everyapi
Legal

Privacy Policy

EveryAPI ("we" or "the Service") respects and protects every user's personal information. This Policy explains, when you use everyapi.ai and the accompanying clients, API, and console, which data we process, why we process it, how long we keep it, who we share it with, and how you can exercise your rights. Please read it carefully, paying particular attention to the key provisions marked in bold.

Effective date: July 30, 2026 · Last updated: July 30, 2026

01Scope of This Policy

This Policy applies to the entire process of your using the Service through any entry point provided by EveryAPI, including but not limited to: the official website and marketing pages, the user console (app.everyapi.ai), the model-call gateway, the CLI / browser extension / desktop clients, the credit-hosting backend for Channel Providers, and any subsequent services we launch under the same name.

If you use EveryAPI through a third-party application (such as Cursor, Cherry Studio, or LobeChat), the third party's processing of your device's local data is governed by its own privacy policy; this Policy covers only the stages after a request enters the EveryAPI gateway.

02What Information We Collect

2.1 Information You Provide Directly

  • Account information: email address, username or display name, login identifiers, and security or session information associated with your account.
  • Billing information: top-up order identifiers, credited amounts, payment status, and limited results returned by payment channels; we do not intentionally collect full card numbers or payment passwords.
  • Seller-channel information: provider type, channel configuration and status, plan or usage information, and the credentials or OAuth authorization you submit so the gateway can operate the channel.
  • Support and feedback: the content you send us through tickets, email, Telegram, and other channels.

2.2 Information Generated Automatically by Service Operation

  • API call metadata: API key identifier, call time, target model, token consumption, HTTP status code, call duration, and error reason; used for billing, quota control, abuse detection, and troubleshooting.
  • Request and response content: processed to route and fulfill model calls and transmitted to the selected upstream provider. Content may also be processed when you submit it to support for troubleshooting.
  • Device and network information: IP address, User-Agent, client language, and other technical request context may be processed for service delivery, security, anti-abuse, and troubleshooting.
  • Cookies and local storage: used for authentication or session continuity and to remember language and interface preferences; see Section 8 for details.

2.3 Information from Third Parties

We may receive information about you from the following sources: basic profile data returned by third-party login providers, transaction results returned by payment providers, and diagnostic information returned by upstream model providers in abnormal cases.

03Why We Process This Information

  • Providing core services: identity authentication, key issuance, forwarding your calls to the chosen model provider, and billing by usage.
  • Billing and settlement: processing top-ups, calculating usage, maintaining balances and itemized records, and crediting or transferring eligible seller revenue.
  • Security and compliance: risk control and anti-abuse, identifying misuse, responding to malicious attacks, and complying with mandatory disclosure obligations under applicable law.
  • Service quality and observability: monitoring latency and error rates, locating failures, and capacity planning.
  • Communication and notifications: sending account security reminders, billing reminders, and service-change and major notices.
  • Product improvement: optimizing the product and pricing based on aggregated and non-personally-identifiable statistics.

We will not use your prompts or model output to train our own models, nor will we disclose this content to third parties other than upstream providers for that purpose.

04Information Sharing and Disclosure

4.1 Upstream Model Providers

EveryAPI is essentially a model gateway. When you initiate a call, we forward the request to the corresponding provider (OpenAI, Anthropic, Google, xAI, DeepSeek, and others) based on the target model you select. The request body itself, the necessary authentication headers, and the model's returned response all exist in the forwarding path and are processed in accordance with the respective provider's privacy policy. Please confirm the upstream providers' compliance requirements yourself before use.

4.2 Service Providers

To operate the Service, we share necessary data with a limited set of service providers, including: cloud computing and object storage providers, CDN and edge nodes, email / SMS delivery services, payment and invoicing services, customer support / ticketing systems, and error monitoring and observability platforms. We require service providers to process data only within the scope of providing services to us and to maintain a protection level consistent with this Policy.

4.3 Legal or Protective Disclosure

We may disclose relevant information in accordance with the law or in good faith in the following cases: responding to lawful requests from judicial, administrative, or regulatory authorities with jurisdiction; protecting the life, property, or safety of users, third parties, or the public; and investigating, preventing, or addressing fraud, abuse, security incidents, or violations of the Terms of Service.

