Effective 8 October 2026

Privacy Policy

What data SaaufAI processes, what it stores, who it shares it with and your rights.

1. Summary

SaaufAI does not store the content of your prompts or of the model responses. Content passes through our servers in memory only to be checked against safeguards, translated and forwarded to the upstream provider of the model you chose, or of one of its disclosed fallback models. Where a model uses content-category safeguards, the prompt is also sent to the classifier model named on that model's page. We store request metadata (which key, which model, token counts, status, timing) to operate and secure the Service.

2. Data we process

DataWhyStored?
Prompt and response content (text, images, tool calls)To forward your request to the upstream model and return the answerNo, processed in transit only
API key (as a SHA-256 hash) and its labelTo authenticate requestsYes, until the key is deleted
Request metadata: timestamp, model, API key used, HTTP status, token counts, latency, whether streaming was used, and a short upstream error message when a request failsPer-model usage analytics, capacity planning, debugging and abuse preventionYes
IP address and user agentHandled by our hosting provider for delivery and securityOnly in the hosting provider's short-lived logs
Administrator's Discord ID, username and avatarTo sign the administrator into the admin panelOnly in a signed browser cookie (7 days)

3. Upstream AI providers

When you call a model, the content of your request is sent to the provider that serves it. That provider processes it under its own terms and privacy policy, which may include retaining data for a limited period for abuse monitoring, or (for some providers or plans) using it to improve their models. Each model's page lists the answers the administrator has recorded about these practices; see Model disclosures.

4. Infrastructure providers (sub-processors)

  • Vercel Inc.: hosting and serverless execution of the website and API.
  • Supabase Inc.: database for configuration, hashed API keys and usage metadata (EU region, Frankfurt).
  • Discord Inc.: sign-in for the administrator only.
  • The upstream AI provider(s) of the model you call (see each model's page).

5. Cookies

Public pages set no cookies. The admin panel uses one strictly necessary, HTTP-only session cookie and a short-lived OAuth state cookie during sign-in. There are no analytics or advertising cookies.

6. Retention

Usage metadata is kept while the related API key exists and may be deleted earlier on request. When a key is deleted, its usage records are de-linked from it.

7. Your rights

Depending on where you live (for example under the GDPR), you may have the right to access, correct, delete or export personal data about you, to object to or restrict processing, and to complain to your data protection authority. Contact the administrator on Discord to exercise these rights. For data held by an upstream AI provider, you may also need to contact that provider directly.

8. Security

Traffic is encrypted with TLS. Upstream provider credentials are encrypted at rest with AES-256-GCM, API keys are stored only as hashes, and the database is not reachable from browsers.