Last updated: June 9, 2026
Yomi API relay and quota management service (the "Platform" or "we") values user privacy and personal information protection. This Privacy Policy explains how we collect, use, store, protect and process your information when you visit, register, log in, purchase, redeem credits, create API keys, call APIs, view usage or use other services.
Please read this policy carefully before using the Platform. By clicking agree, registering, logging in or continuing to use the Platform, you acknowledge that you understand and agree to this policy. If you do not agree, please stop using the Platform.
This policy applies to the Platform's API relay, quota management, subscriptions, redemption codes, usage statistics, account management, risk controls, security and related technical services.
The Platform does not provide services to users in mainland China and does not conduct promotion, sales or operations in mainland China.
You must not access or use the Platform if you are in mainland China or if the laws of your location prohibit or restrict your use. If you access or use the Platform through proxies, VPNs, overseas networks, remote servers or other technical means, you alone bear all resulting legal liabilities, regulatory risks, account risks, network risks and other consequences, for which the Platform is not responsible.
The Platform primarily serves overseas Chinese users, overseas developers, cross-border teams and other lawful and compliant overseas users.
To provide, maintain, improve and protect our services, we may collect the following information as required by the relevant features:
Account information: Username, email address, password hash, avatar, role, user group, registration time, login status, account status, invitation code or referral relationship.
Security and login information: IP address, login time, device and browser information, User-Agent, session identifier, failed login records, two-factor verification status and abnormal access records.
Transaction and quota information: Plans, subscriptions, redemption codes, top-up records, quota balance, quota changes, order status, necessary transaction information returned by payment channels, and invoice or accounting information.
API usage information: API key identifier, call time, model name, request path, quota consumed, response status, error information, usage statistics, rate-limit records, concurrency records, and channel or group information.
Information you voluntarily submit: Support tickets, customer service communications, feedback, appeal materials, compliance explanations, notes or other content you upload or submit voluntarily.
Cookies and local storage: Information needed to maintain login sessions, save preferences, identify security risks, improve the page experience and prevent repeated notices.
We do not proactively request sensitive personal information unrelated to the service. Do not submit identity documents, bank card passwords, biometric data, health information, minors' information or other unnecessary sensitive information in tickets, notes, requests or other inputs.
We may use collected information for the following purposes:
Creating, verifying, maintaining and protecting your account;
Providing API relay, quota management, redemption codes, subscriptions, usage statistics, billing settlement and call record queries;
Identity verification, login protection, anomaly detection, risk audits, prevention of fraud, abuse and attacks, and troubleshooting;
Handling orders, payments, refunds, disputes, customer support, appeals and notifications;
Optimizing system performance, improving the product experience and analyzing service stability and capacity;
Meeting applicable legal and regulatory requirements and obligations relating to dispute resolution, audits, security compliance and protection of rights;
Other reasonable uses with your authorization or as permitted by law.
The Platform may record metadata necessary for API calls, such as call time, model, consumption, status code, error information, user ID, API key identifier, channel information and request duration, for billing, statistics, troubleshooting and risk control.
We do not manually inspect your complete business content for routine operations, except for troubleshooting, dispute handling, security audits, compliance requirements or content you voluntarily submit.
You should avoid submitting illegal content, third-party private information, trade secrets, production keys, payment credentials, identity documents or other sensitive information that should not be submitted to model services.
Upstream model providers, third-party APIs, payment channels and client tools may process your requests or transaction information under their own policies. You should also read and comply with their privacy policies and terms of service.
We do not sell your personal information. To deliver the service, we may share information with, or entrust its processing to, the following parties to the extent necessary:
Infrastructure providers for cloud servers, databases, caching, logs, monitoring, security protection, email, messaging, payments, risk controls and customer support;
Upstream model providers, API providers, payment providers, network providers or other third parties necessary to complete API calls, process transactions and deliver services;
Parties to whom information must be provided under laws, judicial or regulatory requests, dispute resolution, protection of rights or security incident handling requirements;
Parties you expressly authorize or request us to share information with.
We will make reasonable efforts to require third parties to process relevant information only as necessary to deliver services and to take reasonable security measures.
Because the Platform serves overseas users, servers, upstream providers, payment channels, customer service and technical support may be located in different countries or regions. By using the Platform, you understand and agree that relevant information may be transferred, stored and processed outside your region. Where reasonably practicable, we will protect information through encryption, access controls and minimum necessary authorization.
We retain your information for as long as necessary for the purposes described in this policy, unless longer retention is required for legal or regulatory requirements, dispute resolution, accounting audits, security and risk controls, or protection of rights.
When information is no longer needed, we will delete it, anonymize it or take other reasonable measures as appropriate.
Because of backups, logs, security audits or technical limitations, deletion requests may not immediately propagate to every copy. We will restrict further use of that information for routine business purposes.
We take reasonable technical and organizational measures to protect information, including:
Encrypted transmission, access controls, least privilege, isolation of account permissions, log audits and security monitoring;
Encryption or irreversible hashing of sensitive authentication information such as passwords;
Restricting internal access to personnel who need the information and only within their authorized scope;
Monitoring and responding to abnormal logins, abnormal calls, abuse and security incidents.
However, internet services cannot guarantee absolute security. For information disclosures, losses or service interruptions caused by users, third parties, force majeure, upstream failures, cyberattacks or other factors beyond the Platform's control, we will provide reasonable assistance but do not assume liability beyond that required by law and this policy.
To the extent permitted by applicable law, you may exercise the following rights using Platform features or by contacting us:
Access, correct or supplement your account information;
Request deletion of your account or certain information;
Request an export or copies of certain records relating to you;
Withdraw nonessential authorizations or disable certain features;
Close your account or stop using the Platform;
Raise questions, complaints or appeals concerning the processing of personal information.
To protect account security, we may require identity verification before processing requests. We may lawfully refuse or delay requests that could affect others' rights, Platform security, accounting audits, dispute resolution or legal obligations, or that are technically infeasible, and will explain the reasons.
The Platform does not provide services to minors. Do not register or use the Platform if you have not reached the age of majority in your jurisdiction or lack full civil capacity. If we discover that a minor's information was improperly submitted, we will verify it and delete it or take other necessary measures as required by law.
We may use cookies, local storage or similar technologies for login sessions, language preferences, theme settings, security checks, preventing repeated notices, statistics and performance optimization. You can manage or delete cookies through your browser settings, but this may prevent some features from working properly.
We may update this policy in response to changes in laws, service features, operations, third-party services or security requirements. Updated policies take effect when published on the Platform. Continued use means you accept the updated policy; if you disagree, stop using the Platform.
For questions, complaints or requests regarding this policy, personal information processing, account security or compliance, contact us through the customer service, ticket, email or other channels published on the Platform. We will handle your request within a reasonable time.