Privacy Policy

Effective date: August 20, 2026

This Privacy Policy explains how Havenbyte LLC ("Havenbyte", "Modelflare", "we", "us", or "our") collects, uses, discloses, and protects information when you access or use Modelflare websites, accounts, dashboards, APIs, documentation, payment flows, support channels, and related services.

This policy is written in English. If we provide a translation, the translation is for convenience only, and the English version controls to the extent of any conflict.

1. Information We Collect

We collect information that you provide directly, including account information, login identifiers, contact information, API key names, organization or project information, support tickets, ticket messages and attachments, other messages you send to us, and payment or billing information handled through supported payment providers.

When you choose a content-bearing persistent feature, we store the content needed to provide it. For example, Image Workbench stores conversation text and asset metadata in the application database and generated images in private object storage until you delete the conversation or another disclosed retention rule applies.

If you choose to subscribe to marketing emails, we record your category preferences, language, the source and time of each consent or withdrawal, and the applicable consent policy version. We also maintain suppression records needed to honor unsubscribes and prevent delivery after a complaint or hard bounce. Existing users and users who do not affirmatively opt in remain unsubscribed.

When you visit or register, we may record attribution information such as UTM parameters, referral host, landing context, and an X click identifier (twclid) or Google Ads click identifier (gclid) when present. We also record the browser privacy signals needed to respect applicable Do Not Track (DNT) or Global Privacy Control (GPC) choices for X and Google Ads measurement.

When you use the API, dashboard, documentation, network tests, or related services, we collect operational metadata such as account ID, API key ID, model name, group, routing and channel diagnostic information, request ID, provider request ID when available, token counts, fees, status code, timing information, timestamps, network route, error information, IP address, user agent, authentication events, payment status, and similar logs needed to operate the service.

Inputs and outputs sent through the API are processed to provide the service and may be transmitted to the model or infrastructure provider selected for the request. In the ordinary API relay path, we do not store request or response bodies as long-term business records in the application database. We do not use customer content to train, fine-tune, distill, benchmark, or improve AI or machine-learning models developed or operated by Havenbyte. A selected model provider's retention and training practices are governed by that provider's applicable terms and may vary by provider, product, account type, and region.

The Images API is a limited exception when you request response_format=url: the validated generated image is stored in private object storage and made available through a signed link that expires after one hour by default. The backing object may remain private after the link expires until the configured short-lived storage lifecycle deletes it. When you request response_format=b64_json, this feature returns the validated image inline and does not persist an API output object.

Short-lived request-debug records contain diagnostic metadata and parameter summaries, not complete request or response bodies, and are designed to expire after 72 hours. Request Archive is a separate body-diagnostic feature that is disabled by default. If specifically enabled, it may store scoped original and service provider request bodies on protected local storage; its current default expiry is 168 hours. These diagnostic capabilities are used only for authorized troubleshooting, security investigations, abuse detection, billing disputes, reliability, or legal compliance and are subject to access and retention controls.

2. How We Use Information

We use information to provide, secure, maintain, and bill for Modelflare services; authenticate users; manage API keys and access groups; route API requests; calculate usage and fees; provide persistent product features; process payments and refunds; detect fraud, abuse, outages, and security issues; respond to support requests; comply with legal obligations; enforce our Terms of Service and Platform Usage Rules; and communicate service, billing, security, or policy updates.

We use limited product, page, account, and attribution information to understand service adoption, measure website and conversion performance, diagnose product issues, and improve the service. We do not send API prompts, API request or response bodies, passwords, secrets, or API keys to PostHog, X, or Google Ads for these purposes.

We send marketing emails only to registered users with a verified login email who have affirmatively subscribed to the relevant category. Marketing consent is optional, is separate from accepting our terms or using the service, and may be withdrawn at any time. Your marketing choices do not affect authentication, billing, security, support, or other transactional communications needed to provide the service.

We may use aggregated or de-identified information for operational reporting, capacity planning, reliability analysis, abuse prevention, pricing analysis, and product improvement, provided it does not identify a specific customer or user and is not used to re-identify anyone.

