Privacy Policy
Version of 27 July 2026
This policy describes what data Wicket AI collects, why, how long it is kept and who it is shared with. We aim to collect the minimum: only what is needed to authenticate a request and charge it correctly.
1. What data is collected
| Data | Source | Purpose |
|---|---|---|
| Numeric Telegram account id | Telegram, on first contact with the bot | Binding keys and balance to an owner |
| API key name, prefix, hash and creation date | Key creation in the bot | Authenticating requests |
| Model, request and response token counts, cost, timestamp | Each served request | Billing and usage statistics |
| Balance and operations ledger (top-ups, charges, adjustments) | Movements of funds | Accounting and correctness checks |
| Technical logs (timestamp, status code, errors) | Gateway operation | Diagnosing failures, abuse protection |
We do not ask for your name, address, phone number or payment details. The website uses no advertising trackers or third-party analytics.
2. Request and response content
Prompt and response text is not stored by the Service. The gateway forwards your request to the model provider and returns the response; only counters reach the database — model, token counts and cost. The content itself is not written to the database.
One exception is technical diagnostics: on failure, a log line may contain the status code, endpoint path and the provider’s error message. We do not deliberately log your message text; if a fragment does end up inside a provider error, it is removed with the log when its retention period expires.
Note that the model provider handling a request does receive its content and applies its own retention policy. Do not send data through the Service that you are not willing to disclose to a third party.
3. How API keys are stored
A key is stored only as an irreversible hash plus a short prefix for display. The plaintext value is not in the database.
- A key can be displayed only once, at creation.
- Recovering a lost key is technically impossible: create a new one.
- Service staff cannot see your key.
- Deleting a key in the bot revokes access immediately.
4. Why this data is needed
- Performance of the contract — providing API access, billing and balance accounting. Without an account id and a key hash the Service cannot tell your request from someone else’s.
- Legitimate interests — abuse protection, failure diagnosis, verifying that charges are correct.
- Legal obligations — where responding to a lawful request from a competent authority is mandatory.
We do not sell data, share it for advertising, or build profiles for targeting.
5. Sharing with third parties
- Model providers — receive the request content needed to generate a response. Your Telegram account id is not passed to them.
- Telegram — the channel used to talk to the bot; Telegram’s own policy applies to that conversation.
- Hosting provider — operates the server the Service runs on.
No other sharing takes place, except where required by law.
6. Retention periods
| Data | Retention |
|---|---|
| Account id, key hashes, balance | While the account is active |
| Token usage records and the operations ledger | While the account is active — required to reconcile the balance |
| Technical logs | Up to 30 days |
| Request and response content | Not stored |
Deleting an account removes its keys, balance and ledger. Some records may be kept longer where necessary to resolve a billing dispute or where required by law.
7. Data protection
- Traffic to the API and the website is HTTPS only.
- Keys are stored as hashes; provider credentials are kept outside the code repository.
- Server access is limited to the Service administrator.
- The database is backed up so that a failure cannot lose your balance.
No protection is absolute. If an incident affects your data we will report it through the bot and describe what happened.
8. Your rights
- Access — view your keys, balance, usage and ledger in the bot at any time.
- Deletion — delete any key yourself; account deletion and removal of associated data on request.
- Rectification — report an incorrect charge; if confirmed, the balance is adjusted.
- Objection — stop using the Service at any time.
Send requests through the Telegram bot. Response time is up to 30 days.
9. Age restriction
The Service is intended for people aged 18 and over. We do not knowingly collect data from minors; such an account is deleted when discovered.
10. Changes to this policy
This policy may be updated. The version date is shown at the top of the page. Changes that widen the data collected or the recipients are announced through the bot before taking effect.
11. Contact
Questions about data handling: use the Telegram bot. The rules for using the Service are in the Terms of Service.