Legal

Privacy policy

What we collect, why we collect it, how long we keep it, and what we never do with it.

Last updated October 3, 2026TermsPrivacy
In short: end users do not create accounts with us. We hold account data for partners, usage metadata for each key, and short-lived operational logs. Request content is proxied to the model and is not retained beyond those logs. We do not sell data, ever.

1. Scope

This policy describes how LotusAI ("LotusAI", "we", "us") handles information when you use the LotusAI API, this website, the one-line installers, the public Check key and status pages, and the partner console. It applies to two kinds of people: end users, who hold a key and call the API, and partners, who are issued accounts in order to create and manage keys.

Partners collect and hold their own records about the customers they sell to. That data is governed by the partner's own privacy practices, not by this policy.

2. What we collect

  • Partner account data. Name, business name, email address, a hashed password, and the settings and activity of the partner console (keys created, plans assigned, limits set). Only partners have accounts.
  • Key usage metadata. For each request made with a key: a timestamp, the model id requested, token counts, the response status code, latency, and the key it was made with. This is the data that enforces the five-hour window, powers the public Check key page, and lets partners see usage for the keys they issue. Keys are stored in a form that lets us validate them, together with a short display prefix.
  • Request logs for operation and abuse prevention. Standard server logs, including IP address, request path, user agent, status and timing, and limited error context when a request fails. These are used to keep the service running, enforce per-IP rate limits and investigate abuse.
  • Website data. This website does not use third-party analytics or advertising trackers. The Check key page may remember the last key you entered in your own browser's session storage, which clears when the tab closes and is never sent anywhere except to the key-status endpoint you asked it to query.
  • Messages you send us. If you contact us by email or Telegram, we keep the correspondence so we can respond and keep a record of the request.

3. Request and response content

The prompts, code, files and images you send, and the responses the models return, are proxied between your tool and the model provider over encrypted connections. Content is processed in memory to route, sanitise and meter the request. It is not stored in a database, not used to build profiles, and not used to train models by us.

Operational logs may transiently capture fragments of content when a request errors, so that faults can be diagnosed and abuse investigated. These logs are short-lived and access to them is restricted to the people operating the service.

Model providers process content under their own terms in order to generate a response. We select providers whose API terms do not permit training on customer content submitted through the API.

4. How we use it

  • to authenticate keys and partner accounts and route requests to models;
  • to meter usage against the five-hour window and per-minute limits, and to show that usage on the Check key page;
  • to give partners usage visibility for the keys they issue;
  • to monitor health, diagnose faults and improve reliability;
  • to detect, investigate and prevent abuse, fraud and security incidents;
  • to respond to you when you contact us and to meet legal obligations.

We do not use your data for advertising, and we do not build marketing profiles from API usage.

5. Sharing

We do not sell personal data and we do not share it with data brokers or advertisers. We share data only in these cases:

  • Model providers receive request content in order to generate responses, as described in section 3.
  • The partner who issued a key can see usage metadata for that key (never the content of requests) so they can support and renew it.
  • Infrastructure vendors that host the service, deliver email and provide monitoring process data on our behalf under contract.
  • Legal requirements, where we are compelled by law or where disclosure is necessary to protect the safety of people or the integrity of the service.
  • A business transfer, in which case this policy continues to apply to the data transferred.

6. Retention

Request and response contentNot retained beyond transient operational logs, which are kept briefly for debugging and abuse prevention and then deleted.
Key usage metadataFor the life of the key, so that the window, the Check key page and partner reporting keep working. Removed when the key is deleted by its partner, after a short grace period.
Partner account dataFor as long as the partner relationship is active, then as long as we are required to keep business records.
Access and security logsFor a limited period consistent with abuse investigation, then deleted or anonymised.

Where a shorter period is required by law, or a longer one is required to resolve a dispute or enforce our Terms, that period applies.

7. Security

  • All traffic to the API and this website is encrypted in transit with TLS.
  • Keys are validated on every request; partner passwords are stored hashed, never in plain text.
  • Access to production systems and logs is limited to the people who operate the service and is protected by key-based authentication.
  • Per-key and per-IP rate limits, together with abuse monitoring, protect the service and the data in it.

No system is perfectly secure. If you believe a key has been exposed, ask the partner who issued it to rotate it straight away.

8. Your choices and rights

  • See your usage. Anyone holding a key can see its status and usage on the Check key page without creating an account.
  • Access, correction and deletion. Partners can update their account details in the console. End users and partners can email us to ask what we hold about them, to correct it, or to have it deleted where we are not required to keep it. Deleting a key removes its usage metadata after a short grace period.
  • Objection and restriction. Depending on where you live, you may have the right to object to or restrict certain processing, and to lodge a complaint with a supervisory authority. We will honour these rights as the law requires.

9. Changes

We may update this policy as the service changes. The current version is always at this address with the date it took effect, and we will make material changes visible on this site.

10. Contact

Privacy questions and requests: [email protected]. Please include the key prefix (the first characters shown on the Check key page) rather than the full key when writing to us about a specific key.