Privacy
Privacy Policy
This Privacy Policy uses direct language to explain what we collect, why we use it, how long we keep it, who receives it, and what choices you have.
Effective date: July 5, 2026
This page is provided in Chinese and English. If the two versions differ in meaning, interpretation, ambiguity, or translation accuracy, the Chinese version prevails.
1. Quick Summary
We process account, billing, usage, request metadata, and other information needed to run the Service.
In general, except for operations, security, anti-abuse, billing, troubleshooting, dispute handling, legal compliance, or history, logging, saved prompt, or similar features you enable, we generally do not persistently store requests sent to AI models and responses returned by AI models, including API request bodies, prompts, inputs, and outputs.
We do not sell API request content or personal information.
Upstream model providers may handle request content under their own rules.
2. What This Policy Covers
This Privacy Policy applies to personal information processing in connection with your access to or use of the I Code Easy website, dashboard, APIs, documentation, billing, support, model routing, AI tools, and related digital services.
Where applicable data protection law applies, I Code Easy acts as data controller or a similar role for personal information relating to the Service. For data you submit on behalf of customers, teams, or end users, you may also act as an independent controller or processor with corresponding obligations.
“Personal information” means information that identifies or can reasonably be linked to an individual. “Processing” includes collecting, recording, organizing, storing, using, transmitting, disclosing, deleting, or otherwise handling personal information.
3. What Information We Collect
We may collect account information, including email address, nickname, login state, account identifiers, organization membership, roles, permissions, invitation state, API key metadata, support messages, and ticket records.
We may process transaction and billing information, including order ID, payment status, balance, credits, usage, invoices, tax information, refund records, dispute records, limited payment information returned by payment processors, and risk results.
We may collect technical and usage information, including IP address, user agent, device and browser information, access time, referring pages, session state, model name, endpoint selection, token counts, error codes, latency, request metadata, security logs, and risk signals.
If you use third-party login, team, organization, documentation, dashboard, shared link, saved prompt, history, debugging, or similar features, we may process preferences, integration source, access records, sharing state, and activity records related to those features.
4. How API Requests, Prompts, and Outputs Are Handled
To provide API gateway, model routing, usage calculation, abuse prevention, security review, troubleshooting, and support, we process API requests, prompts, inputs, reference files, outputs, errors, and request metadata submitted by you and your end users through the Service.
Different Upstream Providers may process, retain, log, moderate, or train on inputs and outputs under their own Model Terms, privacy policies, and data handling rules. We use reasonable efforts to select appropriate routes and reduce unnecessary data transfer, but once a request is sent to an Upstream Provider, it is affected by that provider's data handling rules.
Except where necessary for operations, billing, security, anti-abuse, troubleshooting, customer support, dispute handling, legal compliance, or features you enable such as history, logging, saved prompts, shared links, team collaboration, or debugging, we generally do not persistently store requests sent to AI models and responses returned by AI models, including API request bodies, prompts, inputs, and outputs.
We do not sell API request content or personal information, and we do not use requests sent to AI models and responses returned by AI models to sell personal information; when a necessary scenario requires short-term retention or review of such content, we handle it under a minimum-necessary approach.
5. Cookies, Local Storage, and Analytics
Our website and dashboard may use cookies, localStorage, sessionStorage, pixel tags, logs, device identifiers, or similar technologies to maintain login state, interface language, session information, security state, necessary preferences, and risk state.
We may use analytics, performance monitoring, error reporting, email delivery, transaction event tracking, anti-fraud, session diagnostic, or similar tools to understand product use, detect anomalies, improve experience, protect the Service, and verify system integrity.
You may restrict some cookies or local storage through browser settings, but disabling necessary technologies may cause login, payment, dashboard, API key management, security verification, or preference functions to stop working properly.
6. Payments and Third-Party Payment Providers
Payments may be processed by Creem or another authorized payment service provider. Payment providers may receive information needed to process payments, taxes, receipts, anti-fraud checks, refunds, disputes, chargebacks, and customer portal access.
We generally do not receive full card numbers or full payment credentials. Whether payment providers collect, retain, or disclose payment information is governed by their own terms and privacy policies.
For accounting, tax, audit, dispute, refund, compliance, and anti-fraud purposes, we may retain orders, invoices, payment status, refund status, and limited transaction metadata.
7. Sensitive Information, Minors, and Authorization
Please do not submit unnecessary highly sensitive information to the Service, including government identity documents, health records, financial account details, precise location, private credentials, non-public trade secrets, sensitive information about minors, or data you are not authorized to process.
The Service is not directed to minors for direct use. If you believe personal information about a minor has been improperly submitted to I Code Easy, contact support@icodeeasy.cc so we can assess deletion, restriction, or other necessary measures.
If you submit personal information on behalf of customers, teams, organizations, or end users, you are responsible for providing any required Personal Information Collection Statement, obtaining required consent or other lawful basis, and ensuring your application, product, and data workflows comply with applicable law.