3. How We Share Information

We disclose information only as needed for the purposes described in this policy:

  • Model providers: The provider selected for an API route receives the inputs, necessary context and files, and other data needed to return the requested output.
  • Cloudflare and infrastructure providers: Cloudflare and applicable hosting providers process network traffic, request headers, IP addresses, and related data for edge delivery, security, DNS, DDoS protection, connectivity, hosting, and storage. Cloudflare R2 stores generated-image assets for enabled persistent features in private object storage. Cloudflare Turnstile may process verification data for enabled account flows.
  • Google reCAPTCHA Enterprise: When enabled for an account flow, Google processes verification tokens and related request, device, network, and risk context to assess bot, fraud, or registration risk.
  • PostHog: When analytics is enabled, PostHog receives allowlisted page, product, and account metadata. It does not receive API prompts, API request or response bodies, passwords, secrets, or API keys from our analytics implementation.
  • X: When X measurement is enabled and not suppressed by an applicable browser privacy signal, the website tag may process browser and network data. Server-side conversion events may include an X click identifier, an opaque conversion identifier, event time, and, for an eligible payment conversion, value and currency. We do not send API prompts, API request or response bodies, API keys, or payment credentials to X.
  • Google Ads: When Google Ads measurement is enabled and not suppressed by an applicable browser privacy signal, the Google tag may process browser and network data for website visit and conversion measurement. A browser conversion event may include an opaque conversion identifier. We do not send API prompts, API request or response bodies, API keys, or payment credentials to Google Ads.
  • Stripe and other supported payment providers: Payment providers process payment methods, billing details, transaction value and currency, risk signals, tax information, invoices, receipts, refunds, disputes, and related transaction information under their own policies. We do not store full payment card numbers.
  • Resend: Our email provider receives the recipient address, sender identity, subject and content, delivery headers, and delivery status needed to deliver and protect transactional or consented marketing email. It may return message identifiers and bounce or complaint signals.
  • OAuth and identity providers: A provider you choose for login receives the identity and authentication data needed to complete that login.
  • Advisors, transactions, and authorities: We may disclose information to professional advisors, in connection with a corporate transaction, or to authorities and other parties where required or permitted by law, while applying appropriate confidentiality and legal safeguards.

Third-party services process information under their own terms, privacy policies, data-processing rules, regional restrictions, and retention practices. When you choose a payment method, OAuth provider, model route, or integration, the relevant third party receives the information necessary to complete that service.

We do not sell personal information. We do not disclose customer API inputs or outputs for cross-context behavioral advertising or use them to build advertising profiles.

4. Payments

Payments are processed by supported payment providers such as Stripe. We do not store full payment card numbers. Payment providers may collect and process payment method details, billing details, risk signals, tax information, invoices, receipts, refunds, disputes, and related transaction information under their own policies.

5. Cookies, Analytics, and Similar Technologies

We may use cookies, local storage, website tags, and similar technologies for authentication, session management, security, preferences, language selection, attribution, analytics, conversion measurement, and product operation. Depending on the functions enabled, these technologies may be provided by Modelflare, PostHog, X, Google Ads, Cloudflare Turnstile, or Google reCAPTCHA Enterprise. Some features may not work correctly if required storage or scripts are disabled.

Our current implementation suppresses X and Google Ads browser-tag conversion measurement, and X server-side conversion measurement, when the browser presents a DNT or GPC signal. Browser controls, extensions, or network settings may also block analytics or measurement technologies.

This website measurement is separate from marketing-email tracking. Modelflare does not enable marketing-email open or click tracking by default, and the standard marketing-email flow does not intentionally add an email tracking pixel or rewrite links for behavioral tracking.

6. Retention

We retain information only for as long as reasonably necessary to provide the services, maintain accounts, calculate billing, satisfy accounting and legal obligations, resolve disputes, enforce agreements, detect abuse, protect security, and support operations.

