Privacy Policy
What Information We Collect
To operate our service, we collect several types of information. When you create an account, we collect your email address for communication and account management, along with billing information processed through PayPal. We don’t store credit card details—PayPal handles all payment data directly.
We also collect usage data to operate and improve the service. This includes API request volume, which models you use, processing times, and rate limit events. We track timestamps of service activity to monitor performance and identify issues.
For security and analytics purposes, we collect technical data such as IP addresses, browser type, and device identifiers. We use Google Analytics to understand how people use our website, which helps us improve the experience.
If you opt in to our newsletter, we’ll record that preference so we can send you product updates. You can unsubscribe at any time.
What we don’t collect: We don’t store the actual content of your API requests or responses beyond your tier’s retention period (7, 30, or 90 days). We don’t collect sensitive personal information beyond what’s necessary to run the service. And we never see your payment card details—that’s all handled by PayPal.
How We Use Your Information
We use the information we collect to operate the service, process payments, and keep things running smoothly.
Your account and billing information lets us manage your subscription, process payments through PayPal, and communicate with you about your account. We use your email address to send transactional notifications like payment confirmations, failed payment alerts, and critical service updates.
Usage data helps us monitor service performance, identify technical issues, and prevent abuse. We track API request patterns to detect unusual activity, enforce rate limits, and maintain service stability. This data also helps us understand which models are most popular and where we should focus improvements.
Technical data from Google Analytics shows us how people navigate our website, which helps us improve the user experience. IP addresses help us prevent fraud and identify suspicious activity.
If you’ve opted in to our newsletter, we’ll use your email to send product updates, new feature announcements, and other marketing communications. This is completely separate from your service account—even if you’re a paying customer, we won’t send you marketing emails unless you explicitly subscribe to our newsletter. You can unsubscribe at any time.
We don’t use your data for advertising, we don’t sell it to third parties, and we don’t train AI models on your API requests or responses.
Data Retention & Deletion
The actual content of your API requests and responses—the prompts you send and the model outputs you receive—are retained based on your subscription tier:
- Starter tier: 7 days
- Scale tier: 30 days
- Enterprise tier: 90 days
This retention is a feature, not a limitation. It lets you retrieve past responses if you need them during that window. After your retention period expires, this data is automatically and permanently deleted. We don’t keep backups of it, and it can’t be recovered.
While your subscription is active, we retain your account information (email address, subscription details) and billing history (past invoices, payment records). This is necessary to manage your account, process recurring payments, and provide customer support if issues arise.
We retain anonymized usage logs and analytics data to monitor service health, identify performance issues, and understand how the service is being used. This data doesn’t include the content of your requests—just metadata like timestamps, request counts, model selections, and processing times. We retain this data for up to 12 months for operational purposes.
When you cancel your subscription, your account remains active until the end of your current billing period. During that time, you can continue using the service normally and your data retention follows your tier’s standard period.
Once your billing period ends and your subscription terminates, everything is deleted immediately:
- Your account information is permanently removed
- All API request and response data is deleted, regardless of whether it’s within your retention window
- Your API keys are invalidated
- Your billing history is purged
There’s no grace period, no backup retention, and no way to recover this data after termination. If you need to keep any of your data, you must export it before your subscription ends.
We may retain certain limited data for longer periods only when required by law (for example, payment records for tax compliance) or to resolve active disputes. This data is kept only as long as legally necessary and is stored separately from operational systems.
Who We Share Data With
We don’t sell your data, and we don’t share it with third parties for advertising or marketing purposes. But operating the service requires working with a few specific partners, and there are limited circumstances where we’re legally required to share information.
We use PayPal to process all subscription payments. When you subscribe, PayPal receives your billing information (email address, payment method) to handle the transaction. We never see or store your credit card details—PayPal manages that entirely. PayPal’s handling of your payment information is governed by their own privacy policy, which you can review at paypal.com/privacy.
This is the core of what we do: when you send an API request through our service, we forward it to the appropriate upstream provider—OpenAI, Anthropic, Google, xAI, or DeepSeek—depending on which model you’re using. These providers receive the content of your request (your prompt) and generate the response.
Each provider has their own data handling policies and terms of service. We recommend reviewing their policies if you’re processing sensitive information:
- OpenAI: openai.com/privacy
- Anthropic: anthropic.com/privacy
- Google: policies.google.com/privacy
- xAI: x.ai/privacy
- DeepSeek: deepseek.com/privacy
We don’t add any additional data to your requests beyond what’s necessary for authentication and routing. The providers don’t receive your account information, billing details, or other metadata beyond the API request itself.
We use Google Analytics to understand how people use our website—what pages they visit, how they navigate, where traffic comes from. Google Analytics collects standard web analytics data (browser type, pages visited, time on site) through cookies. This data is anonymized and aggregated. Google’s use of this data is governed by their privacy policy at policies.google.com/privacy.
If you want to opt out of Google Analytics tracking, you can use browser extensions like Google Analytics Opt-out or configure your browser to block tracking cookies.
Our service runs on servers provided by Amazon Web Services (AWS) and Linode. These providers host our infrastructure but don’t have access to your data in any meaningful way—they’re just providing the computing resources. Both providers have robust security practices and compliance certifications.