8. Why We Use This Information
We process personal information to create and manage accounts, authenticate users, deliver digital services, route API requests, calculate usage and balance, process payments and refunds, provide documentation and support, send service notices, maintain security, and prevent abuse.
We may also use personal information to troubleshoot failures, improve reliability, plan capacity, enforce terms and policies, investigate fraud, disputes, security incidents, or rights violations, comply with legal obligations, and protect users, the public, Upstream Providers, payment channels, and the Service.
We may aggregate or de-identify operational data so it no longer identifies a specific individual, then use it for statistical analysis, service improvement, product planning, risk assessment, and public or internal metrics.
9. Who We Share Information With
We may provide necessary personal information to upstream AI services, payment processors, cloud infrastructure, storage services, email services, support tools, risk services, logging and monitoring tools, analytics tools, professional advisers, and other service providers to provide, maintain, bill, protect, troubleshoot, and improve the Service.
If you are part of a team or organization account, organization admins may access or manage members, billing, usage, API keys, model permissions, logs, tickets, and service data related to that organization.
We may disclose necessary information when lawfully responding to courts, regulators, law enforcement, payment networks, Upstream Providers, or third-party rights holders, enforcing terms, investigating fraud, abuse, security incidents, or rights violations, or protecting users, the public, the Service, and third parties.
If we are involved in a merger, restructuring, financing, asset sale, business transfer, bankruptcy, liquidation, or similar transaction, relevant information may be disclosed or transferred as part of the transaction or diligence process, subject to applicable confidentiality and privacy obligations.
10. Retention, Deletion, and Account Closure
Account, billing, order, invoice, tax, payment status, dispute, security audit, anti-abuse, and support records are retained for as long as reasonably necessary for the purposes described in this Policy.
Requests sent to AI models and responses returned by AI models, including API request bodies, prompts, inputs, and outputs, are not kept as long-term records by default; they are retained only as necessary for storage features, support troubleshooting, operations, security, billing, disputes, anti-abuse, legal compliance, or backup recovery.
Request metadata, security logs, error patterns, risk signals, and usage records may be retained as operational, billing, capacity planning, troubleshooting, and security records.
You may close certain features, rotate API keys, or request account deletion through the dashboard. Account deletion requests may require email confirmation, account ownership verification, and resolution of pending orders, disputes, or security matters.
Even after account closure or deletion, we may retain necessary records for legal, tax, payment, audit, dispute, security, anti-abuse, backup, or legitimate business needs.
11. Data Security
We use reasonable technical and organizational measures designed to protect accounts, credentials, billing records, logs, and related personal information, including access controls, key management, log monitoring, risk detection, and necessary operational security measures.
No system, network, or transmission method can be guaranteed to be fully secure. You must protect your account and API keys and must not send passwords, private keys, API keys, or highly sensitive information through public channels.
If an incident may affect personal information security, we will take measures based on the nature and scope of the incident, legal requirements, and actual circumstances, which may include investigation, containment, remediation, regulator notification, or notice to affected users.
12. Your Rights and Choices
You can update some account information, manage API keys, and review balance and usage in the dashboard, and you may contact support@icodeeasy.cc to request access, correction, deletion, export, restriction of processing, objection to processing, withdrawal of consent, marketing unsubscribe, or answers about personal information processing.
Depending on applicable law in your location, you may have rights to obtain a copy of personal information, data portability, restriction or objection, deletion, correction of inaccurate information, or submission through an authorized agent.
To protect account security, we may require account ownership or identity verification. Where permitted by law, we may decline requests that cannot be verified, are excessive or repetitive, affect the rights of others, harm security, or conflict with legal obligations.
13. Cross-Border Transfers
Because upstream models, cloud infrastructure, payment, email, monitoring, support, and customer service tools may be located in different countries or regions, your personal information may be accessed, processed, stored, or transferred outside your location.
We take reasonable measures to protect personal information in cross-border processing based on applicable law and service needs, but data protection laws in other regions may differ from those in your location.
14. Automated Decisions and Marketing
We may use automated or semi-automated systems for risk control, anti-abuse, content moderation, abnormal usage detection, payment risk assessment, route selection, capacity planning, and security protection.
Unless expressly stated otherwise, the Service does not make decisions about you based solely on automated processing that produce legal or similarly significant effects. Decisions involving restrictions, suspension, refund denial, or account action may be submitted for review through support channels.
If we send marketing or promotional messages, you may opt out through unsubscribe instructions in the message or by contacting support@icodeeasy.cc. Service notices, security notices, billing notices, and transaction messages are not affected by marketing opt-out.
15. Policy Updates
We may update this Privacy Policy due to product, technical, upstream, legal, compliance, security, or operational changes. Material changes may be announced through the website, dashboard, account email, or another reasonable method.
The updated Policy applies from the effective date shown on the page. Continued use of the Service after that date means you understand the updated Policy.
16. Contact
For privacy, data rights, security incidents, or personal information processing questions, contact support@icodeeasy.cc or submit a dashboard ticket.