Privacy Policy
Effective date: September 13, 2026 Last updated: September 15, 2026
This Privacy Policy explains how Havenbyte LLC ("Havenbyte", "CheapAI", "we", "us", or "our") collects, uses, discloses, and protects information when you access or use CheapAI websites, accounts, dashboards, APIs, documentation, payment flows, support channels, and related services.
This policy is written in English. If we provide a translation, the translation is for convenience only, and the English version controls to the extent of any conflict.
1. Information We Collect
We collect information that you provide directly, including account information, login identifiers, contact information, API key names, organization or project information, other messages you send to us, and payment or billing information handled through supported payment providers.
When a hosted image-generation feature is enabled, generated images and the metadata needed to serve signed short-lived asset URLs may be stored in private object storage until the disclosed retention period expires.
When you visit or register, we may record attribution information such as UTM parameters, referral host, landing context, and an X click identifier (twclid) or Google Ads click identifier (gclid) when present. We also record the browser privacy signals needed to respect applicable Do Not Track (DNT) or Global Privacy Control (GPC) choices for X and Google Ads measurement.
When you use the API, dashboard, documentation, network tests, or related services, we collect operational metadata such as account ID, API key ID, model name, group, routing and channel diagnostic information, request ID, provider request ID when available, token counts, fees, status code, timing information, timestamps, network route, error information, IP address, user agent, authentication events, payment status, and similar logs needed to operate the service.
Consume and error log rows are governed by the site's Log Retention setting: when automatic cleanup is enabled, the default is 7 days, authenticated users may choose 7, 30, or 60 days, and 60 days is the maximum. Monthly summaries and financial or audit records follow separate retention controls.
Inputs and outputs sent through the API are processed to provide the service and may be transmitted to the model or infrastructure provider selected for the request. In the ordinary API relay path, we do not store request or response bodies as long-term business records in the application database. We do not use customer content to train, fine-tune, distill, benchmark, or improve AI or machine-learning models developed or operated by Havenbyte. A selected model provider's retention and training practices are governed by that provider's applicable terms and may vary by provider, product, account type, and region.
The Images API is a limited exception when you request response_format=url: the validated generated image is stored in private object storage and made available through a signed link that expires after one hour by default. The backing object may remain private after the link expires until the configured short-lived storage lifecycle deletes it. When you request response_format=b64_json, this feature returns the validated image inline and does not persist an API output object.
Short-lived request-debug records contain diagnostic metadata and parameter summaries, not complete request or response bodies, and are designed to expire after 72 hours. Request Archive is a separate body-diagnostic feature that is disabled by default. If specifically enabled, it may store scoped original and upstream request bodies on protected local storage; its current default expiry is 168 hours. These diagnostic capabilities are used only for authorized troubleshooting, security investigations, abuse detection, billing disputes, reliability, or legal compliance and are subject to access and retention controls.
2. How We Use Information
We use information to provide, secure, maintain, and bill for CheapAI services; authenticate users; manage API keys and access groups; route API requests; calculate usage and fees; provide persistent product features; process payments and reconcile provider reversals; detect fraud, abuse, outages, and security issues; respond to support requests; comply with legal obligations; enforce our Terms of Service and Platform Usage Rules; and communicate service, billing, security, or policy updates.
We use limited product, page, account, and attribution information to understand service adoption, measure website and conversion performance, diagnose product issues, and improve the service. We do not send API prompts, API request or response bodies, passwords, secrets, or API keys to PostHog, X, or Google Ads for these purposes.
We may use aggregated or de-identified information for operational reporting, capacity planning, reliability analysis, abuse prevention, pricing analysis, and product improvement, provided it does not identify a specific customer or user and is not used to re-identify anyone.
3. How We Share Information
We disclose information only as needed for the purposes described in this policy:
- Model providers: The provider selected for an API route receives the inputs, necessary context and files, and other data needed to return the requested output.
- Cloudflare and infrastructure providers: Cloudflare and applicable hosting providers process network traffic, request headers, IP addresses, and related data for edge delivery, security, DNS, DDoS protection, connectivity, hosting, and storage. Cloudflare R2 stores generated-image assets for enabled persistent features in private object storage.
- PostHog: When analytics is enabled, PostHog receives allowlisted page, product, and account metadata. It does not receive API prompts, API request or response bodies, passwords, secrets, or API keys from our analytics implementation.
- X: When X measurement is enabled and not suppressed by an applicable browser privacy signal, the website tag may process browser and network data. Server-side conversion events may include an X click identifier, an opaque conversion identifier, event time, and, for an eligible payment conversion, value and currency. We do not send API prompts, API request or response bodies, API keys, or payment credentials to X.
- Google Ads: When Google Ads measurement is enabled and not suppressed by an applicable browser privacy signal, the Google tag may process browser and network data for website visit and conversion measurement. A browser conversion event may include an opaque conversion identifier. We do not send API prompts, API request or response bodies, API keys, or payment credentials to Google Ads.