  • Ordinary API request and response bodies are processed transiently and are not retained as standard long-term application database records.
  • Images API output requested with response_format=url is stored in private object storage under a short-lived lifecycle; its signed link expires after one hour by default. b64_json output is not persisted by this feature.
  • Short-lived request-debug metadata is designed to expire after 72 hours.
  • Request Archive is disabled by default; if authorized and enabled, its current default expiry is 168 hours unless a different period is configured or agreed.
  • Image Workbench conversations and generated-image assets are retained until you delete the conversation or another disclosed retention rule applies.
  • Support ticket messages and attachments are retained while the support matter is active and afterward as reasonably necessary for support, security, disputes, and legal obligations.
  • Account, usage, billing, attribution, product-analytics, security, and operational records are retained as reasonably necessary for their stated purposes and applicable legal obligations.
  • Consent and withdrawal records, together with unsubscribe, complaint, and hard-bounce suppressions, may be retained as reasonably necessary to demonstrate and honor your choices and prevent unwanted delivery.

Data retained in protected backups may remain until overwritten through the ordinary backup lifecycle but is placed beyond active use. Data processed by a selected model provider is subject to that provider's applicable retention terms and controls.

7. Security

We use reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. These measures include authenticated and role-based access, restricted privileged operations, encrypted transport, protection of supported sensitive credentials, and private access paths for stored image assets. No system is perfectly secure, and customers are responsible for protecting their own credentials, API keys, devices, networks, and downstream integrations.

8. International Transfers

Modelflare is operated by Havenbyte LLC and may process information in the United States and other countries where we or our service providers operate. Information may be transferred to and processed in countries that have different data-protection laws. Where applicable law requires a transfer mechanism, we will use an applicable legally recognized mechanism.

9. Your Choices and Requests

You may access and update certain account information in the dashboard, delete API keys, delete Image Workbench conversations, stop using the service, or contact us about account, billing, privacy, access, correction, return, or deletion requests through the official support channels published on our website.

You can manage individual marketing categories from your Profile or use the unsubscribe link included in every marketing email. The one-click unsubscribe option stops all marketing categories. You may later change eligible categories from your Profile, but complaint, hard-bounce, or administrator suppressions may continue to prevent delivery. Unsubscribing from marketing does not stop authentication, billing, security, support, or other transactional messages.

You may use browser DNT or GPC settings to suppress our current X and Google Ads browser-tag conversion measurement, and X server-side conversion measurement. You may also use browser controls to manage cookies, local storage, and scripts, although required service features may not work correctly if disabled.

We may need to verify your identity, account ownership, payment ownership, or authority before responding to certain requests. We may retain information where required or permitted for legal, security, accounting, fraud-prevention, dispute-resolution, or operational reasons. If we process personal information on behalf of an enterprise customer, requests concerning that customer's data may need to be directed to the customer.

10. Children's Privacy

The services are not intended for children or for use by anyone who is not legally allowed to use the services under applicable law. Customers that build products for minors are responsible for obtaining required consent and implementing appropriate safeguards.

11. Changes

We may update this Privacy Policy from time to time. Updated versions become effective when posted or on the date stated in the notice. Where required by law, we will provide additional notice or obtain consent. Continued use of the services after an update means you accept the updated policy to the extent permitted by law.

12. Contact

For privacy questions or requests, contact us through in-dashboard support or email us at support@modelflare.dev.

  • Modelflare – Stable, Lower-Cost GPT, Claude & Grok API Gateway

    Use GPT, Claude, Grok, and other leading models through one stable, lower-cost gateway. Track every request, token usage, and cost in one place.

  • Models & Pricing – Modelflare

    Compare current models, model groups, and prices against official API list prices, then review compatible API formats.

  • AI API Engineering Blog: Routing & Cost

    Engineering guides to OpenAI-compatible APIs, streaming, provider routing, fallback design, error diagnosis, API key security, token usage, and cost control.

  • About Modelflare – AI Model API Platform for Teams

    Learn how Modelflare supports developers, teams, and organizations with unified model access, flexible routing, usage and cost records, and enterprise assistance.

  • Trust & Security – Data Handling and Safeguards

    Learn how Modelflare handles API data, protects credentials, uses service-provider categories, and manages retention, diagnostics, and security incidents.

  • Documentation

    Setup guides, model contracts, and API reference.