Skip to main content
Last updated: 30 September 2026 The RuAPI service is operated, and personal data is controlled, by CYBERBIT PTE. LTD. — a private company limited by shares, incorporated in the Republic of Singapore (UEN 202452247D). Registered office: 15 Beach Road, #05-08, Beach Centre, Singapore 189677. CYBERBIT PTE. LTD. is an independent company. It is not affiliated with, owned by, or connected to Cyberbit Ltd. (Israel) or any of its group companies; any similarity in names is coincidental. This Privacy Policy describes how RuAPI (“we”, “us”) processes information when you use our service.

What we do not store

We are designed around minimum data exposure. Specifically:
  • We do not store the content of your prompts or model responses. API calls pass through our gateway to upstream providers. We do not log, save, or analyze the text of your inputs or outputs.
  • We do not sell, rent, or share your data with advertisers or data brokers.
  • We never see or store your card number. Card payments are entered directly on the payment processor’s own page; card data does not pass through our servers.
  • We do not track your browsing across other websites.
  • We do not use advertising cookies or browser fingerprinting, and we never use your data for ad targeting.
  • We do not build psychographic profiles of users. (For website analytics we use Yandex Metrika — see Website analytics below.)

What we operationally process

To run the Service we process the operational minimum:
  • Account information: email address, password hash, optional language preference. Used for authentication and transactional communication.
  • Third-party account sign-in: if you register or sign in with a third-party account such as Google or Yandex, we receive from that provider your account identifier on their platform, your email address, username and display name. We use these to create your account, recognise you on later sign-ins, and link that account to your RuAPI account. We do not receive your password held by that provider, and we do not store its authorisation token — the token is used only during that sign-in to read the information above, then discarded. We do not access any other data in that account on your behalf. You can switch to email-and-password sign-in and unlink the account in the console.
  • API keys: the tokens you generate. Used to authenticate your API requests.
  • Balance and transaction records: top-ups (crypto or card) and per-call deductions. Used for billing. For card payments we store the payment processor’s customer identifier so we can match a payment to your account.
  • Request metadata (no content): model name, token counts, timestamp, status code. Used for billing and debugging.
  • Client IP address: for newly registered accounts, the IP that made the API call is recorded in “consumption” and “error” logs by default, so we can investigate failures and detect leaked keys or abuse. You can turn this off at any time under Console → Settings, via the “Record request and error log IP” switch; once off, newly written logs contain no IP. This applies only to API call logs and is separate from website analytics.
  • Email delivery status for verification and password-reset messages from our email provider.
We do not process information for purposes beyond running the Service.

Who we share information with

We share information only with these limited parties, each strictly necessary to operate the Service:
  • Upstream AI providers (OpenAI, Anthropic, Google, DeepSeek and others you call): receive your API requests. Subject to their respective privacy policies.
  • Payment processors: Stripe (card payments) and Cryptomus (crypto payments) receive the data needed to process your top-up — for Stripe this includes your email, IP address and the card details you enter on their page. Each acts as an independent controller under its own privacy policy.
  • Public blockchain networks (TRON, BSC, Polygon): receive on-chain transaction data inherent to USDT transfers.
  • Email delivery provider (Amazon SES): handles outbound transactional emails.
  • Hosting / DNS / CDN providers: process traffic incidentally as part of infrastructure operation.
  • Web analytics (Yandex Metrika): our website loads the Yandex Metrika tag, which receives site-usage data — see Website analytics below.
We do not share data with advertising platforms or data brokers, and we never use your data for advertising.

Website analytics

Our website and documentation use Yandex Metrika (counter 109153189) to understand how visitors use the site and to improve it. Metrika sets cookies and may collect:
  • page views, referrer, approximate location (from IP), device and browser;
  • click maps and scroll depth;
  • session replay (Webvisor) — recordings of anonymized on-page interactions (mouse movement, clicks, scrolling; sensitive fields such as passwords are masked), used to diagnose usability problems.
This is website-usage analytics only. It is separate from your API traffic and prompt content (which we never log), and we do not use it for advertising or psychographic profiling. The data is processed by Yandex under its privacy policy. How to opt out: turn on Do Not Track in your browser, use the Yandex Metrika opt-out, or block the mc.yandex.ru domain.

Security

  • All traffic to and from the Service is encrypted via TLS (HTTPS).
  • Passwords are stored as one-way hashes using industry-standard algorithms; we never store plaintext passwords.
  • You can view and copy your full API key in the Console (API Keys). If a key may have leaked, delete it and create a new one.
  • Internal access to operational data is restricted on a need-to-know basis.

Your rights

You have the right to:
  • Access the information we hold about you (account email, balance, recent transactions — visible in your dashboard).
  • Correct inaccurate account information through your dashboard.
  • Delete your account to remove your account record from the active service.
  • Withdraw consent to email notifications via account settings or by contacting support.
  • Lodge a complaint with Singapore’s Personal Data Protection Commission (PDPC).

International transfers

The Service is operated by CYBERBIT PTE. LTD. from Singapore but processes traffic globally. By using the Service, you acknowledge that your account metadata may be transferred to and processed in jurisdictions outside your country of residence, subject to appropriate safeguards.

Children

The Service is not directed to children under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us immediately.

Changes

Material changes to this Policy will be notified via email or in-app notice at least 14 days before taking effect.

Contact

Privacy questions: support@ruapi.ai