Free test tokens — try any model

Privacy policy

Last updated 30 September 2026

VipAI is an AI API gateway. This policy explains what we collect when you use it, why, and what we do not do with it.

Who we are

VipAI operates the gateway at api.vipai.site and the site at vipai.site. Questions about this policy, or a request about your data, go to @vipai.

What we collect

  • Account data. The email address and password hash (or third-party sign-in identifier) you register with. Passwords are stored hashed, never in plain text.
  • API keys. The keys you create, and their metadata — name, creation time, last use. A full key is shown once when created and is not readable afterwards.
  • Usage records. For each request: the model, the token counts, the cost, the timestamp, a request id and the account the key belongs to. These are what your bill and the usage dashboard are built from.
  • Request content. Prompts and completions pass through the gateway in order to be forwarded to the model provider. They are processed for routing and are not retained for any other purpose.
  • Technical data. IP address and user-agent, used for rate limiting, abuse prevention and keeping the service available.

Why we process it

To deliver the request, to meter and bill it, to keep the platform free of abuse, and to answer your support questions. Prompt and completion content is processed only to the extent needed to route and measure a call.

What we do not do

  • We do not use your prompts or completions to train models.
  • We do not sell your data.
  • We do not share your traffic with other customers.

Who else is involved

A request you make is forwarded to the model provider that serves the model you selected — for example OpenAI, Anthropic, Google or DeepSeek — because that is what answering the request means. The provider’s own terms govern its handling of that request. We also use hosting and infrastructure providers to run the gateway.

How long we keep it

Usage records and billing history are kept for as long as your account is open, because they are your invoice and your audit trail. Account data is kept while the account exists. Technical logs are kept for a short period for abuse prevention and then discarded.

Your choices

  • You can revoke any API key at any time from the dashboard, which stops further use.
  • You can delete your account and ask for your data to be removed; contact us on Telegram and we will confirm what is deleted and what must be retained for billing integrity.
  • You can ask for a copy of the account and usage data we hold about you.

Security

Traffic is encrypted in transit, keys are stored so a full key cannot be read back, and access to production systems is restricted. No system is perfect; if we become aware of a breach affecting your account we will tell you.

Changes

If this policy changes in a way that matters, we will update the date above and, for significant changes, tell you through the site or Telegram.

See also the terms of service.