Last updated June 12, 2026
Privacy Policy
On this page
How SnifoxAI Gateway collects, uses, and protects your data, and what we deliberately never store.
In short: we do not read your prompts
SnifoxAI Gateway does not store the prompts you send or the responses the AI models return. We meter your usage by counting input and output tokens, the numbers only, never the text. We do not use your content to train models, and we do not sell it to anyone.
1. Scope
This Privacy Policy explains how SnifoxAI Gateway ("SnifoxAI", "we", "us") handles information when you use our website, dashboard, and API. It applies to every plan we offer, including Pay As You Go (PAYG) and Quantum subscriptions.
This policy works together with our Terms of Service. By using the Service, you agree to both.
2. What We Do Not Collect
This is the part that matters most, so we are stating it first and plainly:
- Prompt content. The messages, system instructions, documents, and code you send through the API are forwarded to the model provider and discarded. They are never written to our database.
- Model responses. The completions returned to you are streamed or relayed straight back to your application. They are not persisted in normal operation.
- Training data. We never use your prompts or responses to train, fine-tune, or evaluate any model — ours or anyone else's.
- Sale of data. We do not sell, rent, or trade your data or usage patterns to advertisers, data brokers, or any third party.
One narrow exception, stated honestly
Our platform includes a diagnostic mode that can temporarily capture raw upstream responses when we are investigating a specific incident (for example, an upstream provider returning malformed data that breaks billing). This mode is disabled by default, is used only for troubleshooting, is never applied to build user profiles, and any data it captures is deleted once the incident is resolved. It never captures your prompts.
3. What We Do Collect
3.1. Account information: your name, email address, and password. Passwords are never stored in readable form — they are hashed with bcrypt, a one-way algorithm, so nobody at SnifoxAI can recover your password.
3.2. API keys: the keys issued to your account, so we can authenticate requests, apply your plan, and let you revoke a key you no longer trust.
3.3. Usage metadata: for each request we record the API key used, the model requested, the timestamp, the request status, and the input and output token counts. This is what your bill and your dashboard charts are built from. It contains no message text.
3.4. Billing records: top-up amounts, credit balances, subscription periods, payment references, and invoice history, as required to run the service and meet Indonesian accounting and tax obligations.
3.5. Technical logs: IP address, error codes, and latency figures, retained briefly for security, abuse prevention, and debugging.
4. How We Use Your Information
- To route your API requests to the AI model you selected
- To meter token usage and charge credits or quota accurately
- To show you usage analytics in your dashboard
- To detect abuse, fraud, credential sharing, and attempts to bypass billing or rate limits
- To provide support when you contact us
- To send operational notices about outages, billing, and material changes to the Service
We do not use your information for advertising or automated profiling beyond the abuse detection described above.
5. Encryption and Security
5.1. In transit: all traffic to snifoxai.com and to our API endpoints is encrypted with TLS (HTTPS). Requests sent over plain HTTP are rejected or redirected.
5.2. Credentials: account passwords are stored as bcrypt hashes and are irreversible. Upstream provider credentials are held in restricted infrastructure that no customer-facing endpoint can read.
5.3. API key handling: your API key is a bearer credential. It is displayed in your dashboard so you can copy it, and it is transmitted only over TLS. Treat it like a password: never commit it to a repository, never embed it in client-side code, and revoke it immediately in the dashboard if it may have leaked.
5.4. Access control: administrative access to production data is limited to authorised personnel, protected by authentication, and scoped to what each role needs. Billing and usage records are isolated per account.
5.5. Honest limitation: no system is perfectly secure. We apply industry-standard safeguards, but we cannot guarantee absolute security. If a breach affects your data, we will notify affected users without undue delay and describe what happened and what to do about it.
6. Third-Party Model Providers
SnifoxAI Gateway is a gateway. To answer your request, we forward your prompt to the upstream AI provider that serves the model you chose. This is unavoidable — it is how the Service works.
Our no-logging commitment covers oursystems. Once a prompt reaches an upstream provider, that provider's own privacy policy and retention rules apply, and they are outside our control. If you handle regulated, confidential, or personal data, review the policy of the provider behind the model you intend to use, and choose your model accordingly.
We also rely on a small number of service providers for hosting, payment processing, and messaging. They receive only the data needed to perform their function.
7. Data Retention
- Prompts and responses: not retained.
- Usage and billing records: retained while your account is active and afterwards for as long as Indonesian tax and accounting law requires.
- Technical logs: retained for a short period for security and debugging, then rotated out.
- Account data: retained until you ask us to delete your account, subject to the billing-record obligation above.
8. Your Rights
You may ask us to:
- Access the personal data we hold about you
- Correct inaccurate account details
- Delete your account and associated personal data
- Export your usage history
- Revoke any API key at any time, immediately, from your dashboard
Send requests via our WhatsApp support and include your registered email address. We respond within 30 days. Some records must be kept where the law requires it, and we will tell you if that applies.
9. Cookies and Local Storage
We use cookies and browser local storage strictly to keep you signed in and to remember basic interface preferences. We do not run third-party advertising or cross-site tracking cookies. Clearing this storage signs you out; it does not affect your API keys or credit balance.
10. Children
The Service is not directed at children under 18. We do not knowingly collect data from minors. If we learn that an account belongs to a minor, we will close it and delete the associated personal data.
11. Data Location and Transfers
SnifoxAI Gateway operates from Indonesia. Upstream AI providers and some infrastructure vendors operate servers outside Indonesia, so forwarding your request may involve an international transfer. By using the Service you acknowledge this transfer, which is inherent to reaching the models you have selected.
12. Changes to This Policy
We may update this policy as the Service evolves. Material changes — especially any change to what we log — will be announced in the dashboard and by email before they take effect. The "Last updated" date above always reflects the current version.
13. Contact
Questions about privacy, or a request under Section 8:
WhatsApp: +62 856-9235-0401
Website: https://snifoxai.com
We meter tokens, not text. Your prompts pass through SnifoxAI Gateway, they do not stay in it.