Skip to content
Q3Qwen3.8 Playground

Privacy

Privacy policy

This policy explains which service handles each kind of data, what we keep, and the choices available to you.

Effective August 22, 2026

1. Data we receive

  • Account email, verification time, and account identifier when you request and use a sign-in link.
  • Hashed session and API-key values, key prefixes, plan state, call counts, token counts, and provider request identifiers.
  • Yito Pay order identifiers, selected plan, entitlement state, and signed billing events. We do not receive or store full card numbers.
  • Basic request logs such as time, route, status, Cloudflare request ID, and operational error codes.
  • Page and conversion analytics collected through Google Analytics 4 and click.pageview.click, subject to their technologies and your browser choices.

2. Prompt content

The first-party API forwards request content to OpenRouter and its selected upstream model provider to produce a response. We do not write prompts or completions to our D1 application database. Infrastructure or upstream providers may process or retain data under their own policies. Do not send secrets, regulated data, or personal data you are not authorized to process.

3. Third-party demo

The homepage frame loads directly from a community Hugging Face Space. Prompts entered there go to that Space, not to our Worker or D1 database. Hugging Face and the Space operator control its availability and data practices. Use the external-link control to inspect the host before submitting sensitive content.

4. Why we use data

We use data to authenticate accounts, issue and revoke keys, enforce quotas and rate limits, settle entitlements, prevent abuse, send transactional email, diagnose errors, and understand the conversion funnel. We do not sell personal data.

5. Service providers

Cloudflare hosts the Worker and D1 database. ZeptoMail delivers sign-in and operational email. pay.yito.ai and Stripe support checkout and billing. OpenRouter provides model routing. Hugging Face hosts the independent demo. Google Analytics 4 and click.pageview.click provide traffic analytics. Each provider acts under its own terms and privacy practices.

6. Retention and security

One-time sign-in tokens expire after 15 minutes, sessions after 30 days, and expired authentication and rate-limit rows are cleaned on a schedule. Account, entitlement, usage, billing-reference, and security records are retained as needed to operate the service, resolve disputes, prevent fraud, and meet legal obligations. Secrets are stored as encrypted Worker secrets; session tokens and API keys are stored only as hashes.

7. Your choices

You may revoke API keys, cancel future subscription renewals through the billing portal, block analytics with browser controls, or request access, correction, or deletion by emailing contact@qwen3-8.org. Some billing and security records may need to be retained after account deletion.

8. Changes

Material changes will be reflected by a new effective date on this page. Continued use after a change means the updated policy applies to future activity.