Request processing
Your request content is processed to provide the service and may be sent to external safety, generation, or embedding providers. Those providers operate under their own policies and may process or retain submitted content, including outside your country. Avoid sending secrets or personal data you do not need to include.
Requests are subject to safety, abuse-prevention, availability, and service-integrity controls. Andy API does not store prompt or response content in its usage, account analytics, or performance telemetry databases.
Accounts and security
For account holders, Andy API stores the account email, access tier, key names and scopes, self-imposed limits, usage aggregates, and restriction history. API keys, browser sessions, and anti-forgery values are stored as non-reversible keyed hashes; raw secrets are shown only when created where applicable.
Raw client IP addresses are not persisted. Privacy-preserving network identifiers and operational records may be used for rate limiting, abuse prevention, and security enforcement.
Metrics and retention
Public usage aggregates contain time buckets, requested public model IDs, endpoints, request and success totals, request units, and token totals. Account analytics additionally associate successful usage with an account and key.
Andy API retains identity-free model-attempt telemetry for 30 days. It contains time, concrete model, endpoint, text-or-image class, streaming mode, outcome, elapsed and first-data timing, and output-token count. It does not contain prompts, responses, account or key identifiers, network identifiers, remote image URLs, or monetary cost.
Public aggregate analytics may be retained indefinitely. Account-linked data is retained while the account exists or as needed for security and legal obligations.
Service providers and browser data
Andy API uses external infrastructure, email, anti-abuse, safety, and model providers to deliver the service. Andy API does not sell personal information or use it for advertising.
The browser session cookie is HttpOnly. A readable anti-forgery cookie protects account changes. Per-tab browser storage may retain only signed-in and administrator booleans to avoid navigation flicker; it does not retain email, API keys, session secrets, or request content.
Your choices
You can permanently delete your account and associated account data from the Account page. Identity-free public aggregates, performance telemetry, and network-only security records cannot be attributed to an account for selective deletion. External providers may retain data under their own policies.
For access, correction, or deletion help, email [email protected]. Never email API keys or sensitive prompts.
Changes
This policy may change as Andy API evolves. Material revisions will receive a new effective date here.