TheaimartAIx DOCS
Home Get API key

Data & privacy

AIx is built for code, which is often proprietary. The system is designed to keep as little as possible.

Zero prompt retention

We do not store your prompts or completions. The durable usage record (api_usage) holds only:

  • the model and kind (chat / embeddings / image / tts / audio),
  • token counts and units (images, audio seconds),
  • the cost and a timestamp.

No message content, no request bodies, no responses. The usage breakdown the dashboard shows is aggregated from exactly these columns.

ℹ Note

Your prompt is, of course, sent to the upstream provider that serves the call for the duration of that request. That provider’s data policy applies to that hop — choose models accordingly for sensitive workloads. AIx itself adds no retention on top.

Keys are hashed at rest

API keys are stored as a SHA-256 hash, never in plaintext, and shown to you exactly once, when created or rotated. A database leak therefore never exposes a usable, credit-bearing key. Logs only ever contain a short prefix of the hash, never the key itself.

What we do store

DataWhy
Account credit balance (user_credits)Billing source of truth — credits belong to the account, not to a key.
Itemized usage (api_usage)Per-call model/kind/tokens/cost/time — no content.
Billing reconciliation rowsUnsettled refund/charge discrepancies.
Key hash, name, status, expiry, last-usedAuth and lifecycle.
Key policy (key_policies)The scopes and caps you set on a key.
Payment recordsOrder/payment ids and amounts, to credit top-ups exactly once.

What the servers log

Access logs record the request path, status, size and timing — never query strings, request bodies, prompts or responses. When an upstream provider rejects a call, the first 200 characters of its error message are logged for diagnosis; providers occasionally echo part of the request in such errors, so treat that as the one place a fragment could appear.

Moderation posture

The content block-list is empty by default — aggressive moderation breaks legitimate coding (security tooling, parsers, exploit explainers in CTF/education contexts). Input sanitisation only strips NUL bytes and trims whitespace; it deliberately preserves backticks, $, angle brackets and other characters that matter in source code. Operators can add specific block-terms via policy if a deployment requires it. See Acceptable use for prohibited-use handling.

Payment integrity

A top-up is credited only after the payment is confirmed with the gateway itself: PayPal orders are captured server-side, and Razorpay payments must pass the signature check (constant-time) and be confirmed as captured, in INR and fully paying the order through Razorpay’s API. The amount credited always comes from our own order record, never from the browser.

Your controls

  • Scoped keys — limit a key to specific models/kinds and set daily/monthly spend caps and TPM with PUT /api/v1/api-keys/{key_id}/policy, so a leaked key has a bounded blast radius. Caps are enforced server-side and reserved atomically, so concurrent requests cannot overrun them. See Limits, caps & scopes.
  • Key rotation — rotate or revoke keys from the dashboard at any time; the old secret stops working immediately, and a rotated key keeps its scopes and caps.

Last updated September 12, 2026

Was this page helpful?