Privacy Policy
Last Updated: June 20, 2026
1. Introduction
At Native1API, we respect your privacy and are committed to protecting it. This Privacy Policy describes the types of information we may collect from you or that you may provide when you visit the Native1API.com website and use our AI API supply and model routing services, and our practices for collecting, using, maintaining, protecting, and disclosing that information.
2. Zero-Retention Inference Policy
Strict Pass-Through Processing: Native1API is designed as a secure, stateless arbitrage router. Your prompts, contexts, system messages, and the resulting AI outputs are processed live at the edge or routed securely to the selected upstream model providers.
- We enforce zero data retention for inference payloads. No prompt or output data is logged or stored on our servers.
- We never train models on your queries, request content, or generated completions.
- Your requests are fully processed inside temporary V8 isolates and cleared immediately upon execution.
3. Key Vault Security & Encryption
To allow secure, serverless credentials routing, our Bring Your Own Key (BYOK) database provides edge storage of provider credentials.
- All vault keys are encrypted at rest using industry-standard **AES-2CM** cryptography.
- Encryption keys are derived dynamically at request execution using **PBKDF2** key derivation, meaning they are never stored in plaintext.
- Keys are decrypted exclusively in the transient memory space of active V8 isolates to process requests, and they are destroyed as soon as the response is dispatched.
4. Information We Collect
We collect only the minimum required information to provide, maintain, and secure our services:
- Account Information: When you register, we collect your email address and credentials using Google Firebase Authentication.
- Usage Analytics: To calculate billing details and enforce rate limits, we track metadata such as request timestamps, token usage counts, and model identifiers.
- Stripe Transactions: Financial data is processed directly by Stripe. Native1API does not store raw credit card numbers or bank credentials.
5. Data Sharing and Transfer
We do not sell, rent, or trade your personal information. We share data only with the following sub-processors to the extent necessary to deliver the service:
- Cloudflare: For edge routing, serverless execution, and network security.
- Google Firebase: For user authentication management.
- Stripe: For secure billing and subscription transactions.
- Upstream Inference Providers: For processing prompts (only when you explicitly request a model provided by that respective vendor).
6. GDPR and CCPA Compliance
Under regional laws including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), you have the right to access, rectify, or request the deletion of your account and credentials. To exercise these rights, you can revoke your keys in the developer console or contact us at our privacy inbox below.
7. Contact Information
For inquiries regarding this privacy policy or to submit data requests, contact us at: privacy@native1api.com
