API Privacy Policy
Effective 2026-09-29
How the UltraGPT API handles your data. The UltraGPT Privacy Policy covers the rest of your account.
1. What we store
For each API request we store metadata: the time, model, key, token counts, cost, latency, finish reason, and the app name and URL you send in X-Title / HTTP-Referer. This powers your activity, usage and billing views.
We do not store the content of chat completion, messages, embeddings, image or audio requests beyond the time needed to process them.
Exceptions you control: /v1/responses stores the conversation (encrypted) for 30 days when store is true (the default) so previous_response_id works — send store: false to opt out; Batch API input and output files are kept until you delete them.
2. Model providers
Your requests are sent to the provider serving the model you choose, which processes them under its own terms. Use provider routing (provider.data_collection: "deny", zdr: true) to restrict requests to providers that do not retain or train on data.
3. Secrets
API keys are stored only as hashes and shown once. Webhook secrets and your own provider keys (BYOK) are encrypted at rest.
4. Retention and deletion
Request metadata is kept for as long as your account exists, for billing and abuse prevention. Contact support@ultragpt.pro to request deletion of your account data.
Questions? Write to support@ultragpt.pro.