| Operator / brand | metaproxy |
|---|---|
| Covered products | https://metaproxy.agency, the console, API gateway (https://api.metaproxy.agency/v1), and related services |
| Version | v1.0 |
| Effective date | July 31, 2026 |
| Privacy contact | privacy@metaproxy.agency |
| Support contact | support@metaproxy.agency |
Key commitments
- We do not retain complete API request or model-output bodies by default. We retain usage metadata needed for billing and troubleshooting, such as model, token counts, cost, and status.
- metaproxy does not use your inputs or outputs to train any AI model and does not sell conversation content.
- Requests are forwarded to the upstream model provider you select. That provider handles content under its own privacy policy.
- Online payments are handled by third-party processors such as Creem. We do not store full card numbers or CVVs.
Scope
This Privacy Policy describes how metaproxy (“we”, “us”) collects, uses, stores, shares, and protects information when you visit our site, register or sign in, create API keys, use the gateway, add credit, review logs, read integration documentation, or contact support.
If this policy conflicts with the Terms of Service on personal-data processing, this policy controls.
Information we process
We process the following information as necessary for each feature and apply data-minimization principles.
Account and identity information
- Username, display name, account ID, and registration and sign-in times;
- Email, when email verification is enabled, and salted password hashes; we do not store plaintext passwords;
- Minimum information received from third-party sign-in such as GitHub OAuth, generally email and username within the scope you authorize;
- Sessions, optional two-factor settings, unusual sign-in signals, and risk-control indicators;
- Referral relationships when you use referral features.
API keys and developer configuration
- Key name, identifier, status, creation time, expiration, permission scope, and model scope;
- Key hashes used for verification; the complete plaintext key is generally shown only once at creation;
- Metadata necessary for base URL, model ID, SDK, and CLI configuration.
Do not send complete API keys in public repositories, screenshots, communities, or support tickets. You are responsible for credit consumed through a leaked key.
API usage data and logs
A. Usage metadata, retained by default for billing, reconciliation, security, and troubleshooting
- Request time, model ID, API-key identifier, and request ID;
- Input, output, and cached token counts; cost, currency, and balance-deduction result;
- HTTP status, error code, streaming status, latency, and upstream routing summary;
- Source IP for risk control and security audit, User-Agent, and endpoint path.
B. Request and response bodies, not retained long-term by default
- Inputs such as prompts, system messages, messages, files, and parameters;
- Model outputs such as text, code, and tool-call results.
Bodies are processed transiently for routing and are not retained long-term after a request completes. They may be retained briefly in the following exceptional cases, generally for no more than 30 days unless law or an upstream review requires otherwise:
- You explicitly enable a debugging or full-log feature, if offered;
- You paste request or response content into a support ticket or email;
- Risk control, abuse detection, security audit, or lawful enforcement requires review;
- We must resolve a billing dispute, refund dispute, chargeback, or third-party complaint.
Payments, balance, and order information
- Top-up amount, currency, order number, payment status, credited amount, and usage details;
- Minimum transaction information returned by processors. Card payments are handled by third parties such as Creem; we do not store full card numbers, CVVs, or payment-account passwords;
- Redemption-code use, refunds, unusual transactions, and related risk-control records.
Support and communications
- Descriptions, request IDs, screenshots, and log excerpts you submit through email or other support channels;
- Communication history and case status.
Do not send complete API keys, passwords, or other sensitive credentials through support channels.
Website, device, cookies, and product usage
- IP address, access time, page path, browser, operating system, device type, language preference, and referrer, usually limited to the domain;
- Sign-in session, theme preference, and security signals;
- Optional console telemetry, enabled by default and controllable in Settings: page visits and duration, sign-in and registration outcomes, key and catalog actions, top-up outcomes, filters, performance metrics, and error categories. Telemetry does not collect prompt or response bodies, plaintext API keys, or card numbers.
How we use information
- Provide and maintain routing, console, key management, model catalog, logs, documentation, and examples;
- Authenticate accounts, detect unusual sign-ins, rotate keys, and manage risk;
- Measure tokens, charge credit, reconcile usage, and manage orders and balances;
- Respond to support requests, troubleshoot failures, and resolve payment disputes;
- Send security, balance, policy, and necessary maintenance notices;
- Prevent fraud, attacks, abusive volume, and violations of law or upstream policies;
- Improve usability using anonymous, de-identified, or aggregated analysis, excluding training on conversation content.
