1. Introduction
This Privacy Policy explains how OPENSTART TECHNOLOGY LIMITED ("we", "us", or "our") collects, uses, stores, shares, and protects your personal information, and what rights you can exercise. "the Platform" refers to the InOneAPI website, the management console, and the API services.
We provide only platform capabilities such as model access, smart routing, metering and billing, and observability. We are not a developer of large models, and we are not the party that actually provides the model services. Inference for the models you call through the Platform is performed by third-party model providers, and that processing is governed by each provider's own policies, which this policy cannot replace.
By using the Platform you acknowledge that you have read and understood this policy. This policy applies to your account, to the management console, and to your API calls, in the language you selected when you registered.
2. Information We Collect
Account Information
- Your email address, name (optional), account language preference, and account status.
- If you register with email, we store your password only as a salted memory-hard hash. We never store plaintext passwords.
- If you sign in with Google or GitHub, that provider shares details such as its account identifier, your email address, and your avatar after you grant permission, and we store them in our own account tables. We never automatically link accounts created through different sign-in methods based on email address.
Sessions and Credentials
- Login session records (session identifier, expiry, last activity time, User-Agent), used to keep you signed in and for security audits.
- One-time tokens for email verification, password reset, and similar operations are stored only as hashes.
- API Key settings such as the key identifier, name, owning project, permitted model scope, budget, and rate limits. To protect credentials, we store only the key digest used for verification and the display prefix needed to identify the key.
Workspace and Project Information
Configuration details for workspaces, projects, members, member roles, and sub keys, such as their names, email invitation addresses, budget limits, and model allowlists.
Billing Information
- Wallet currency, balance, top-up orders, payment transactions, invoices, and usage records.
- When you pay through Stripe, the payment provider handles your payment account and transaction information independently. We receive only the order number, amount, currency, and transaction status needed to credit your wallet, and we neither collect nor store your card number or payment password.
Usage and Diagnostic Metadata
To authenticate, bill, route, and troubleshoot requests, the Platform records request-level metadata, for example: request time, status code, latency and time to first token, model identifier, the provider channel actually used, retry count, input, output, and cached token counts, cost, X-Gateway-Trace-ID, and any application attribution identifier declared in request headers.
Content You Upload
Playground conversation history, attachments, and materials you upload through the file interface are business data that you choose to store. Attachments are kept in private object storage, and signed access URLs are generated only after you sign in and only for content whose ownership check has passed.
Device and Log Information
Browser type and version, operating system type and version, IP address, times of access and page paths, and abnormal traffic patterns. We use this information for security protection, error diagnosis, and capacity planning, and never link it to advertising profiles.
3. What We Do Not Store
The Platform applies zero content logging consistently. This is our standard mode of operation, not an optional setting:
- Prompt text, model response text, and streamed content chunks are never written to request log databases.
- Content is only forwarded, streamed, and counted for tokens in gateway memory.
- Metadata is not content. The request-level usage and diagnostic data described above does not include prompt or response text.
Exceptions we should explain: to provide technical support that you have explicitly requested, to handle feedback you submit voluntarily, or to investigate suspected unlawful conduct or abuse, we may process additional information to the minimum extent necessary, and we will tell you the basis and scope of that processing.
4. How We Use Information
- To provide, maintain, and improve features such as accounts, routing, billing, the console, and the online experience.
- To perform identity authentication, session maintenance, and credential verification.
- To carry out request-level metering, invoice generation, balance deductions, and reconciliation.
- To detect abnormal traffic, retry storms, leaked API keys, and abuse, and to apply proactive circuit breaking and alerts.
- To enforce the permissions, budgets, and model restrictions you configure for projects, members, and sub keys.
- To send you service notices, billing reminders, and security alerts.
- To meet legal, accounting, and audit requirements, and to respond to requests to exercise your rights.
5. Sharing, Entrusted Processing, and Disclosure
We do not sell your personal information, and we do not share personal information for advertising purposes. We share or entrust processing only in the following situations:
- Model providers: request content must be sent to the provider that performs the inference in order to generate a result. Providers differ in their retention, regional, and compliance policies, so please review their terms before choosing a model and a channel.
- Cloud infrastructure providers: hosted databases, object storage, servers, and network services, which process data only under our instruction in order to run the service.
- Payment providers: top-ups and transactions run through Stripe; the provider returns to us the result information needed to credit your wallet.
- Sign-in and notification services: Google and GitHub provide third-party sign-in, and our email provider sends verification, reset, and notification emails.
- Abnormal traffic alert channels: alerts pushed to administrators over WeChat or email according to your configuration.
- Legal requirements: disclosure where required by law, where judicial or administrative authorities make a request in accordance with law, or where necessary to protect the legitimate rights and interests of us or of you. We will notify you in advance or promptly to the extent this is permitted.
