Last updated: 10 May 2026 This Privacy Policy describes how RuAPI (“we”, “us”) processes information when you use our service. We are operated by RuAPI Pte. Ltd., incorporated in the Republic of Singapore, and we comply with the Singapore Personal Data Protection Act (PDPA).Documentation Index
Fetch the complete documentation index at: https://docs.ruapi.ai/llms.txt
Use this file to discover all available pages before exploring further.
What we do not store
We are designed around minimum data exposure. Specifically:- We do not store the content of your prompts or model responses. API calls pass through our gateway to upstream providers. We do not log, save, or analyse the text of your inputs or outputs.
- We do not sell, rent, or share your data with advertisers or data brokers.
- We do not track your browsing across other websites.
- We do not use cookies or fingerprinting for advertising or analytics profiling.
- We do not perform behavioural profiling to build psychographic profiles of users.
What we operationally process
To run the Service we process the operational minimum:- Account information: email address, password hash, optional language preference. Used for authentication and transactional communication.
- API keys: hashed identifiers for tokens you generate. Used to authenticate your API requests.
- Balance and transaction records: USDT top-ups and per-call deductions. Used for billing.
- Request metadata (no content): model name, token counts, timestamp, status code. Used for billing and debugging.
- Email delivery status for verification and password-reset messages from our email provider.
Who we share information with
We share information only with these limited parties, each strictly necessary to operate the Service:- Upstream AI providers (OpenAI, Anthropic, Google, xAI, DeepSeek and others you call): receive your API requests. Subject to their respective privacy policies.
- Public blockchain networks (TRON, BSC, Polygon): receive on-chain transaction data inherent to USDT transfers.
- Email delivery provider (Amazon SES): handles outbound transactional emails.
- Hosting / DNS / CDN providers: process traffic incidentally as part of infrastructure operation.
Security
- All traffic to and from the Service is encrypted via TLS (HTTPS).
- Passwords are stored as one-way hashes using industry-standard algorithms; we never store plaintext passwords.
- API keys are hashed before storage; the full key is shown only once at creation.
- Internal access to operational data is restricted on a need-to-know basis.
Your rights
You have the right to:- Access the information we hold about you (account email, balance, recent transactions — visible in your dashboard).
- Correct inaccurate account information through your dashboard.
- Delete your account to remove your account record from the active service.
- Withdraw consent to email notifications via account settings or by contacting support.
- Lodge a complaint with the Personal Data Protection Commission (PDPC) of Singapore.