Skip to content
Jiayu API
Models Product BYOK Docs Pricing Console
Log in Create account
ModelsProductBYOKDocsPricingConsoleLog inCreate account

Legal

Privacy Policy

This Policy explains how information is collected, used, disclosed, transferred, retained, and protected when you use Jiayu API.

Last updated: July 28, 2026Privacy contact: hj1915886818@outlook.com

On this page
Scope and operator Information collected API request handling How information is used Disclosures Cross-border processing Retention and deletion Security measures Your privacy rights Children Policy changes Contact

The operator of Jiayu API is responsible for the processing described here when it determines the purposes and means of that processing. Independent model, payment, and other providers apply their own privacy notices.

1. Scope and operator

This Privacy Policy explains how the operator of Jiayu API (“Jiayu API,” “we,” “us,” or “our”) collects, uses, discloses, transfers, retains, and protects information when you use the Jiayu API website, console, hosted model routes, bring-your-own-key (“BYOK”) routes, support channels, and related services (collectively, the “Service”). Where applicable privacy law uses the term “controller” or a similar term, the operator of Jiayu API is the controller for the information described here, except where another party determines its own processing purposes.

This Policy does not govern a model provider, payment provider, or other third party acting under its own privacy notice.

2. Information we collect

Account information. We collect information you provide when creating or managing an account, such as username, display name, email address, sign-in credentials or authentication identifiers, account settings, account status, and related communications.

Transaction metadata. When you add balance, purchase service credits, or incur charges, we may process transaction amount, currency, status, timestamps, account identifiers, payment method type, and payment or order reference numbers. A payment provider may collect payment instrument details under its own privacy notice; the information Jiayu API receives depends on the payment method used.

API usage records. We may process the Jiayu API key or token identifier associated with a request, selected model and route, request time, token or other usage units, charge amount, response status, error information, latency, rate-limit events, and similar operational metadata. Secret keys should not be included in ordinary logs, but you remain responsible for not placing secrets in URLs, prompts, error messages, or other fields not intended for credentials.

Request and response data. To provide an API response, the Service processes the request payload you submit, which may include prompts, messages, files, images, audio, or other Input, and processes the Output returned by the selected provider. This data necessarily passes through systems involved in routing and delivering the request. Hosted routes may send Input to, and receive Output from, the relevant model provider. For BYOK routes, your provider credential also necessarily passes through Jiayu API’s TLS endpoint before being forwarded. The current BYOK proxy is designed not to write provider credentials to the Jiayu application database or BYOK access logs. The selected provider may process and retain request and response data under its own privacy notice and your agreement with that provider.

Device, network, and log information. When you use the website, console, or API, we may receive IP address, user agent, browser or device type, operating system, referring page, requested URL, timestamps, diagnostic events, and security or access-log information. Some BYOK routes have access logging disabled, but related authentication, network, provider, or security systems may still process limited connection or request metadata.

Support and communications. If you contact us, we collect your email address, message, attachments, account or transaction references you provide, and information needed to investigate and respond.

Local preferences. The public site may store language and theme choices in your browser’s local storage. These preferences remain on the device unless your browser, an extension, or another feature synchronizes or clears them.

3. How API requests are handled

Jiayu API is a gateway. We use request and response data to authenticate, route, process, return, meter, secure, and troubleshoot API calls. Depending on the selected route, data is transmitted to an independent model provider. Do not submit personal, confidential, regulated, or sensitive information unless you have a lawful basis, necessary permissions, and safeguards appropriate to that information.

We may inspect or preserve limited request or response data when reasonably necessary to investigate abuse, a security incident, a billing dispute, a support request, or a legal obligation. Whether an upstream provider stores or uses request or response data is governed by that provider’s terms and privacy practices. Jiayu API does not control those independent practices.

4. How we use information

We use information to:

  • Provide, authenticate, route, meter, and maintain the Service.
  • Create and administer accounts and API credentials.
  • Calculate usage, maintain balances, process transactions, and resolve billing issues.
  • Provide support and communicate about service, security, or policy changes.
  • Monitor performance, diagnose errors, improve reliability, and plan capacity.
  • Prevent fraud, spam, abuse, credential misuse, and attacks.
  • Enforce our Terms and provider requirements.
  • Comply with legal obligations and valid legal requests, and establish, exercise, or defend legal claims.

Where applicable law requires a legal basis, processing may be necessary to perform our contract with you, comply with law, protect legitimate interests in operating and securing the Service, protect vital interests, or be based on consent. Where we rely on consent, you may withdraw it, without affecting processing already carried out.

