sell personal information or share it for cross-context behavioral advertising.
- Submit a request from your registered email address to the contact above.
- We may verify identity and authority before completing a request.
- You may appeal a denied request by replying to our decision.
- You may lodge a complaint with your local supervisory authority.
08
Children and changes
The service is not directed to children under 13, and users must meet the minimum age required by the Terms of Service. We may update this policy as the service or law changes. Material changes will be posted here with a new effective date and, where appropriate, an additional notice.