Privacy
Privacy Policy
Last updated: July 19, 2026. This policy explains what Subaxis stores, what it does not store, and why some account records are required for the service to work.
1. Who We Are
Subaxis AI is operated by an EU-based company. Subaxis is an OpenAI-compatible API gateway and customer portal. The Service routes API requests to trusted first-party and carefully selected provider networks with strong privacy commitments, and gives users tools for API keys, model access, usage tracking, credits, and billing.
By signing up, logging in, creating an API key, topping up, or using the Service, you agree to this Privacy Policy and the Terms of Service.
2. What We Do Not Store or Sell
Subaxis does not store, save, sell, rent, or use for training your:
- prompts or chat messages;
- uploaded image content or file content sent to models;
- tool-call payloads or function arguments;
- model responses or generated outputs;
- application source code sent inside request content.
Request content is forwarded only to the trusted provider selected by Subaxis routing so the model can respond. Subaxis records metadata about the request, not the private content of the request.
3. Information We Store
We store the minimum operational records needed to run accounts, billing, abuse prevention, support, and API access:
- Account data: user ID, email address, display name, account status, authentication metadata, and timestamps.
- API-key data: key ID, masked key, key description, creation time, active/inactive status, allowed models, budgets, and limits. Full API keys may be stored server-side so authentication can work.
- Usage metadata: endpoint, selected model, timestamp, status code, token counts, cost, free-allowance usage, balance deductions, and error type. We do not store the request messages or responses behind those usage events.
- Billing data: balance, credits, top-ups, transaction history, checkout IDs, payment verification status, and limited payment-method metadata provided by payment processors for fraud prevention.
- Security and activity data: account actions, admin actions, API-key changes, billing actions, latest error metadata, IP or browser signals where needed for rate limiting, login protection, fraud prevention, and audit trails.
- Support communications: information you send us through Discord, email, or the contact page.
4. Why We Use This Information
We use stored metadata to:
- authenticate users and API keys;
- show balances, usage, billing history, and dashboard analytics;
- calculate costs, apply discounts, deduct usage, and credit top-ups;
- provide support and investigate issues such as failed payments or API errors;
- detect trial abuse, payment abuse, key abuse, platform abuse, and fraud;
- secure, debug, maintain, and improve reliability of the Service;
- comply with legal, tax, accounting, and payment obligations.
5. Trusted AI Providers
When you send an API request, Subaxis routes the request content only to trusted first-party model providers or carefully selected provider networks needed to process the request. We choose providers based on reliability, security posture, and privacy commitments, including providers that state they do not sell customer request data or use API request content to train models without permission.
Subaxis is built to keep users safe: we do not store your request content, we do not sell it, and we do not intentionally route requests through unknown or low-trust providers. Provider systems may still process request content transiently to generate the response and may apply their own security, abuse-prevention, or legal controls under their published terms.
For maximum safety, do not send secrets, regulated information, or third-party personal data unless you have the legal right and appropriate safeguards to do so.
6. Authentication and Payments
We use Clerk for authentication and Polar or other payment processors for checkout and payment operations. These providers receive the data needed to provide their services, such as login identifiers, customer references, checkout details, and payment metadata.
Subaxis does not store full card numbers or full payment credentials. Payment details are handled by the payment processor. We may store limited card metadata or processor references, such as brand, last four digits, expiry, customer ID, or payment-method signature, to prevent duplicate free-trial abuse and payment fraud.
7. Sharing
We do not sell personal data or request content. We share information only when needed to operate the Service:
- with authentication providers for login and account management;
- with payment processors for checkout, billing, refunds, and fraud checks;
- with trusted AI providers so API requests can be processed;
- with hosting, security, infrastructure, and analytics tools needed to run and protect the Service;
- with authorities or legal parties when required by law or to protect Subaxis, users, providers, or the public.
8. Optional Website Analytics
With your consent, we use Google Analytics and the Meta Pixel to understand aggregate site visits, pricing/model views, sign-up intent, and checkout starts. Analytics is off by default. We do not send prompts, API keys, email addresses, Discord IDs, payment details, balances, or model request content to these tools. You can decline analytics without losing access to the Service.
9. Retention
We keep operational metadata for as long as needed to provide the Service, resolve disputes, comply with legal and tax obligations, prevent abuse, and maintain account history.
- Account and API-key metadata is kept while your account exists and for a reasonable period afterward for security, audit, and support.
- Billing and transaction records may be kept longer where required for accounting, tax, refund, chargeback, and fraud-prevention reasons.
- Usage metadata and activity logs are kept to show your usage, support billing, debug errors, and protect the platform.
- Request content such as prompts, messages, images, tool payloads, and model responses is not stored by Subaxis as part of normal operation.
10. Your Choices and Rights
You can request access, correction, export, or deletion of account data by contacting us. We may need proof that you own the account. We may also need to retain certain records where required for legal, security, billing, tax, chargeback, or fraud-prevention reasons.
Deleting an account may disable API keys and access. Deletion does not erase records we are legally or operationally required to keep.
11. Security
We use reasonable safeguards to protect account, billing, API-key, usage, and activity records. No internet service is perfectly secure. You are responsible for protecting your account, devices, passwords, and API keys.
12. Children
Subaxis is not intended for children under 13. If you believe a child has used Subaxis in violation of this policy, contact us so we can review and take action.
13. Changes to This Policy
We may update this Privacy Policy. If we make material changes, we will update the date above and may notify users through the website, customer portal, Discord, or email. Continued use of Subaxis after changes means you accept the updated policy.
14. Contact
For privacy requests, data requests, account deletion requests, or legal notices, email legal@subaxis.dev. For billing, refunds, failed payments, or account support, email support@subaxis.dev. For abuse, NSFW or sexual-content misuse, fraud, security concerns, or policy violations, email safety@subaxis.dev. For general questions, email hello@subaxis.dev. Discord is also available for fast support at https://discord.gg/2C3cduC2Rm.