API content and upstream model providers
metaproxy is a third-party model aggregation and routing gateway. To complete a request, we forward its content, required parameters, and context to the selected upstream provider, such as OpenAI, Anthropic, Google, xAI, or DeepSeek, according to the actual route.
- Each upstream processes data under its own terms and privacy policy;
- Whether an upstream uses content for training and how long it retains content depend on its policies, which can change;
- If you process another person’s personal, sensitive, or regulated data, you must have proper authorization and satisfy applicable law.
How we share or disclose information
We do not sell personal information or share it for targeted advertising.
We share or appoint others to process information only as necessary:
| Recipient | Purpose |
|---|---|
| Upstream model providers | Complete the model request you selected |
| Cloud, CDN, and security providers | Hosting, transmission, protection, and availability |
| Payment processors such as Creem | Top-ups, refunds, reconciliation, and payment risk control |
| Email and support tools | Verification, service notices, and support |
| Professional advisers | Legal, accounting, tax, or dispute needs |
| Authorities and law enforcement | Legal requirements or protection of lawful rights |
International transfers
Our infrastructure, upstream models, and payment channels may be outside your jurisdiction. By registering, paying, and using the service, you understand that information may be transferred, stored, and processed abroad. You are responsible for assessing and complying with local rules on cross-border services, data transfers, and payments.
Storage and retention
| Category | Default retention |
|---|---|
| Basic account information | While the account exists; briefly after closure when needed for disputes |
| API-key metadata | While the key exists; briefly after revocation for security audit |
| Usage metadata | A reasonable period needed for billing, reconciliation, and risk control |
| Request and response bodies | Not retained long-term by default; exceptional retention is generally no more than 30 days |
| Payments and orders | Statutory periods required for accounting, tax, and disputes |
| Support cases | A reasonable period needed for support and complaint handling |
After the applicable period, information is deleted or irreversibly anonymized. Anonymous statistics may continue to be used to improve the service.
Your rights
To the extent available under applicable law, you can generally:
- Access and correct account information;
- Export or review usage and top-up records in the console;
- Rotate, disable, or delete API keys;
- Disable product telemetry in Settings, which stops sending immediately and discards queued in-memory events;
- Request account closure and deletion, subject to legal retention obligations;
- Ask questions or submit a privacy complaint.
Use console controls or email privacy@metaproxy.agency. We may verify your identity before acting to protect the account.
Account closure and deletion
You may request account closure through support. You will lose access and API keys will be revoked. Account and key metadata will be deleted or anonymized under this policy, while records required for payments, tax, risk control, or legal holds may remain for the applicable period.
Export any logs and invoices you need and migrate workloads before closing the account.
Minors
The service is for developers and organizations and is not offered to anyone under 18. We do not knowingly collect minors’ personal information. Contact privacy@metaproxy.agency if you believe a minor is using the service without guardian consent.
Security
We use reasonable technical and organizational safeguards, including:
- HTTPS / TLS in transit;
- Salted password hashes and no long-term plaintext API-key storage;
- Access control, least privilege, and operational audit;
- Detection of unusual usage and abuse.
No internet transmission is absolutely secure. Use a strong password, protect keys, and rotate them immediately after exposure. If a security incident affects personal information, we will take legally required remediation and notify affected users within applicable time limits.
Cookies and similar technologies
We use cookies, local storage, or similar technologies to:
- Maintain sign-in sessions and security checks;
- Remember interface preferences such as theme and language;
- Perform basic risk control and performance diagnosis;
- Send product telemetry within the scope of your consent.
You can manage cookies in your browser. Disabling required cookies may prevent sign-in or console features from working.
Third-party services
Our site and console may link to upstream documentation, payment pages, OAuth providers, and other third parties. They operate independently under their own privacy policies. When using third-party CLI or IDE tools with our service, review those tools’ policies as well; we are not responsible for their access to local files.
Policy updates
We may update this policy for legal, business, or technical changes. We will provide reasonable notice of material changes through the site, console, or registered email. Continued use after an update takes effect means you understand the revised policy; if you disagree, stop using the service and request account closure.
Contact us
| Privacy | privacy@metaproxy.agency |
|---|---|
| Support | support@metaproxy.agency |
| Legal | legal@metaproxy.agency |
| Website | https://metaproxy.agency |
We will handle requests within the time required by applicable law or within a reasonable period.