Privacy Policy
Last updated: May 8, 2026
Your privacy matters to us. This Policy sets out how we collect, use, store and protect your personal information, and how you can control it.
WanAPIs is independently operated by an individual developer and has no affiliation or partnership with OpenAI, Anthropic, Google or any model provider. Your requests are forwarded to the upstream provider you select, and we retain nothing for training purposes.
WanAPIs is an independently operated service, not affiliated with OpenAI, Anthropic, or Google. Your requests are forwarded to the selected upstream model provider for processing; we do not retain your content for training purposes.
1. Overview
WanAPIs (the "Service") respects and protects your privacy. This Privacy Policy explains what information we may collect while you use the Service, how we use and protect it, and what rights you have over it.
Please read this Policy carefully. By registering for or using the Service, you acknowledge and agree to it.
2. Information we collect
To provide the Service we collect:
(1) Registration data: your email address, your password (stored salted-and-hashed, so we cannot recover it) and an optional display name;
(2) Sign-in data: sign-in time, IP address and user agent;
(3) API usage metadata: request time, model selected, tokens consumed, source IP of the call, HTTP status code and whether a cache was hit;
(4) Billing records: order number, amount, payment channel and status;
(5) Anything you send us directly, such as the content of support emails.
3. What we do not collect
In normal operation the Service does not persist any of the following:
(1) the prompts you send to upstream LLMs or the completions they return — we record only usage metadata (model, token counts, latency, source IP, route) and never write conversation content to disk;
(2) file content passed with synchronous requests, which is released from memory once forwarded;
(3) sensitive personal data such as bank accounts, national ID numbers or phone numbers — the Service never asks for them.
Exception: asynchronous image and video generation are job-based. Your request (including the prompt) is written to disk only while the job is running, so progress can be tracked across polls; it is cleared as soon as the job completes or fails, and in any case within 7 days. The API key used to forward it is cleared the same way. See the Data & Security page (/legal/data) for the full explanation.
For troubleshooting and anti-abuse purposes we may, in exceptional cases, temporarily record request summaries (never the content itself), kept for no more than 7 days.
4. How we use information
We use your information to:
(1) provide core functionality — API calls, billing and usage statistics;
(2) send you service notices such as security alerts, billing reminders and changes to our terms;
(3) improve the Service — for example, analysing the distribution of model calls to tune routing (always in aggregate, never targeting an individual);
(4) detect, prevent and pursue abuse and fraud;
(5) meet our legal obligations.
We do not use your personal information for advertising, and we do not sell it to third parties.
We never use your prompts, completions or any request content to train our own or any third-party models. The Service only forwards requests and retains nothing for training.
5. Third-party services
To operate the Service we must pass some information to the following third parties:
(1) Cloudflare — CDN, WAF, DNS and email routing. Every request to the Service passes through Cloudflare's network;
(2) Spacemail (Spaceship) — delivers our transactional email, such as sign-up codes and password resets;
(3) Upstream LLM providers — OpenAI, Anthropic, Google, DeepSeek and others. When you call the API, your request is forwarded to the model you selected, and that processing is governed by the provider's own privacy policy;
(4) Payment channels — when you top up, your payment details go directly to the payment provider; we receive only the order number and a success/failure status.
We require all third parties to protect your information within reason, but their processing is governed by their own policies and falls outside the scope of this Policy.
7. Retention periods
(1) Account data: kept until 30 days after you close the account or it is terminated;
(2) API call logs: purged automatically after 90 days;
(3) Billing and invoice records: 5 years, for tax compliance;
(4) Support correspondence: 1 year.
After you close your account we permanently delete the relevant data once the periods above elapse, unless the law requires otherwise.
8. Your rights
You may exercise the following rights at any time:
(1) Access — obtain all information we hold about you;
(2) Rectification — correct inaccurate or incomplete information;
(3) Erasure — request deletion of your account and related information;
(4) Portability — request an export of your usage records in CSV or JSON;
(5) Withdrawal of consent — where processing relies on your consent, you may withdraw it at any time.
To exercise these rights, write to [email protected]; we reply within 7 business days.
9. Cross-border transfers
You understand and agree that most upstream LLM providers used by the Service are located outside mainland China. When you call one of those models, your prompt is sent to overseas servers for processing.
We apply the necessary safeguards — end-to-end HTTPS and API-key authentication — to protect data in transit, but we cannot control the legal environment of the destination country or region.
If you would rather your requests never leave the country, use only the models marked as domestically hosted (such as DeepSeek and Qwen).
10. Security measures
We protect your information by:
(1) storing passwords as one-way bcrypt hashes, so we cannot recover them;
(2) encrypting all API traffic with HTTPS (TLS 1.2+);
(3) hosting in access-controlled data centres, with the admin panel behind Cloudflare Zero Trust;
(4) storing API keys encrypted and displaying only a masked prefix and suffix;
(5) running regular security audits and vulnerability scans.
Even so, no internet transmission is completely secure. In the event of a data breach we notify affected users by email within 72 hours of discovery.
11. Protection of minors
The Service is not directed at children under 14. If we discover we have inadvertently collected a child's information, we delete it immediately.
If you are a guardian and find that a child has registered without your consent, contact us and we will delete the account.
12. Changes to this Policy
We may revise this Policy as the law or the Service changes.
Material changes — such as broadening what we collect or changing who we share it with — are announced by email 30 days in advance. Minor changes are reflected in the "Last updated" date on this page.
Continuing to use the Service constitutes acceptance of the current version of this Policy.
13. Contact us
For any question or complaint about this Policy, or to exercise the rights above, contact us at:
Email: [email protected]
We reply within 7 business days of receipt.
This Policy and the Terms of Service together form the complete legal basis for your use of WanAPIs.