Privacy Policy

Last updated: August 2026 · “Store no content by default” is one of our design principles.

1. What we do not store by default

  • Full prompts and model responses;
  • Your downstream users' credentials such as Authorization headers and cookies;
  • File contents and sensitive parameters in tool calls.
  • The above passes through memory only while a request is forwarded and is never persisted as operational data.

2. Metadata we record

  • For billing, troubleshooting, and abuse prevention, each API request records: requested model, actual channel used, token usage, status code, first-token latency, total duration, request and response sizes, error category, and the upstream request ID.
  • These records do not include the content of requests or responses.

3. Account information

  • We collect your email address at sign-up; passwords are stored as salted Argon2id hashes, which no one — including us — can reverse.
  • API keys are stored only as irreversible hashes; login sessions and email verification tokens are likewise stored as hashes only.
  • We send transactional email (verification, password reset) through our email provider (Resend); these emails never contain your password or API keys.

4. Payment information

  • Payments are processed by Stripe. Card numbers and Alipay/WeChat account details are collected and stored by Stripe; we never touch or store them.
  • We keep transaction records such as order amounts and payment status for reconciliation and receipts.

5. Cookies

  • We use only strictly necessary cookies: the login session (HttpOnly), a CSRF protection token, and one UI preference cookie remembering the console sidebar's collapsed state (containing no personal information).
  • We do not use third-party tracking or advertising cookies.

6. Data sharing & security

  • We share your data with no third parties beyond the upstream model providers and the payment and email providers required to deliver the service, except where required by law.
  • Upstream provider credentials and sensitive configuration are stored encrypted with AES-GCM, with decryption keys kept separate from the database.
  • Data is stored on servers in Singapore and transmitted over encrypted channels.

7. Your rights & contact

  • You can revoke API keys and log out at any time; to export or delete your account data, contact us.
  • Contact: support@dukou.ai