- Stripe and other supported payment providers: Payment providers process payment methods, billing details, transaction value and currency, risk signals, tax information, invoices, receipts, refunds, disputes, and related transaction information under their own policies. We do not store full payment card numbers.
- Advisors, transactions, and authorities: We may disclose information to professional advisors, in connection with a corporate transaction, or to authorities and other parties where required or permitted by law, while applying appropriate confidentiality and legal safeguards.
Third-party services process information under their own terms, privacy policies, data-processing rules, regional restrictions, and retention practices. When you choose a payment method, model route, or integration, the relevant third party receives the information necessary to complete that service.
We do not sell personal information. We do not disclose customer API inputs or outputs for cross-context behavioral advertising or use them to build advertising profiles.
4. Payments
Payments are processed by supported payment providers such as Stripe. We do not store full payment card numbers. Payment providers may collect and process payment method details, billing details, risk signals, tax information, invoices, receipts, refunds, disputes, and related transaction information under their own policies.
5. Cookies, Analytics, and Similar Technologies
We may use cookies, local storage, website tags, and similar technologies for authentication, session management, security, preferences, language selection, attribution, analytics, conversion measurement, and product operation. Depending on the functions enabled, these technologies may be provided by CheapAI, PostHog, X, or Google Ads. Some features may not work correctly if required storage or scripts are disabled.
Our current implementation suppresses X and Google Ads browser-tag conversion measurement, and X server-side conversion measurement, when the browser presents a DNT or GPC signal. Browser controls, extensions, or network settings may also block analytics or measurement technologies.
6. Retention
We retain information only for as long as reasonably necessary to provide the services, maintain accounts, calculate billing, satisfy accounting and legal obligations, resolve disputes, enforce agreements, detect abuse, protect security, and support operations.
- Ordinary API request and response bodies are processed transiently and are not retained as standard long-term application database records.
- When automatic cleanup is enabled, consume and error log rows use a 7-day site default. Authenticated users may choose 7, 30, or 60 days, subject to a 60-day maximum; monthly summaries and financial or audit records follow separate controls.
- Images API output requested with
response_format=urlis stored in private object storage under a short-lived lifecycle; its signed link expires after one hour by default.b64_jsonoutput is not persisted by this feature. - Short-lived request-debug metadata is designed to expire after 72 hours.
- Request Archive is disabled by default; if authorized and enabled, its current default expiry is 168 hours unless a different period is configured or agreed.
- Account, usage, billing, attribution, product-analytics, security, and operational records are retained as reasonably necessary for their stated purposes and applicable legal obligations.
Data retained in protected backups may remain until overwritten through the ordinary backup lifecycle but is placed beyond active use. Data processed by a selected model provider is subject to that provider's applicable retention terms and controls.
7. Security
We use reasonable administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. These measures include authenticated and role-based access, restricted privileged operations, encrypted transport, protection of supported sensitive credentials, and private access paths for stored image assets. No system is perfectly secure, and customers are responsible for protecting their own credentials, API keys, devices, networks, and downstream integrations.
8. International Transfers
CheapAI is operated by Havenbyte LLC and may process information in the United States and other countries where we or our service providers operate. Information may be transferred to and processed in countries that have different data-protection laws. Where applicable law requires a transfer mechanism, we will use an applicable legally recognized mechanism.
9. Your Choices and Requests
You may access and update certain account information in the dashboard, delete API keys, stop using the service, or contact us about account, billing, privacy, access, correction, return, or deletion requests through the official support channels published on our website.
You may use browser DNT or GPC settings to suppress our current X and Google Ads browser-tag conversion measurement, and X server-side conversion measurement. You may also use browser controls to manage cookies, local storage, and scripts, although required service features may not work correctly if disabled.
We may need to verify your identity, account ownership, payment ownership, or authority before responding to certain requests. We may retain information where required or permitted for legal, security, accounting, fraud-prevention, dispute-resolution, or operational reasons. If we process personal information on behalf of an enterprise customer, requests concerning that customer's data may need to be directed to the customer.
10. Children's Privacy
The services are not intended for children or for use by anyone who is not legally allowed to use the services under applicable law. Customers that build products for minors are responsible for obtaining required consent and implementing appropriate safeguards.
11. Changes
We may update this Privacy Policy from time to time. Updated versions become effective when posted or on the date stated in the notice. Where required by law, we will provide additional notice or obtain consent. Continued use of the services after an update means you accept the updated policy to the extent permitted by law.
12. Contact
For privacy questions or requests, contact us at castaly.ai@gmail.com, or through the official Telegram or QQ group shown in the console overview: Telegram https://t.me/+s2ZNXHUDTIFiZmE1; QQ group 973031226.