AI-Pay. Privacy Policy

AI-Pay Privacy Policy

Version 2026-10-08 | AI-Pay service | Privacy and data-rights contact: contact@coswic.ai

This service is currently an invitation-only Beta. Features may fail, service may be interrupted, and data may be lost. Avoid uploading sensitive or important data and keep your own backups. This notice does not replace necessary data security measures or reduce the data protection obligations described in this policy.

This policy explains what data AI-Pay collects, why, who receives it, how long it is kept, and your rights. AI-Pay does not use your AI request content for its own model training, sale or advertising; upstream services' practices are described in Sections 3 and 5.

This policy covers data processed between you and us through AI-Pay accounts, the Dashboard/Console, authorization services, APIs, SDKs and CLI. AI-Pay processes account, authorization, billing and service-operation data. Please also read the App's privacy policy for data it collects independently and how it uses that data.

What changed in this version: we explain processor-returned payment data, error-diagnostic excerpts, pseudonymous identifiers and the scope of encryption more fully. We distinguish the 15-minute replay window from actual deletion and disclose records that currently have no automatic deletion. Section 9 explains how to request access, correction, erasure and other data rights.

2. What we collect

CategoryDataSource
Account and sign-in dataemail, display name, internal account identifier; Google account identifier when using Google sign-in; a password hash when using password sign-in; sign-in and revocation statusyou, Google and the system
Authorization dataApps authorized, scopes, spending limits, consent times, pricing and consent information shown to you, and their versions or fingerprintsyour actions on the authorization screen and the system
Self-reported regionreported country/region and US state codes, reporting time and IP address at that time, used to assess regional rules, tax jurisdiction and evidence of your declaration; a reported region does not confine data processing to that regionyour Dashboard or authorization-screen declaration; IP recorded by the system
Record of consent to the Termsthe Terms version you explicitly accepted and the acceptance time; updating a page does not itself mean you accepted new Termsyour Dashboard or authorization-screen submission
Usage and billingrequest time, model, App, authorization and account associations, token counts, amounts and splits, request and retry identifiers, request fingerprints, outcomes and upstream diagnostic informationthe system and upstream services; see Section 3 for content handling
Payment dataorder amounts, status, transaction identifiers, fees, refund and dispute records, and payment events returned by processors. Events may include payer name, email, address, phone number, payment-instrument type or last four card digits, depending on the fields the processor returnsStripe/PayPal; full card numbers, security codes and PayPal sign-in credentials are collected on the processor's payment pages, not through AI-Pay forms
Developer dataApp and publisher names, website and privacy-policy links, redirect URIs, fee settings, payout account identifiers and link status; framework, package manager, generated file names, test receipt identifiers, CLI version and execution status reported while signed in to the CLIyour Console input, CLI actions and payment processors
Technical, security and audit recordsIP address, User-Agent, account and request identifiers, operation paths, times, outcomes, errors and administrative actions, for security, rate limiting, incident investigation and dispute reviewthe system

Ordinary account registration does not request government identity documents or biometric data. Content you submit may contain personal or sensitive data; submit only data you are entitled to provide and that the request needs. Payment processors may request identity verification directly under their own rules. We do not build advertising profiles inside AI-Pay.

