> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ruapi.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

> How RuAPI handles your information

**Last updated: 10 May 2026**

This Privacy Policy describes how RuAPI ("we", "us") processes information when you use our service.

## What we do not store

We are designed around **minimum data exposure**. Specifically:

* **We do not store the content of your prompts or model responses.** API calls pass through our gateway to upstream providers. We do not log, save, or analyze the text of your inputs or outputs.
* We do not sell, rent, or share your data with advertisers or data brokers.
* **We never see or store your card number.** Card payments are entered directly on the payment processor’s own page; card data does not pass through our servers.
* We do not track your browsing across other websites.
* We do not use advertising cookies or browser fingerprinting, and we never use your data for ad targeting.
* We do not build psychographic profiles of users. (For website analytics we use Yandex Metrika — see **Website analytics** below.)

## What we operationally process

To run the Service we process the operational minimum:

* **Account information**: email address, password hash, optional language preference. Used for authentication and transactional communication.
* **API keys**: hashed identifiers for tokens you generate. Used to authenticate your API requests.
* **Balance and transaction records**: top-ups (crypto or card) and per-call deductions. Used for billing. For card payments we store the payment processor’s customer identifier so we can match a payment to your account.
* **Request metadata** (no content): model name, token counts, timestamp, status code. Used for billing and debugging.
* **Email delivery status** for verification and password-reset messages from our email provider.

We do not process information for purposes beyond running the Service.

## Who we share information with

We share information only with these limited parties, each strictly necessary to operate the Service:

* **Upstream AI providers** (OpenAI, Anthropic, Google, xAI, DeepSeek and others you call): receive your API requests. Subject to their respective privacy policies.
* **Payment processors**: **Stripe** (card payments) and **Cryptomus** (crypto payments) receive the data needed to process your top-up — for Stripe this includes your email, IP address and the card details you enter on their page. Each acts as an independent controller under its own privacy policy.
* **Public blockchain networks** (TRON, BSC, Polygon): receive on-chain transaction data inherent to USDT transfers.
* **Email delivery provider** (Amazon SES): handles outbound transactional emails.
* **Hosting / DNS / CDN providers**: process traffic incidentally as part of infrastructure operation.
* **Web analytics (Yandex Metrika)**: our website loads the Yandex Metrika tag, which receives site-usage data — see **Website analytics** below.

We do not share data with advertising platforms or data brokers, and we never use your data for advertising.

## Website analytics

Our website and documentation use **Yandex Metrika** (counter 109153189) to understand how visitors use the site and to improve it. Metrika sets cookies and may collect:

* page views, referrer, approximate location (from IP), device and browser;
* click maps and scroll depth;
* **session replay (Webvisor)** — recordings of anonymized on-page interactions (mouse movement, clicks, scrolling; sensitive fields such as passwords are masked), used to diagnose usability problems.

This is **website-usage analytics only**. It is separate from your API traffic and prompt content (which we never log), and we do **not** use it for advertising or psychographic profiling. The data is processed by Yandex under its [privacy policy](https://yandex.com/legal/confidential/).

**How to opt out:** turn on *Do Not Track* in your browser, use the [Yandex Metrika opt-out](https://yandex.com/support/metrica/general/opt-out.html), or block the `mc.yandex.ru` domain.

## Security

* All traffic to and from the Service is encrypted via TLS (HTTPS).
* Passwords are stored as one-way hashes using industry-standard algorithms; we never store plaintext passwords.
* API keys are hashed before storage; the full key is shown only once at creation.
* Internal access to operational data is restricted on a need-to-know basis.

## Your rights

You have the right to:

* **Access** the information we hold about you (account email, balance, recent transactions — visible in your dashboard).
* **Correct** inaccurate account information through your dashboard.
* **Delete your account** to remove your account record from the active service.
* **Withdraw consent** to email notifications via account settings or by contacting support.
* **Lodge a complaint** with the Office of the Privacy Commissioner for Personal Data, Hong Kong (PCPD).

## International transfers

The Service is operated from the Hong Kong Special Administrative Region but processes traffic globally. By using the Service, you acknowledge that your account metadata may be transferred to and processed in jurisdictions outside your country of residence, subject to appropriate safeguards.

## Children

The Service is not directed to children under 18. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us immediately.

## Changes

Material changes to this Policy will be notified via email or in-app notice at least 14 days before taking effect.

## Contact

Privacy questions: [support@ruapi.ai](mailto:support@ruapi.ai)
