Version 1.1 · last updated 2026-09-04
The short version: we store what is needed to run an account, bill it correctly and investigate abuse — who you are, how many tokens you spent, what you paid, the IP address your calls come from, and, for 30 days, the content of your API requests and the model's answers.
[LEGAL ENTITY NAME], [REGISTERED ADDRESS], is the controller of the data described here. Privacy questions and rights requests go to privacy@unbleep.ai.
We store the content of your API calls. For every request we accept and forward to a model we write the request body, the response content and the source IP address the request came from into our database, alongside the metering data listed in section 3. Bodies are truncated to the first 64 KB (65,536 bytes) and marked where the cut was made, so a very large request is stored in part rather than in full. Streamed answers are stored the same way, assembled once the stream has finished.
A request we reject before it reaches a model — an invalid API key, a malformed body, an unknown model, a request refused by the strict policy, or one you have no credit for — has no content stored. Where it got far enough to be attributed to your account it is recorded only in the metering data described in section 3.
Why. To investigate abuse reports and enforce the Acceptable Use Policy, to answer support requests, and to resolve billing disputes.
How long. The request and response content: 30 days from the request, after which the record is deleted automatically by a scheduled job. The source IP address is kept for longer than that. As well as sitting in the 30-day record, it is written to the usage row that bills the request, and usage rows are financial records kept for the period given in section 7.
Who can see it. The operator, through the admin console. It is not shown in your own console, we do not share it with anyone else, and we do not use it to train models. There is currently no customer-facing setting that turns this logging off.
An earlier version of this policy said prompt and completion content was never written to our database. That stopped being true when request logging was added, and this section replaces that claim.
We still never see your card number: card details go straight to Stripe from their hosted checkout page and never touch our servers.
scrypt hash of that password. We never store the password itself. If you sign in with Google we store the account identifier Google gives us instead.We use a small number of providers to run the service. They act on our instructions, except where noted.
We do not sell your personal data, and we do not use your prompts or outputs to train models.
Depending on where you live — including under the GDPR in Europe, the LGPD in Brazil, and comparable US state laws — you may ask us to:
The request and response content in section 2 is covered by those same rights: you can ask for a copy of what we still hold for your account and ask us to delete it. There is no self-service export or delete button for it in the console — ask us and we will do it by hand.
Write to privacy@unbleep.ai and we will respond within the period the applicable law allows. You also have the right to complain to your local data protection authority.
Traffic is encrypted with TLS. Passwords are hashed with scrypt; API keys and session tokens are stored only as hashes, so a copy of our database would not yield a usable key. Administrative access is restricted, the application runs under a sandboxed service account, and backups are held on the same restricted infrastructure. No system is perfectly secure; if a breach affects your data we will notify you and the relevant authority as the law requires.
Your data is processed on servers in [REGION] and by the providers listed above, which may be located outside your country. Where the law requires it, transfers rely on standard contractual clauses or another approved mechanism.
The service is not for anyone under 18 and we do not knowingly collect their data. If you believe a minor has an account, tell us and we will remove it.
We will post any update here and change the date at the top. Material changes will be announced by email or in the console before they take effect.