Privacy Policy
Effective: 2026-05-19 Operator: X80 Pte. Ltd. (Singapore) — "we", "us" Service: the MyAPI inference API at inference.myinferenceapi.com — "the Service"
1. What we collect
When you (or an upstream service such as OpenRouter routing your traffic to us) make a request to the Service, we receive and process:
- Request payload: the prompt, system instructions, tool definitions, model parameters (temperature, max_tokens, etc.), and stream preferences.
- Response payload: the model output we return.
- Operational metadata: timestamp, source IP, bearer-token identifier (NOT the secret itself), request/response size in tokens, latency, status code.
We do not require, request, or collect any information about the identity of the end user behind the request.
2. What we do with it
- Serve the request. Payloads are forwarded to the model and the response is returned to the caller.
- Operational logs. Status code, latency, and token counts are retained for up to 30 days for capacity planning and incident investigation.
- Billing and routing reconciliation. Per-token usage by bearer-token identifier is retained for up to 24 months to reconcile invoices with routing partners.
We do not:
- train models on your data,
- sell or share request/response content with third parties,
- combine request content with other data for marketing purposes,
- read or inspect request content except as needed to investigate an active security incident.
3. Retention
- Full request and response bodies: not retained beyond the lifetime of the request, except in transient debug logs (purged within 24 hours) and only if you have explicitly enabled trace-level logging on your account.
- Token-usage metadata (counts, latencies, bearer-token identifier): up to 24 months.
- Operational logs (status, latency, errors): up to 30 days.
4. Subprocessors
The Service runs on:
- Google Cloud Platform (compute, networking, storage) — GCP's security and privacy applies to data at rest and in transit on its infrastructure.
We do not use other subprocessors for request content.
5. Your rights
If you are an end user whose prompt was routed to us through a third party (such as OpenRouter), please contact that third party for data-subject requests, since they hold your account relationship. We will cooperate with verified requests forwarded by them.
For direct customers, write to simon@myapihq.com with:
- the bearer-token identifier (the prefix, not the secret),
- the time window of the requests in question,
- the right you wish to exercise (access, deletion, etc.).
We will respond within 30 days.
6. Security
- All traffic to the Service is TLS-encrypted.
- Bearer tokens are stored hashed at rest; the secret value is shown to you only at creation time.
- We follow standard GCP IAM least-privilege practices for operator access.
7. Changes
We will notify customers of material changes to this policy at least 30 days before they take effect, by email to the account contact on file.
8. Contact
Operator: X80 Pte. Ltd. Email: simon@myapihq.com