- Business transfers: in the event of a merger, acquisition, or asset transfer, we will require the successor to remain bound by this policy, and we will notify you to the extent it affects you.
6. Where We Store Data and Cross-Border Transfers
Core business data is stored in cloud environments located within China. Each account has a single billing currency, fixed at registration and topped up through Stripe, so payment transactions are processed by payment providers outside China. When you sign in with Google or GitHub, the corresponding provider also processes your authorization information outside China.
In these cross-border scenarios we transfer only the minimum information necessary for the purpose, and we safeguard the security of the transfer and of storage through contractual and technical measures. The regions in which upstream model providers process data are governed by their own policies.
7. Retention Periods
- Accounts, workspaces, projects, key configuration, and wallets: retained for as long as the account exists; after account closure we retain the records that law requires.
- Session records: invalidated immediately on expiry or when you sign out, and revocable at any time.
- Usage and billing records: retained for the statutory periods needed to satisfy accounting, tax, and dispute-resolution requirements.
- Attachments and Playground history: handled according to your own save or delete actions. Once a file is deleted it cannot be used for new requests, but we cannot recall content that has already been sent to a provider.
- Email verification and reset tokens: short-lived, and invalidated immediately once used or once expired.
When the retention period ends, or when you request deletion and no statutory retention obligation applies, we delete the data or anonymize it.
8. Security Measures
- Passwords are stored as salted memory-hard hashes. Sessions are revocable records in the database, delivered through signed HttpOnly cookies.
- Verification and reset tokens are stored only as hash values. OAuth authorization uses PKCE and state validation.
- Server secrets, authentication credentials, and payment credentials are kept only in server-side environment variables. They are never given the
NEXT_PUBLIC_prefix or sent to the browser. - The database enforces row-level security policies that limit visibility by user and by project. The server verifies ownership before processing attachments or requests.
- Uploaded objects are stored in private buckets and accessed through a restricted, signed custom domain.
- Internal access follows least privilege and audit requirements, and abnormal access can be detected and blocked.
No internet environment is absolutely secure. If a personal information security incident occurs, we will notify you of the incident, its likely impact, the measures we have taken, and recommendations for remedy as required by law, and we will keep records of how it was handled.
9. Your Rights
You can do the following yourself in the management console: view and correct your account profile, manage projects and members, create and revoke API keys, set budgets and model restrictions, delete Playground conversations and attachments, and export usage and billing details.
You also have the right to access, copy, correct, or delete your personal information, to withdraw consent you previously gave, or to request account closure. Please contact OPENSTART TECHNOLOGY LIMITED at support@inoneapi.ai and state which right you wish to exercise. To protect the security of your account, we may first verify your identity and then respond within a reasonable period. Closing your account does not relieve you of payment obligations incurred while the account was open, and records that must be retained by law will continue to be kept for their retention period.
10. Cookies and Similar Technologies
The Platform uses only cookies that are necessary to keep it working. We do not serve advertising and do not perform cross-site behavioral tracking:
ioa_session: keeps you signed in. It is a session-required cookie, is signed, and is readable only by the server.ioa_oauth_stateandioa_oauth_verifier: prevent request forgery during third-party sign-in, and expire once the flow completes.
You can block these cookies in your browser's cookie settings, but you will then be unable to sign in or use the console. Language preference is maintained by the language prefix in the address, and switching language never changes your account currency.
11. Automated Decisions
Smart routing selects a path among the multiple provider channels available for the same model, based on service quality metrics such as price, latency, throughput, error rate, and availability. This is technical scheduling of service resources; it does not constitute profiling of individuals or decisions that materially affect your rights. Abnormal traffic detection may trigger rate limiting or circuit breaking. If you disagree with such a measure, you may raise an objection and request human review using the contact details in Section 9.
12. Minors
The Platform is intended for business users and for adults with full civil capacity, and is not directed at children under 14. If you are a minor, please read this policy with your guardian and use the Platform only with your guardian's consent. We do not knowingly collect personal information from minors, and if we discover such information we will delete it as soon as possible.
13. Changes to This Policy
We may update this policy when features, legal requirements, or operational requirements change. Material changes will be announced to you through site notices, email, or a prominent notice on the page, and the updated policy applies from the effective date stated on the page. If you do not agree to the changes, you should stop using the Platform and request account closure.
14. Contact Us
- Operating entity: OPENSTART TECHNOLOGY LIMITED
- Email: support@inoneapi.ai
- Postal address: available on request by email
If you have questions about this policy, about your personal information, or about how third-party providers process data, please contact us. Questions about data processing for a specific model usually also need to be raised with that provider.