4.4 Business Changes

In the event of a merger, acquisition, reorganization, or asset transfer, relevant user data may be transferred as part of the transaction; we will notify you in advance in a prominent manner and continue to protect your data to a standard no lower than this Policy.

4.5 Other Cases

Apart from the above cases, we will not sell your personal information to unrelated third parties.

05Cross-Border Data Transfer

Most of the target models EveryAPI forwards to are operated by overseas providers. When you call models such as GPT, Claude, or Gemini, your request is transmitted to servers outside mainland China for processing; this is a step necessary to deliver the service. We adopt industry-standard encrypted transmission and access-control measures to protect the path's security, but you should be aware that overseas providers may be located in different jurisdictions, and you should assess the compliance risk of your input information in such scenarios yourself.

If you do not want certain data transferred to specific countries or regions, please avoid sending such content to the corresponding models, or contact us to learn about optional regional routing arrangements.

06Information Storage and Retention Periods

  • Account and billing information: retained continuously for the life of the account; after the account is deactivated, retained for the minimum necessary period required by applicable law (such as the minimum retention requirements for vouchers under tax and accounting regulations), then deleted or anonymized.
  • Call metadata: recorded as needed for billing, usage history, abuse prevention, troubleshooting, and applicable legal obligations. Retention can vary by record type and operational requirement.
  • Request and response content: processed to relay your call and may be handled by the selected upstream provider. Avoid sending data you are not authorized to disclose and review the relevant provider's terms and privacy practices.
  • Risk-control and security logs: retained for periods appropriate to security, abuse prevention, troubleshooting, and applicable legal obligations; the period varies by log type and operational need.

We use HTTPS for supported network entry points and apply access controls and operational safeguards appropriate to the service. No security measure is absolute; protect your credentials and report suspected exposure promptly.

07Your Rights

To the extent permitted by applicable law, you may exercise the following rights at any time:

  • Access and copy: view your account information, call records, and bills in the console, or request a copy of your data.
  • Correction: update fields available in the dashboard, or contact us about information you cannot correct there.
  • Deletion: request account or personal-data deletion by contacting us. We will evaluate the request subject to identity verification, technical constraints, dispute handling, and legal retention requirements.
  • Withdrawal of consent: withdraw an optional authorization where the relevant product control or applicable law provides that right.
  • Complaint: if you believe our processing violates this Policy or applicable law, you may contact us or file a complaint with the regulatory authority that has jurisdiction.

We will respond within the timeframe required by applicable law. Identity verification, request complexity, technical constraints, or legal retention obligations may affect how a request is handled, and we will provide an explanation where appropriate.

08Cookies and Similar Technologies

We use necessary cookies for authentication and session continuity. Browser storage may remember language, theme, onboarding, table, announcement, support-widget, and other interface preferences, and may temporarily preserve navigation or form state. The marketing site also records a limited set of first-party product events, such as code-sample copies, using event names and restricted metadata rather than account credentials or prompt content. You can clear or disable browser storage in your browser settings; some features may then stop working as intended.

We currently do not participate in any advertising network, nor do we share your browsing data with third-party advertisers.

09Protection of Minors

EveryAPI is a technical service for developers and enterprises. Account eligibility is governed by the Terms of Service and the Service is not directed at children. If you are a guardian and discover that a child has used the Service without appropriate authorization, please contact us.

If we identify an account that does not meet the eligibility requirements in the Terms of Service, we may suspend or close it and handle the relevant personal information in accordance with applicable law.

10Third-Party Links and Services

This site may contain links that redirect to third-party websites or services (such as model providers' homepages, open-source project repositories, or integration tools). The pages reached by clicking such links are operated by third parties, whose handling of your data is governed by their own policies, and this Policy does not apply to them.

11Changes to This Policy

We may update this Policy from time to time. Versions involving material changes will be notified to you via in-site announcement, email, or a prominent prompt in the console, and the "effective date" at the top of this page will be updated. Continuing to use the Service after a change takes effect is deemed acceptance of the updated Policy; if you disagree, please stop using the Service and contact us to deactivate your account.

12Contact Us

For any questions, comments, or complaints regarding this Policy or the handling of personal information, please contact us by the following means:

  • Email: support@everyapi.ai
  • For compliance and data-protection matters, please mark "隐私" or "Privacy" in the email subject to expedite handling.

This Policy is governed by the Simplified Chinese version; if any other language version we provide is ambiguous compared with the Chinese, the Chinese version prevails.