3. Your prompts and responses

  • AI-Pay processes your input and model responses in memory while handling a request and sends request content to OpenRouter and the provider executing the model. This is not an end-to-end encrypted service or one in which AI-Pay cannot access plaintext.
  • Upstream retention and training practices depend on the provider, endpoint, routing and account settings. The brand prefix in a model identifier is not necessarily the hosting provider, and owned_by is not a complete recipient or processing-location list. See OpenRouter's data collection notice and provider data policies. AI-Pay does not promise zero retention or no training across all upstream services.
  • Ordinary requests do not write full prompt or response bodies into the usage ledger. When a request carries a Replay-Key, AI-Pay encrypts the response using a key derived from it and stores the ciphertext for replay. The default replay window is 15 minutes. After expiry, replay is unavailable and a background task deletes ciphertext in batches. This does not mean all copies disappear at the fifteenth minute; see Section 8 for backups and archives.
  • The caller supplies the Replay-Key to AI-Pay for encryption or replay decryption during the request; it is not written into capsule storage. Capsule ciphertext alone, without the corresponding key, cannot restore a response through the normal replay process. Callers must protect their keys.
  • To identify retries, we retain an authorization-associated request fingerprint (HMAC), rather than using it to store the original text. Fingerprints and pseudonymous identifiers may still be associated with an account and are not anonymous data.
  • Error diagnostics are an exception: excerpts of upstream error messages may be recorded in usage or incident records, and those messages may contain content fragments returned by the upstream service. Avoid unnecessary sensitive data in requests or support messages. See Section 8 for retention of these records.

4. Purposes and legal bases

The table explains processing purposes and their corresponding bases; GDPR terminology applies where that law applies. Processing based on a legal obligation is limited to an obligation that actually applies to the data and purpose. Reliance on legitimate interests must take account of your rights and reasonable expectations. Accepting the Terms is not blanket consent to every personal-data use.

PurposeCorresponding basis under applicable law
Providing the service: identity verification, authorization, model calls, charges and receiptsProcessing necessary to perform a contract
Accounting, reconciliation, tax and auditApplicable statutory retention or reporting obligations; otherwise legitimate interests in accurate accounts and dispute handling
Assessing regional rules and keeping evidence of Terms acceptanceLegal obligations where regional assessment is required; contract processing necessary to provide the service, and legitimate interests in keeping contractual evidence
Security, fraud prevention, rate limiting and abuse detectionLegitimate interests in protecting accounts, user funds and service security
Service notices and important changesContract performance; legal obligations where notification is required
Debugging, integration status and quality improvementsLegitimate interests in reliability and user support; data scope is described in Sections 2 and 3

Data necessary for account, authorization and payment functions is required to use those functions; without it, sign-in, authorization or payment may be unavailable. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing. We do not send marketing emails during the pilot.

5. Who receives data

RecipientPurposeData received
GoogleGoogle sign-in when you choose itverification and associated device, connection and flow information; Google is opened or its sign-in component loaded after you press “Sign in with Google”
StripePayments, refunds, disputes and developer payouts when enabledorder amount, currency, email and payment/payout information; payment-instrument and identity-verification information is collected directly on Stripe's pages
PayPalPayments, refunds and disputesorder amount, currency and transaction information; your PayPal account and payment-instrument information is collected on PayPal's domain
OpenRouter and the actual model providersExecuting AI requests and operating their servicesrequest content, parameters, usage and related request data; we send a stable authorization identifier to OpenRouter. AI-Pay can associate it with an authorization and account, so it is not anonymous. We do not separately add account email to model requests, but your content may itself identify you
Cloud provider (AWS)Hosting servers, databases, backups and archivesthe relevant hosted service data; processing may take place outside your country, as described in Section 11
Authorities / law enforcementApplicable legal requirementsdata required under applicable law

Section 6 describes third-party Apps' access. We do not sell personal data or exchange it with data brokers. Google, payment processors and upstream services may also process data for their own service purposes under their policies. Contact us using Section 1 to ask about recipients and processing arrangements relevant to your service.

6. What third-party Apps receive

  • An App receives a pseudonymous identifier specific to that App. The same user has different identifiers across Apps, reducing direct matching. Apps may still identify or associate you through the same email or other information you provide; complete unlinkability is not guaranteed.
  • Email and display-name information supplied through AI-Pay sign-in depends on the email/profile scopes you authorize.
  • AI-Pay does not provide Apps with your full wallet balance or other Apps' authorizations and usage. Developers can inspect their own App's usage, charges, request and authorization identifiers and related records; identifiers may be linked with the App's own records.
  • An App will commonly process what you enter into it and the responses it receives, and may independently collect account or other data. The Console's exclusion of full prompt and response bodies does not mean the App itself cannot access content.
  • Apps should explain their data uses and privacy policies. You can revoke an authorization in the Dashboard to prevent new authorized usage. Revocation does not automatically delete data already received by an App or recall requests already sent upstream.

