What Andy API processes
Requests are sent to the configured safety provider and, when permitted, the selected model provider so the service can moderate and answer them. Andy API does not store prompt or response content in its usage or analytics databases. Providers process requests under their own privacy terms and may operate in other countries.
Account and security data
Andy API stores the email attached to an account, tier and quota configuration, keyed hashes of sessions, CSRF values and API keys, key names and model scopes, and account restriction records. Raw key and session secrets are not recoverable from the database.
Raw client IP addresses are not persisted. Network rate limits, blocks, and security events use keyed HMAC network identities. Privacy-safe security events may include an internal request ID, account ID, safety category, action, and timestamp—never request content.
Analytics and retention
Public aggregates contain UTC time buckets, public model IDs, endpoints, request/success counts, request units, and token totals. Private authenticated analytics additionally use account and key IDs. They do not contain prompts, responses, email addresses, raw IPs, or secrets.
Aggregate analytics are currently retained indefinitely. Account-linked moderation and suspension history is retained until the account is deleted. Operational security and rate-limit records are retained as needed to protect the service.
Cookies and browser storage
The andy_session cookie authenticates the browser and is HttpOnly. The readable andy_csrf cookie protects account changes. Per-tab sessionStorage caches only signed-in and administrator booleans to prevent navigation flicker; it never stores email, keys, or CSRF material.
Service providers
Andy API uses Cloudflare Turnstile for abuse prevention, Zoho SMTP for passwordless email, OpenRouter for Llama Guard moderation, and the live model providers shown by the service. Andy API does not sell personal information and does not use it for advertising.
Your choices and security
Email [email protected] to request access, correction, or deletion of account information. Never include API keys or sensitive prompts. No system is perfectly secure, but Andy API minimizes retained data and limits access to operational needs.
Changes
Mindcraft CE may update this policy as Andy API changes. Material revisions will receive a new effective date on this page. Continued use after an update means you acknowledge the revised policy.