Privacy Policy
This Privacy Policy explains what information cuberout collects, how it is used, how API traffic is handled, and how you can request access, correction, or deletion of your information.
1. Scope
This policy applies to cuberout, including the Telegram bot, API endpoints, payment callbacks, prepaid wallet, model catalog, and operational systems used to provide the service.
The cuberout Telegram bot is not operated by Telegram. Telegram provides the messaging platform and may process data under its own terms and privacy policy.
2. Information We Collect
We collect information needed to create accounts, operate prepaid billing, and secure the service, including:
- Telegram account information, such as Telegram user ID, username, language preference, and messages or commands sent to the bot.
- API key metadata, such as key label, prefix, last four characters, status, creation time, and last-used time.
- Wallet, ledger, hold, payment, top-up, refund, and balance records.
- API usage metadata, such as request ID, user ID, API key ID, model ID, endpoint type, timestamps, request status, latency, token counts, image counts, costs, and error codes.
- Technical and security metadata, such as headers needed for authentication, request size, rate-limit counters, concurrency state, webhook signature data, and infrastructure logs.
- Support or admin communications you choose to send.
3. Request and Response Content
cuberout does not intentionally store the content of your API prompts, files, images, or model responses in its application database. Request content passes through cuberout transiently so it can be forwarded to the configured upstream router or model provider and returned to you.
We do not use your prompts or model responses to train AI models. However, upstream routing services, AI model providers, hosting providers, payment providers, network infrastructure, or temporary operational logs may process or retain data under their own policies or technical controls.
4. How We Use Information
We use collected information to:
- Create and maintain your cuberout account.
- Issue, authenticate, list, and revoke API keys.
- Process prepaid top-ups, wallet holds, usage charges, refunds, and account balances.
- Route API requests to upstream services and return responses.
- Enforce rate limits, concurrency limits, body size limits, and abuse controls.
- Provide model lists, pricing, balance, usage, and support information.
- Monitor service health, debug failures, prevent fraud, protect security, and improve reliability.
- Comply with legal, tax, accounting, payment, dispute, and regulatory obligations.
5. Third-Party Services
cuberout relies on third-party services to operate. These may include Telegram for account onboarding and bot messaging, upstream AI routing services and model providers for request fulfillment, third-party payment services, infrastructure providers, databases, monitoring tools, and other operational vendors.
When you make an API request, the request content and related metadata may be transmitted to the upstream router and model provider needed to generate a response. Those providers operate under their own privacy policies and data processing terms.
6. Payment Data
cuberout does not intentionally store full payment card numbers. Payment providers may process payment credentials directly. cuberout stores payment identifiers, amounts, currencies, Telegram IDs or metadata needed to match payments, provider event IDs, webhook status, and ledger records required to credit balances and prevent duplicate credits.
7. API Key Security
Full API keys are shown only once when created. cuberout stores API keys in hashed form together with non-secret metadata such as prefix and last four characters. You remain responsible for protecting any full key you copy, store, or use in your applications.
8. Data Retention
We retain account data while your account exists. Usage metadata, request records, wallet records, ledger entries, payment records, security logs, and abuse-prevention records may be retained as long as needed for billing, support, accounting, tax, fraud prevention, security, dispute resolution, analytics, and legal compliance.
If you request deletion, we will delete or anonymize eligible account data within a reasonable timeframe, subject to records we must or may retain for legitimate business, legal, accounting, payment, security, or fraud-prevention reasons.
9. Data Sharing
We do not sell your personal data. We share data only when needed to provide the service, process payments, route model requests, operate infrastructure, secure the platform, handle support, comply with law, enforce agreements, or protect the rights, safety, and integrity of cuberout, users, providers, or the public.
10. Security
We use reasonable technical and organizational measures to protect data, including HTTPS/TLS for API traffic where configured, hashed API keys, production secret validation, limited internal endpoints, and operational access controls. No system is perfectly secure, and you should keep API keys, Telegram access, and payment credentials protected.
11. International Processing
cuberout, its upstream providers, payment providers, and infrastructure vendors may process data in countries other than your country of residence. By using the service, you understand that data may be transferred and processed where those providers operate.
12. Your Choices and Rights
Depending on your jurisdiction, you may have rights to access, correct, export, restrict, object to, or delete certain personal data. You can revoke API keys through the bot and request account-related help by contacting us.
To exercise privacy rights or request account deletion, contact [email protected]. We may need to verify your identity or Telegram account ownership before fulfilling the request.
13. Changes to This Policy
We may update this Privacy Policy from time to time. The updated date above will change when updates are published. Material changes may be announced through the bot, service notices, documentation, or another reasonable channel. Continued use after changes take effect constitutes acceptance of the updated policy.
14. Contact
Questions or requests about this Privacy Policy can be sent to [email protected].