Privacy Policy

Last updated:

This policy explains what data xbapi ("we") collects when you use our website, console, and API, how we use it, who we share it with, and what choices you have.

1. Data we collect

  • Account data. When you sign in with Google we receive your email address, name, and Google account identifier. We never see your Google password.
  • Sign-in sessions. A session identifier, its creation and expiry time, and your browser's user agent string.
  • API keys. We store a hash of each key and its first few characters for display. The full key is shown once when you create it and cannot be recovered afterwards.
  • Task data. The parameters you submit (prompts, image URLs, and other model inputs), the callback URL if you set one, task status, error messages, and the generated result files.
  • Billing records. Your credit balance and every recharge, charge, and refund, with amount and time.
  • Technical logs. Request metadata such as IP address, time, and error details, recorded by our hosting provider.

2. How we use data

  • To sign you in and keep you signed in.
  • To authenticate API requests and run the tasks you submit.
  • To hold, settle, and refund credits, and to show you your usage history.
  • To deliver callbacks to the URL you provide.
  • To investigate failures, prevent abuse, and keep the service secure.
  • To contact you about your account, billing, or changes to these policies.

We do not sell your data, and we do not use your task inputs or results to train models.

3. Who we share data with

We share data only with the providers we need to run the service:

  • Google, for sign-in.
  • Cloudflare, which hosts our application, database, file storage, and logs.
  • Model providers. Your task inputs are sent to the upstream provider that runs the model you select. They receive what is needed to generate the result, not your account details. Each provider processes inputs under its own terms.

We may also disclose data when required by law or to protect the rights and safety of our users and the service.

4. How long we keep data

  • Result files are deleted 30 days after the task is created. Copy anything you need to keep to your own storage before then.
  • Sign-in sessions expire after 30 days, or earlier when you sign out.
  • Account, API key, task, and billing records are kept while your account is active. When you ask us to delete your account we delete them, except billing records we must keep for legal or accounting reasons.
  • Hosting logs are kept for the period set by our hosting provider.

5. Cookies

We use only the cookies needed for the site to work. We do not use advertising or cross-site tracking cookies.

  • A session cookie (HttpOnly, 30 days) that keeps you signed in to the console.
  • A short-lived state cookie that protects the Google sign-in flow.
  • Language and theme preference cookies (1 year).

6. Your choices and rights

You can view your tasks, API keys, and transactions in the console, and revoke any API key at any time.

To get a copy of your data, correct it, or delete your account, email support@xbaiapi.com. We reply within 30 days. Depending on where you live, local law may give you further rights, such as objecting to certain processing or lodging a complaint with a data protection authority.

7. Security

All traffic is served over HTTPS. API keys are stored only as hashes, and session cookies are HttpOnly and Secure. No system is perfectly secure: keep your API keys private, and revoke a key immediately if you think it has leaked.

8. International transfers

Our providers operate infrastructure in many countries, so your data may be processed outside the country where you live.

9. Children

The service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has given us data, contact us and we will delete it.

10. Changes to this policy

When we change this policy we update the date at the top. For material changes we will notify you by email or in the console before they take effect.

11. Contact

Questions about this policy or your data: support@xbaiapi.com.