Privacy Policy

Effective date: October 1, 2026 · Last updated: October 1, 2026

Koozhan AI (酷站AI) is developed and operated by Sunyears, Inc. Sunyears, Inc. is responsible for the processing of personal information described in this policy.

1. Scope

This policy covers the Koozhan AI website, console and API (the "Service"). It does not cover the separate practices of upstream model providers or payment processors, which are described in section 4 and section 6.

2. Information we collect

  • Account information: email address, username, a secure hash of your password (never the password itself), email verification status, account status and security settings.
  • API content: the prompts, messages, files and other input you send through the API, and the responses returned by the model, including tool calls.
  • Usage and billing information: the model used, token counts, request time, charges, price snapshots, API key identifier, request status, latency and error category.
  • Payment information: order number, amount, currency, payment method type, payment status, the transaction identifiers of the checkout provider, and refund or dispute status. For orders placed through FastSpring checkout, FastSpring collects your billing and payment details as merchant of record under its own privacy policy and shares order details with us.
  • Console activity: actions you take in the console, such as creating or revoking API keys and changing settings.
  • Device, security and risk information: IP address, browser and device information, session identifiers, security events, and signals used to detect abuse, fraud and attacks.
  • Support communications: your name, email address, account or order details and the content of messages you send to us.

3. How we use information

We use information to provide and maintain the API; authenticate you; route requests; meter usage and calculate charges; process payments and refunds; show your usage and billing history; troubleshoot; audit security; protect accounts and systems; prevent fraud and abuse; answer support requests; and meet our contractual and legal obligations.

4. API content and upstream providers

  • Why we process it. To deliver a request we transmit its content to an upstream model provider and return the response to you. We may also temporarily cache, queue, retry, route or transform content as needed to complete the request.
  • What we keep. To complete requests, troubleshoot problems, audit security and abuse, and verify billing, we process request content as needed and keep request metadata (such as model, token counts, time and cost). How long we keep API prompt and response content depends on feature configuration, operations, troubleshooting and security needs. Complete technical debugging records of a request are kept for up to 14 days. Access is limited to authorized staff for these purposes.
  • No training. We do not use your API content to train any AI model.
  • Upstream providers. Upstream providers process the content they receive under their own terms and may have their own data handling, retention and security practices. Consider whether a model is appropriate for the data you submit, and avoid sending sensitive personal data you do not need to send.

5. Cookies and similar technologies

We use necessary cookies and browser local storage to keep you signed in, protect the Service and remember preferences such as your language. Our sign-up and security checks may use Cloudflare Turnstile, which uses similar technologies to tell people from bots. We use Cloudflare Web Analytics to count page visits; it does not use cookies. We do not use advertising cookies.

6. Sharing and disclosure

We share information only as needed to run the Service, with:

  • upstream model providers that process your requests to generate responses;
  • FastSpring, our authorized reseller, and our payment processors, to take payments, issue refunds and prevent payment fraud;
  • infrastructure and security providers for hosting, networking, content delivery, security and email delivery;
  • professional advisers, such as lawyers and accountants, under confidentiality obligations;
  • authorities or other parties when required by law, or to protect the rights, safety and property of our users, Sunyears, Inc. or others.

We do not sell personal information and do not share your API content for third-party advertising.

7. International processing

Information may be processed outside the country or region where you live, including in the United States and in the countries where our upstream providers, payment processors and infrastructure providers operate. We use contractual and other reasonable safeguards, but data protection rules in these places may differ from those where you live. If the law where you are restricts transferring certain data, assess this before you submit it.

8. Retention

  • API prompt and response content: processed as needed to complete requests, troubleshoot, audit security and verify billing, with request metadata kept. How long we keep it depends on feature configuration, operations, troubleshooting and security needs; it is deleted when no longer needed. It is not used to train models.
  • Complete technical debugging records: up to 14 days.
  • Usage, billing and request records: as long as needed for billing, security, troubleshooting, accounting and disputes.
  • Account information: while your account exists, and afterwards only as needed below.
  • Payment, refund, dispute, anti-fraud and financial records: as long as contracts, tax, accounting, payment network rules or law require.

Data in backups is deleted when the backup expires rather than immediately.

9. Security

We use encryption in transit, access controls, separation of permissions, key protection, audit logs, security monitoring, rate limits, abuse detection and backups to protect information. No internet service can be perfectly secure. Use a strong password, rotate API keys you suspect are exposed, and never send your password, full API key or full card details through support channels.

10. Your rights

Depending on the law where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal information, to receive a copy of it, or to withdraw consent. Email [email protected] with the subject "Privacy request". We will verify your identity and respond as required by applicable law. Some records may be kept after an account is deleted to meet financial, security, dispute and legal obligations.

11. Children

The Service is for people aged 18 and over and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that an account belongs to a minor, we will restrict or close it and delete or anonymize the related personal information where the law allows.

12. Questions and complaints

If you have a concern about how we handle your information, contact us first at [email protected] and we will try to resolve it. You may also have the right to complain to a data protection authority where you live.

13. Changes to this policy

We may update this policy. We will post the new version on this page with a new effective date and give reasonable notice of material changes on the website, in the console or by email.

14. Contact

Sunyears, Inc. · Koozhan AI Privacy
Email: [email protected]