Privacy policy.
This policy explains what Model.sale processes to provide accounts, prepaid API access, the optional Playground, payments and support. It also explains what we deliberately do not collect from API requests.
The short version
We process the minimum information needed to authenticate you, protect the service, meter usage, settle your wallet and answer support requests. API prompts, source code and model responses are not stored by default. Playground conversations are saved only when you explicitly enable encrypted history.
You control API keys, optional analytics and Playground history from the product. Contact support@model.sale for privacy requests; report suspected credential exposure to security@model.sale.
1. Information we process
| Category | Examples | Why it is needed |
|---|---|---|
| Account and identity | Email, display name, password digest, Google/Telegram identity IDs and verification state | Sign-in, account recovery, identity linking and security notifications |
| Access credentials | API-key prefix, keyed digest, creation/revocation time, limits and last-used time | Authenticate requests, enforce limits and let you manage keys without storing the secret |
| Wallet and payments | Balance, reservations, immutable ledger entries, invoice ID, asset/network, amount, status and provider payload hash | Credit deposits, calculate charges, prevent duplicate credits and reconcile payment state |
| Operational metadata | Request ID, model, endpoint, status, token counts, latency, error class, origin and timestamps | Billing, reliability, abuse prevention, troubleshooting and aggregate reporting |
| Support | Email address, subject, message and ticket status | Respond to your request and keep a reliable support history |
We do not ask for a prompt or response to diagnose a billing or transport issue. A request ID and timestamp are normally enough.
2. API requests and model content
Model.sale acts as an API gateway. The gateway needs request headers and the request body briefly in memory to forward the call, but prompts, source code, files and response bodies are not written to our database, request logs, analytics or error tracking by default.
We retain safe metadata such as model ID, protocol, status, token usage, charge, latency and disconnect state. Authorization headers are redacted before logging. We do not use API content for advertising or train a Model.sale model.
Processing follows the selected model route and its applicable service terms. Do not send regulated, confidential or sensitive personal data unless you have assessed that the selected service is appropriate for it.
3. Optional Playground history
The Playground is different from API traffic. You choose whether to save conversations. When enabled, titles and messages are encrypted with AES-256-GCM before storage; plaintext operational records contain only IDs, model, timestamps, status and billing request ID.
- Default retention is 30 days; available choices are 7, 30 or 90 days, or until you delete the history.
- You can delete one thread or all saved history from the dashboard.
- Playground content is not sent to analytics, traces, Sentry, Telegram alerts or Prometheus labels.
- When you choose “Do not save”, the conversation is used for the live response and then discarded by the application path.
4. Product analytics and cookies
We use first-party analytics to understand page views, setup clicks and the signup-to-first-request funnel. The browser identifier is random and stored only as a one-way hash. Events may include pathname, a short allowlisted action ID, referrer host, UTM campaign tags, language and broad device class.
We do not collect query strings, form values, email addresses, API keys, prompts, responses or DOM text. Server-generated events such as a paid deposit and first successful request are not trusted to the browser. Staff, probes and smoke tests are marked internal and excluded from product conversion metrics.
To opt out in this browser, set ms_analytics_opt_out=1. Essential session and security cookies remain active because the service cannot sign you in or protect a request without them.
5. Payments and service providers
Crypto payment providers receive the invoice details required to create and verify a payment, such as amount, asset, network and invoice reference. We store a normalized event and a hash of the provider payload, not provider secrets. A payment is credited only after status verification and idempotent ledger processing.
We use infrastructure and operational vendors for hosting, DNS/CDN/WAF, email delivery, payment processing, error reporting and telemetry. They receive only the data needed for their function and are not authorized to use Model.sale request content for unrelated advertising. Current operational contacts are listed on the support page.
6. Retention
| Data | Current retention approach |
|---|---|
| Request and usage metadata | Up to 90 days for billing and operational review, then removed or aggregated. |
| Analytics aggregates | Retained longer to measure product performance; raw event detail follows the configured retention schedule. |
| Playground history | Your selected 7/30/90-day period or until manual deletion. |
| Wallet, ledger and payment records | Retained as needed for accounting, fraud prevention, dispute handling and legal obligations. |
| Support tickets | Retained while needed to resolve the issue and maintain service records, subject to deletion/legal requirements. |
Aggregated reliability statistics may remain after detailed records are deleted, but they are not intended to identify an individual user.
7. Security
Passwords are stored as one-way password hashes. API secrets are shown once; subsequent authentication uses a keyed digest with server-side pepper. Sessions use protected cookies, administrative actions are audited and sensitive credentials are redacted from logs.
No security control is perfect. Revoke an exposed API key immediately, rotate a compromised password and email security@model.sale with the request ID if one is available. Never include the secret, prompt or response in that email.
8. Your choices and rights
Depending on your location, you may request access to, correction of or deletion of personal information, object to optional analytics, or ask us to explain a processing decision. Some records cannot be deleted immediately when they are needed to settle a payment, prevent abuse, resolve a dispute or meet a legal obligation.
- Delete API keys and Playground history in the dashboard.
- Opt out of non-essential analytics with the browser opt-out flag.
- Request account closure or a copy of account data via support@model.sale.
- Include the account email and a description of the request, but never send passwords or API secrets.
9. Updates and contact
We may update this policy when the product, vendors or legal requirements change. The “updated” date at the top identifies the current version. Material changes will be highlighted in the product or account email where appropriate.
Questions about privacy, account data or deletion: support@model.sale. Security incidents: security@model.sale. Legal notices: legal@model.sale.