7. Cookies and local storage

We use cookies and browser storage for sign-in, security, flow state and interface preferences, and do not configure advertising-tracking cookies on AI-Pay's own pages. Google and payment-processor pages may use their own cookies under their policies. AI-Pay's ordinary forms use origin headers for cross-site-request protection; the authorization server may also use anti-forgery flow cookies.

NamePurposeLifetime
aipay_gateshared pilot invitation pass; covers the main and authorization subdomains, with HttpOnly/Secure protections30 days
aipay_userDashboard/Console sign-in sessionexpires after 1 hour idle; at most 12 hours from sign-in
aipay_sessionsign-in state during a third-party App authorization flow10 minutes; flow actions may set it again
aipay_oauth_rememberremembers sign-in identity when you select “Remember me”; authorization still has account confirmation and consent steps; cleared by “Use another account”7 days
aipay.localeChinese/English language preference; set by language switching, a language-specific link or synchronization of an existing preference; readable/writable by the front end, not HttpOnly1 year
aipay_google_login / aipay_google_oauthanti-forgery state and one-time verification material during Google sign-in; HttpOnly10 minutes
aipay_shellinitial-screen hint: dash/dash-dev/setup, selecting the dashboard, developer workspace or account setup; no direct identity identifier; readable/writable by the front end, not HttpOnlyat most 12 hours; cleared on sign-out or when the system detects an invalid sign-in
authorization server oauth2_*anti-forgery, sign-in and flow state on the authorization domainexpiry is set by the authorization server and may be reset during a flow; you can inspect and clear it in your browser's cookie details

Browser storage (localStorage / sessionStorage)

AI-Pay's page scripts read and write the following data to operate the interface and flows; form, payment and authorization actions still send relevant data to the service. Storage does not contain full card numbers, security codes or sign-in passwords, but does include payment-intent data and one-time verification material:

  • sessionStorage (normally cleared when the tab closes; browser session restoration may affect its lifetime): selected App, tab, setup-wizard step, payout-availability cache, top-up amount, payment method and retry identifier, and consent-screen selections, limits and region. Flows also clear relevant data on completion or sign-out.
  • localStorage: language, sidebar, docs-hint and developer-workspace preferences, without a common automatic expiry. The Console's OAuth verification PKCE verifier and state are deleted when the verification page reads them; an unfinished flow may leave them until site data is cleared.

You can clear cookies and site data in your browser. This may sign you out, reset preferences or interrupt incomplete flows; it does not erase server-side accounts or transaction records.

The AI-Pay CLI (on your own machine)

The CLI keeps developer-management sign-in tokens, account identifiers and connection settings locally: in an operating-system keychain when available, or a user-scoped DPAPI-encrypted file on Windows; fallback or explicitly selected file mode uses a permissions-restricted plaintext file. The default is your user configuration directory, not your project. If you customize that directory, keep it outside the project and version control.

The project separately contains an .aipay/project.json link file and public .env.local settings. Sign-in, management and test commands send the credentials and request data needed for those operations. Integration reports sent while signed in contain the status data in Section 2, not the entire project or source files. aipay logout clears local credentials and attempts server-side revocation; if offline or revocation fails, revoke “AI-Pay CLI” under the Dashboard's “Connected apps”.

8. How long we keep data

The table describes current retention and cleanup. Categories without an automatic deletion deadline continue to be retained; deactivating an account or deleting an App does not automatically remove them. This does not limit your statutory rights to request erasure or restriction. Individual retention must take account of ongoing service provision, transaction completion, unresolved refunds or disputes, and applicable legal retention or evidence-preservation requirements.

