Privacy Policy

Version of 27 July 2026

This policy describes what data Wicket AI collects, why, how long it is kept and who it is shared with. We aim to collect the minimum: only what is needed to authenticate a request and charge it correctly.

1. What data is collected

DataSourcePurpose
Numeric Telegram account idTelegram, on first contact with the botBinding keys and balance to an owner
API key name, prefix, hash and creation dateKey creation in the botAuthenticating requests
Model, request and response token counts, cost, timestampEach served requestBilling and usage statistics
Balance and operations ledger (top-ups, charges, adjustments)Movements of fundsAccounting and correctness checks
Technical logs (timestamp, status code, errors)Gateway operationDiagnosing failures, abuse protection

We do not ask for your name, address, phone number or payment details. The website uses no advertising trackers or third-party analytics.

2. Request and response content

Prompt and response text is not stored by the Service. The gateway forwards your request to the model provider and returns the response; only counters reach the database — model, token counts and cost. The content itself is not written to the database.

One exception is technical diagnostics: on failure, a log line may contain the status code, endpoint path and the provider’s error message. We do not deliberately log your message text; if a fragment does end up inside a provider error, it is removed with the log when its retention period expires.

Note that the model provider handling a request does receive its content and applies its own retention policy. Do not send data through the Service that you are not willing to disclose to a third party.

3. How API keys are stored

A key is stored only as an irreversible hash plus a short prefix for display. The plaintext value is not in the database.

4. Why this data is needed

We do not sell data, share it for advertising, or build profiles for targeting.

5. Sharing with third parties

No other sharing takes place, except where required by law.

6. Retention periods

DataRetention
Account id, key hashes, balanceWhile the account is active
Token usage records and the operations ledgerWhile the account is active — required to reconcile the balance
Technical logsUp to 30 days
Request and response contentNot stored

Deleting an account removes its keys, balance and ledger. Some records may be kept longer where necessary to resolve a billing dispute or where required by law.

7. Data protection

No protection is absolute. If an incident affects your data we will report it through the bot and describe what happened.

8. Your rights

Send requests through the Telegram bot. Response time is up to 30 days.

9. Age restriction

The Service is intended for people aged 18 and over. We do not knowingly collect data from minors; such an account is deleted when discovered.

10. Changes to this policy

This policy may be updated. The version date is shown at the top of the page. Changes that widen the data collected or the recipients are announced through the bot before taking effect.

11. Contact

Questions about data handling: use the Telegram bot. The rules for using the Service are in the Terms of Service.