1. Data we collect
- Account data. When you sign in with Google we receive your email address, name, and Google account identifier. We never see your Google password.
- Sign-in sessions. A session identifier, its creation and expiry time, and your browser's user agent string.
- API keys. We store a hash of each key and its first few characters for display. The full key is shown once when you create it and cannot be recovered afterwards.
- Task data. The parameters you submit (prompts, image URLs, and other model inputs), the callback URL if you set one, task status, error messages, and the generated result files.
- Billing records. Your credit balance and every recharge, charge, and refund, with amount and time.
- Technical logs. Request metadata such as IP address, time, and error details, recorded by our hosting provider.
2. How we use data
- To sign you in and keep you signed in.
- To authenticate API requests and run the tasks you submit.
- To hold, settle, and refund credits, and to show you your usage history.
- To deliver callbacks to the URL you provide.
- To investigate failures, prevent abuse, and keep the service secure.
- To contact you about your account, billing, or changes to these policies.
We do not sell your data, and we do not use your task inputs or results to train models.
4. How long we keep data
- Result files are deleted 30 days after the task is created. Copy anything you need to keep to your own storage before then.
- Sign-in sessions expire after 30 days, or earlier when you sign out.
- Account, API key, task, and billing records are kept while your account is active. When you ask us to delete your account we delete them, except billing records we must keep for legal or accounting reasons.
- Hosting logs are kept for the period set by our hosting provider.
6. Your choices and rights
You can view your tasks, API keys, and transactions in the console, and revoke any API key at any time.
To get a copy of your data, correct it, or delete your account, email support@xbaiapi.com. We reply within 30 days. Depending on where you live, local law may give you further rights, such as objecting to certain processing or lodging a complaint with a data protection authority.
7. Security
All traffic is served over HTTPS. API keys are stored only as hashes, and session cookies are HttpOnly and Secure. No system is perfectly secure: keep your API keys private, and revoke a key immediately if you think it has leaked.
8. International transfers
Our providers operate infrastructure in many countries, so your data may be processed outside the country where you live.
9. Children
The service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.
10. Changes to this policy
When we change this policy we update the date at the top. For material changes we will notify you by email or in the console before they take effect.
11. Contact
Questions about this policy or your data: support@xbaiapi.com.