Legal

Privacy Policy

Last updated: March 3, 2026

1. Information We Collect

Account Information: When you create an account, we collect your email address and authentication details via magic link login. We do not collect passwords.

Usage Data: We log API calls, token usage, model selections, and response metadata (latency, status codes) to provide analytics and enforce billing. We do not store the content of your prompts or AI-generated responses beyond the duration of the request.

Payment Information: Payments are processed by Stripe. We store your Stripe customer ID and subscription details but never store credit card numbers or bank details directly.

Technical Data: We collect IP addresses, browser user-agent strings, and device information for security, rate limiting, and abuse prevention.

2. How We Use Your Information

  • To provide, maintain, and improve the AI Tutor API service
  • To process payments and manage your account balance
  • To enforce rate limits, prevent abuse, and maintain security
  • To provide usage analytics and statistics in your dashboard
  • To send transactional emails (magic links, billing notifications)
  • To respond to support requests

3. Data Retention

Prompt & Response Content: We do not persistently store the content of API requests or responses. Data is processed in-memory and discarded after delivery.

Workflow Metadata: Workflow run records (timestamps, model used, token counts, status) are retained for billing and analytics purposes.

Streaming Tokens: Single-use tokens are stored in Redis with a maximum TTL of 300 seconds and are automatically deleted after use or expiry.

Account Data: Retained as long as your account is active. You may request deletion by contacting support.

4. Third-Party Services

We use the following third-party services to operate the platform:

  • Vercel — Hosting and serverless infrastructure
  • Stripe — Payment processing
  • Upstash Redis — Rate limiting and temporary token storage
  • OpenRouter — AI model routing to providers (OpenAI, Anthropic, Google, etc.)
  • Resend — Transactional email delivery

Each provider processes data according to their own privacy policies. We select providers that meet industry security standards.

5. API Keys & Security

Your API secret keys are stored securely in our database. Bring Your Own Key (BYOK) credentials are encrypted at rest using AES encryption.

We implement rate limiting, single-use token authentication for streaming, and fail-closed security patterns to protect your data and prevent unauthorized access.

6. Your Rights

  • Request access to your personal data
  • Request correction of inaccurate data
  • Request deletion of your account and associated data
  • Export your workflow configurations
  • Revoke API keys at any time from your Settings dashboard

7. Cookies

We use essential cookies for authentication session management. We use Vercel Analytics for anonymous usage statistics. We do not use advertising cookies or third-party tracking pixels.

8. Contact

For privacy-related inquiries, contact us at support@mytsi.org.