Privacy Policy
Effective 2026-09-09 · applies to the ThunderPeak API gateway, website and console.
1 · Overview
ThunderPeak is an independently operated AI API gateway. We collect the minimum data required to run the service, meter usage and prevent abuse — and nothing more. This policy explains exactly what that means.
2 · What we collect
- Account information — the email address or username you register with, and a hashed version of your password. We never store plain-text passwords.
- API request metadata — timestamps, model names, token counts (input/output/cache/thinking), status codes and originating API key. This is the data that produces your bill and your usage graphs.
- Payment references — for USDT top-ups, the transaction ID (TXID) and the amount you tell us about, used to credit your account and to resolve disputes.
- Support conversations — messages you send us on Telegram or by email, kept so we can answer follow-ups.
- Basic site preferences — theme and language choices, stored locally in your browser only.
3 · What we do not collect
- Your prompts and model responses are not logged or stored beyond transient in-memory processing needed to fulfil the request. We do not build training sets from your traffic.
- We do not run advertising trackers, and we do not sell or rent personal data to anyone.
4 · How we use it
- To authenticate you and operate your account, keys and limits.
- To calculate usage and maintain accurate balances.
- To detect and stop abuse, fraud, key leakage and unusual traffic patterns.
- To provide support and respond to your requests.
- To communicate service changes, outages or security notices affecting your account.
5 · Sharing
Prompts and completions are forwarded to the upstream model provider to fulfil your request — that forwarding is the service. Beyond that, data is shared only with: payment processors identifying a crypto transfer; infrastructure providers hosting the gateway; and authorities where legally compelled. Aggregated, non-identifying statistics may be used internally for capacity planning.
6 · Retention
- Request metadata — up to 180 days, then deleted or aggregated.
- Account data — kept while your account is active, and deleted after you request closure (except records we must keep for accounting or legal reasons).
- Payment references — retained as long as needed for dispute resolution and legal obligations.
7 · Security
Traffic to the gateway and console is encrypted in transit. API keys are stored hashed where possible and can be rotated or revoked at any time from the console. Access to production systems is restricted and credential-protected. If we ever discover a breach affecting your data, we will notify affected accounts promptly.
8 · Your rights
You can request a copy of your account data, ask us to correct it, or ask us to delete your account by contacting [email protected] or Telegram @thunderpeak_support. We respond within a reasonable period and may need to verify your identity first. Deleting your account cancels outstanding credit; it is not refundable except where required by law.
9 · Cookies & local storage
The website uses your browser's local storage for display preferences (dark/light theme, language) and the console uses a session cookie to keep you signed in. We do not use third-party advertising cookies.
10 · Changes
If this policy changes materially, we will update the effective date above and, for significant changes, notify account holders. Continued use of the service after changes means you accept the updated policy.
11 · Contact
Questions about privacy? Email [email protected] — messages in any language are welcome.