DataRetention and cleanup
Encrypted replay capsulesdefault 15-minute replay window; after expiry, replay stops and background tasks delete ciphertext in batches. Actual cleanup may occur after expiry; backup copies are handled separately as described below
Accounts, authorizations, region declarations and Terms acceptancekept with the account/authorization. There is currently no complete automatic cleanup process following account deletion, so records may remain after deactivation. Erasure and retention exceptions require manual handling
Usage, ledgers, payment events and financial auditcurrently retained without an automatic deletion deadline, including usage diagnostics and processor-returned data. Any continued retention of personal data must be assessed against necessary transaction review, refund/dispute handling and applicable law
CLI integration reports and administrative auditcurrently retained without an automatic deletion deadline; deleting an App does not delete these records
Application operations logs and technical metricsdatabase operations logs are cleaned under default 14-day and 2 GiB limits; the size limit may remove data sooner. Technical metrics follow their associated cleanup job. Container logs rotate by size; ingress and other security records follow separate settings, with no single fixed number of days for all logs. Background cleanup is not instantaneous
Sign-in device records and consent-screen presentationseligible old records are cleaned on later sign-in or presentation; expiry of a cookie or screen does not mean associated database rows are deleted at that moment
Backups and archivesdatabase backups and financial-journal archives have separate retention and cleanup and may remain after primary data is deleted. There is currently no single fixed erasure deadline covering all copies

Complete account and personal-data erasure currently requires manual handling; there is no one-click complete erasure feature. Under Section 9, you may request the reasons, applicable periods and scope for retention or deletion of particular data. We handle requests under applicable law and explain any inability to erase all data. Account deactivation or authorization revocation does not itself erase data.

9. Your rights

Depending on applicable law, you may have rights of access, rectification, erasure, restriction, objection and portability. You can:

  • view authorizations, usage and transaction records in the Dashboard and revoke App authorizations;
  • send data-rights requests to contact@coswic.ai. During the Beta, requests are handled manually and may require reasonable identity verification. We respond within applicable legal deadlines and explain lawful extensions or reasons a request cannot be fully met;
  • withdraw consent where it is the basis of processing, or object to legitimate-interest processing where the law permits;
  • complain to the relevant data-protection authority, including your local authority in the European Economic Area or United Kingdom.

Complete personal-data export and erasure are not currently self-service features. For data held by an App or a service provider determining its own processing purposes, you may also need to contact that party.

10. Security measures

  • Production external connections use TLS. Authentication session cookies use protections including HttpOnly, Secure and SameSite; Section 7 explains differences for interface-preference cookies.
  • Database roles and permissions restrict access and protect ledger entries and key settled financial fields. Usage status and other mutable data change through authorized workflows; we do not claim all data is unchangeable in every circumstance.
  • Section 3 explains replay ciphertext and key handling and their limits. Encrypted storage does not mean AI-Pay never processes plaintext.
  • Passwords use a slow hashing algorithm. Full card numbers and security codes are entered on processors' payment pages; Section 2 describes transaction data AI-Pay receives.
  • No system is perfectly secure. For a personal-data incident, we assess risk and notify affected people and authorities where, and within the deadlines, applicable law requires.

11. International transfers

AI-Pay, cloud hosts, payment processors and model providers may process data outside your country, including in the United States. Reporting a region or choosing a model is not a data-residency restriction or a promise of processing within a particular region.

International data transfers must meet applicable legal requirements, including any required transfer grounds or safeguards. Contact us using Section 1 to ask about processing locations, recipients and transfer arrangements relevant to the service you use. This policy does not promise that every service uses the same transfer mechanism.

12. Children

The service is for people who have reached the age at which they can contract independently where they live and meet their selected model's age and regional restrictions. If you believe an ineligible minor has provided us with personal data, contact us using Section 1. We will investigate, restrict ineligible use and handle erasure under applicable law. Transaction records subject to legal retention obligations are handled under Section 8.

13. Changes and contact

For material changes, we will give prominent notice before they take effect, according to the nature of the change and applicable law, and obtain consent where required. For questions, requests or complaints, contact contact@coswic.ai.

Last updated: 2026-10-08. You can request relevant historical versions and change information using the contact details above.