Privacy Policy
Last updated: July 2026
This policy explains how LLMAPI (llmapi.pro, operated by Shanghai Xunhong Culture Communication Co., Ltd.) collects, uses, retains and protects your data when providing LLM API aggregation and access services. It is kept consistent with the downloadable Data Processing & Security Statement, for compliance review by both individual users and enterprise customers.
1. Roles
With respect to your data and your end users' data, you are the data controller / personal-information handler; the platform, as the relay and access layer for the API service, acts as a processor entrusted by you and processing data only on your instructions.
We process data only to the extent necessary to provide the service, never beyond the purpose and scope of your instructions, and never for our own purposes.
2. Information We Collect & Process
We collect the following information when you use our Service:
- Account information: Email address and name provided during registration
- Usage data: API request metadata including timestamps, token counts, model called and call status — used for billing, usage statistics and service assurance
- Request & response content: Prompts you submit through the API and model outputs returned to you — see Section 4 for processing and retention rules
- Payment information: Processed securely through third-party payment providers
3. How We Use Your Information
- To provide and maintain the Service
- To manage your account and subscription
- To enforce rate limits and prevent abuse
- To send service-related communications (e.g., verification codes)
4. Processing & Retention of Request/Response Content
To deliver the service, we must receive and process the content you submit through the API, forward it to the model you selected, and return the model's response to you — a technical step inherent to providing the service.
Limited retention: to keep the service secure, prevent abuse, resolve billing disputes and troubleshoot faults, we may retain related request/response content for the shortest period necessary for those purposes; such content is generally deleted or anonymized within 30 days (unless a longer retention period is required by law).
Processing of such content is strictly limited to the operational and security purposes above, and we make the following explicit commitments:
- We never use your data for any model training, fine-tuning or distillation;
- We never sell or rent your data, nor use it for advertising or profiling;
- We never disclose your data to unrelated third parties (except to upstream model providers as necessary to deliver the service, or where required by law).
Least privilege: access to request/response content is restricted to the minimum personnel necessary for security or troubleshooting work, with access records kept.
5. Data Security Measures
- Encryption in transit: All API and website traffic is encrypted via HTTPS / TLS
- Credential protection: API keys are stored as SHA-256 hashes — we cannot recover your original key
- Access control: Internal access follows the principle of least privilege, with audit records for key operations
- Account isolation: Accounts and keys are independent of each other, with separate billing
- Abuse protection: Rate limiting and risk monitoring of abnormal calls keep the service stable and accounts safe
6. Upstream Model Providers & Liability Boundaries
The platform aggregates mainstream LLMs; you choose which model/tier to call. LLM services are inherently "use means transmission and processing": data you submit through the API is received and processed by the upstream provider of the model you selected — this is intrinsic to and necessary for the service; upstream providers process data under their own terms.
We are responsible for conduct within our own control (no resale, no leakage, no use of data beyond this service), and we exercise confidentiality and non-resale obligations to the fullest extent within that scope.
7. Data Sharing
We do not sell your personal information. We may share data with:
- Upstream AI model providers (only the API request content, which is transient)
- Payment processors for billing purposes
- Law enforcement when required by applicable law
8. Your Rights, Data Retention & Deletion
Query & export: you can check real-time balance, usage and itemized billing in the console at any time, and export them yourself.
Usage metadata (timestamps, token usage, model called, etc.) is retained for billing and statistics; retention of request/response content follows Section 4.
You can permanently delete your account at any time — from the account settings in the app, the web dashboard, or by emailing support@llmapi.pro. Deletion immediately removes your account, profile, and API keys and stops all associated services. Transaction and billing records may be retained where required by law or for fraud prevention. If you subscribed through the Apple App Store, also turn off auto-renewal in your Apple ID settings to stop future charges.
9. Security Incident Response
We maintain a security-incident response process. If an incident may affect the security of your data, we will promptly take containment and mitigation measures, notify affected users within a reasonable period, and assist you in fulfilling your own notification or reporting obligations.
10. Cookies & Tracking
We use a session cookie for authentication. We do not use tracking or advertising cookies.
11. Policy Updates
We may update this policy in response to legal or service changes; material changes will be announced on the website or by email.
12. Contact
For privacy-related inquiries, contact support@llmapi.pro.