We may disclose your information if required by law, court order, subpoena, or other valid legal process. We may also share information if we believe in good faith that disclosure is necessary to:
- Comply with legal obligations
- Protect our rights, property, or safety, or the rights, property, or safety of others
- Investigate fraud, security breaches, or violations of these terms
- Respond to emergency situations involving threats to personal safety
If we receive a legal request for user data, we’ll review it carefully and will only provide the minimum information necessary to comply. When legally permitted, we’ll notify affected users before disclosing their information.
If www.beginswithai.com is acquired, merged, or undergoes a similar business transaction, your information may be transferred to the new entity as part of that transaction. We would notify affected users and provide options where possible, but such transfers are sometimes necessary for business continuity.
Beyond what’s listed above, we don’t share your data with anyone. We don’t sell it, we don’t provide it to advertisers, we don’t use it for cross-promotional purposes, and we don’t participate in data broker networks.
Your Rights & Security
You have control over your data and how we use it. Here’s what you can do, what protections we have in place, and what you should know about data security.
Access Your Data: You can view your account information, subscription details, and API usage history through your dashboard at any time. If you need additional information about what data we hold, contact us at [email protected] and we’ll provide it.
Delete Your Data: Canceling your subscription triggers immediate deletion of all your data as described in Section 3. If you want to delete your account before your billing period ends, contact us at [email protected] and we’ll process the deletion immediately. Keep in mind that this is irreversible—once deleted, your data can’t be recovered.
Opt Out of Marketing: If you’ve subscribed to our newsletter, every email includes an unsubscribe link. Click it and you’ll be removed immediately. This doesn’t affect transactional emails (payment confirmations, failed payment notices) which are necessary to operate your account.
Correct Your Information: You can update your email address and other account details through your dashboard. If you need to correct billing information or have questions about your account data, contact us at [email protected].
Export Your Data: While we don’t currently offer automated data export, you can retrieve your API responses during your retention period by using the API itself. If you need help exporting data before cancellation, contact us and we’ll assist.
If you’re located in the European Union, you have additional rights under GDPR:
- Right to portability: Request your data in a structured, machine-readable format
- Right to object: Object to certain types of data processing
- Right to restrict processing: Request that we limit how we process your data in specific circumstances
- Right to lodge a complaint: File a complaint with your local data protection authority if you believe we’ve mishandled your data
To exercise any of these rights, contact us at [email protected] with details about your request.
We take reasonable measures to protect your data from unauthorized access, loss, or misuse:
- All data transmissions use TLS encryption (HTTPS)
- API keys and passwords are cryptographically hashed
- Access to our systems is restricted to authorized personnel only
- We use industry-standard security practices for our infrastructure (AWS and Linode both maintain extensive security certifications)
- We monitor for suspicious activity and unusual usage patterns
But here’s the reality: No system is perfectly secure. We can’t guarantee that unauthorized access will never occur, that data breaches are impossible, or that our security measures will prevent every attack. We implement strong protections and respond quickly to security issues, but absolute security doesn’t exist.
You’re responsible for protecting your account credentials and API keys. Don’t share them, don’t commit them to public repositories, and don’t embed them in client-side code where they’re visible. If you believe your credentials have been compromised, change them immediately through your dashboard or contact us at [email protected].
We use two types of cookies:
Authentication cookies keep you logged in when you visit your dashboard. These are essential for the service to work—you can’t disable them without breaking core functionality.
Analytics cookies from Google Analytics track how you use our website (pages visited, time on site, navigation patterns). These aren’t strictly necessary. You can block them by:
- Using browser settings to block third-party cookies
- Installing browser extensions like Google Analytics Opt-out or Privacy Badger
- Using privacy-focused browsers that block tracking by default
Blocking analytics cookies won’t affect your ability to use the service.
Our servers are located in the United States (AWS and Linode facilities). If you’re accessing the service from outside the US—including from the European Union—your data will be transferred to and processed in the United States.
The US doesn’t have the same data protection regulations as the EU. While we implement strong security measures and comply with our obligations under this Privacy Policy, the legal framework governing data protection in the US is different from GDPR.
By using our service, you consent to this transfer. If you’re uncomfortable with your data being processed in the US, you shouldn’t use the service.
Updates & Contact
We may update this Privacy Policy from time to time to reflect changes in our practices, new features, legal requirements, or other operational needs. When we make changes, we’ll update the “Last Updated” date at the top of this page.
For significant changes that materially affect how we collect, use, or share your data, we’ll notify you by:
- Sending an email to the address associated with your account
- Posting a notice on www.beginswithai.com
- Displaying a notification in your dashboard
We’ll provide this notice at least 7 days before the changes take effect, giving you time to review them. If you don’t agree with the updated Privacy Policy, you can cancel your subscription before the changes take effect.
Your continued use of the service after changes become effective means you accept the updated Privacy Policy. If you cancel because you disagree with changes, standard cancellation terms apply—you retain access until the end of your billing period, and all data is deleted at that time.
For minor changes—like clarifying existing language, fixing typos, or updating links—we may not send individual notifications. We’ll still update the “Last Updated” date, and you can check back periodically to see if anything has changed.
If you have questions about this Privacy Policy, want to exercise your data rights, or need help with privacy-related issues, contact us at:
- Email: [email protected]
- Website: www.beginswithai.com
We’ll respond to privacy inquiries within 7 business days. For EU users exercising GDPR rights, we’ll respond within 30 days as required by law.
If you’re not satisfied with our response to a privacy concern, EU users have the right to lodge a complaint with their local data protection authority.