5. How we disclose information

We may disclose information only as reasonably necessary to the following recipients:

  • Model providers. We transmit API requests and related data to the provider selected by the route. For BYOK, the provider also receives the provider credential you supply.
  • Service providers. Hosting, network, content-delivery, database, monitoring, security, email, support, and payment service providers may process information on our behalf to perform their services. The actual providers used may change as the Service evolves.
  • Professional advisers and authorities. We may disclose information to auditors, legal advisers, insurers, regulators, courts, law enforcement, or other authorities when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or handle a claim.
  • Business transfers. Information may be disclosed as part of a financing, reorganization, merger, acquisition, sale of assets, or transfer of the Service, subject to appropriate confidentiality and applicable law.
  • At your direction. We disclose information when you direct us to do so or give valid consent.

We do not treat a model provider or other independent third party as being covered by this Policy when it determines its own purposes and means of processing. Review the third party’s terms and privacy notice before selecting a route.

6. International and cross-border processing

Jiayu API is intended for users in multiple regions. We and our model providers and other service providers may process information in countries or regions other than the one where you are located. Those locations may have different data-protection laws. Where applicable law requires safeguards for a cross-border transfer, we will use a lawful transfer mechanism or other required protection. Availability of a route may depend on your region and the provider’s regional rules.

7. Retention and deletion

We retain information only for as long as reasonably necessary for the purposes described in this Policy, including to provide an active account, meter and bill usage, maintain security and fraud-prevention records, resolve disputes, enforce agreements, and meet legal, accounting, tax, or reporting obligations.

Retention depends on the type of data and context. Account information is generally kept while the account is active and for a limited period afterward as needed for closure, security, disputes, or legal compliance. Transaction records may be kept for the period required for accounting, tax, anti-fraud, chargeback, and legal obligations. API usage metadata and operational or security logs are kept according to operational, security, billing, and provider needs. Request and response data is ordinarily processed for delivery, but limited copies may remain in troubleshooting records, incident evidence, support communications, or backups when necessary. Upstream providers set their own retention periods. BYOK provider credentials are not intended to be written to the Jiayu application database or BYOK access logs.

Deletion from active systems may not immediately remove information from backup or disaster-recovery systems; backup copies are isolated from ordinary use and deleted or overwritten according to the applicable backup cycle. We may retain information when required by law or when needed to establish, exercise, or defend legal claims. You may ask for the current retention criteria applicable to a particular category by contacting us.

8. Security measures

We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. Measures include TLS for data in transit, access restrictions, credential controls, logging or monitoring where appropriate, and efforts to limit retained data to operational needs. BYOK provider credentials should be sent only from trusted server-side environments and never embedded in browser or client-side code.

No system or transmission is completely secure. You are responsible for securing your systems, account password, Jiayu API keys, provider keys, and any copies of data you receive from the Service. Notify us promptly if you suspect unauthorized account or credential use.

9. Your choices and privacy rights

You may review or update certain account information through the console and may revoke API keys. Depending on the law that applies to you, you may have rights to request access to, correction of, deletion of, or a portable copy of your personal information; object to or restrict certain processing; withdraw consent; or appeal a decision concerning a privacy request. You may also have the right to complain to an applicable data-protection authority.

To make an access or deletion request, email hj1915886818@outlook.com from the address associated with your account and describe the request. We may ask for information reasonably necessary to verify your identity and authority. We will respond within the period required by applicable law. Some information may be retained or excluded where an exception applies, including for security, fraud prevention, transaction records, legal compliance, or legal claims. Deleting an account may make the Service and any remaining balance unavailable; any refund request is handled under the Terms of Service and applicable law.

10. Children

The Service is designed for developers and organizations and is not directed to children. Do not use the Service or submit a child’s personal information if you are below the minimum age required to consent to online services where you live. If you believe a child has provided personal information without required permission, contact us so we can review and take appropriate action.

11. Changes to this Policy

We may update this Policy to reflect changes in the Service, providers, law, or data practices. We will post the revised Policy and update the “Last updated” date. When a change is material, we will provide additional notice through the Service or account contact information where reasonably practicable.

12. Contact

For privacy questions, access or deletion requests, security reports, or other concerns, contact the operator of Jiayu API at:

hj1915886818@outlook.com

Jiayu APIBYOKDocsAboutLog in
Terms of ServicePrivacy PolicySupport: hj1915886818@outlook.com

This Policy covers Jiayu API account, transaction, usage, request, log, support, and preference information.