Skip to content

Legal

Privacy policy

What we collect, why, how long we keep it, and the switch that turns payload storage off.

Last updated: 27 July 2026

Read this first: we store your prompts by default

For every API request we store the full request body and the full response body, together with your user id and the IP address the request came from, for 30 days, after which they are deleted automatically. This is what lets our support team reconstruct a failed call with you.

We therefore do not operate zero data retention by default, and you will not find that claim anywhere on this site. If you would rather we kept only metadata, switch on Zero Data Retention in your dashboard settings; from that moment payload storage is skipped for your account, and existing payloads age out on the schedule above.

1. Who is responsible

FuelOfAI is the data controller for the personal data described here. We are an independent API aggregator and are not affiliated with, endorsed by, or sponsored by Anthropic, OpenAI, or Google. Contact us about anything on this page at support@fuelofai.com.

2. What we collect and how long we keep it

Categories of data we hold, why we hold them, and the retention period for each
DataWhyRetention
Email address, password hash, verification and session recordsTo create and secure your account. Performance of our contract with you.While your account exists
Request and response payloads, with user id and IP addressDebugging failed calls, abuse and fraud investigation. Our legitimate interest in running a supportable, non-abused service.30 days, or not stored at all if you enable Zero Data Retention
Usage metadata: timestamp, model, token counts, latency, cost, status code, request id, key id, IP address, user agentMetering and billing, rate limiting, capacity planning. Performance of our contract.90 days
Aggregated daily usage totalsYour dashboard charts and our own accounting.Retained for the life of the account
Transaction records: amount, credits, gateway reference, statusBilling, refunds and accounting. Legal obligation.As long as tax and accounting law requires
API key metadata: name, prefix, last four characters, last-used timeSo you can identify and revoke a key. The key itself is stored only as a hash.While the key exists

We do not sell personal data, we do not use your prompts or completions to train models, and we run no advertising or cross-site tracking. Our cookies are the ones needed to keep you signed in.

3. Payload storage in detail

The stored payload is the JSON body you sent and the body we returned, exactly as transmitted. If your prompt contains personal data, that personal data is stored for the retention window. Please consider that before sending someone else's information through the API, and use Zero Data Retention if you cannot accept it.

Access is limited to the operators who need it for support and abuse investigation, and it is audited. Payloads carry an expiry timestamp and a scheduled job deletes expired rows; the window is set by the operator and shown on this page, currently 30 days.

Turning on Zero Data Retention stops new payloads being written for your account. It takes effect within about a minute, which is how long an authenticated key context is cached. Metadata in the table above is still recorded — without token counts we cannot bill you.

4. Who we share data with

Model providers. The content of your request is transmitted to the third-party model provider that serves it, under our commercial account with them, and is subject to their own processing terms. We do not publish which provider serves a given model; your own dashboard logs show the channel used for each of your requests.

Infrastructure and service providers. Our hosting and database provider, our payment processor (which handles your payment details directly — we never see them), our transactional email provider, and our rate-limiting cache provider. Each processes data on our instructions only.

Legal. We disclose data where we are legally required to, or to establish or defend legal claims. We will tell you unless we are prohibited from doing so.

These providers operate in several countries, so your data may be transferred outside your own. Where that happens we rely on the transfer mechanisms available under applicable data protection law, such as standard contractual clauses.

5. Security

Passwords are hashed. API keys are stored as a SHA-256 hash and shown to you exactly once. Upstream provider credentials are encrypted with AES-256-GCM and decrypted only in memory at the moment a request is routed. Logs are redacted so that keys and authorisation headers cannot be written to disk.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant supervisory authority as required by law.

6. Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, restrict or object to processing, receive it in a portable form, and withdraw consent. You can exercise most of these directly: export usage from your dashboard, revoke keys, turn on Zero Data Retention, or delete your account.

For anything else, email support@fuelofai.com and we will respond within one month. You also have the right to complain to your local data protection authority.

We do not knowingly collect data from anyone under 18. If you believe a minor has an account, tell us and we will delete it.

7. Changes to this policy

If we change what we collect, why, or how long we keep it, we will update this page and announce material changes on the site and by email where we hold your address. The date at the top of the page always reflects the version in force. Related reading: our terms of service and refund policy.

FuelOfAI is an independent API aggregator and is not affiliated with, endorsed by, or sponsored by Anthropic, OpenAI, or Google. All trademarks belong to their owners.