Legal
Privacy Policy
Last updated: July 18, 2026
1. Summary
KeyC is an AI spend-control gateway. We process account data and request metadata (tokens, model, latency, cost, status). We never store prompts or completions.
2. Data we collect
- Account: email, password hash, organization name, role
- Billing: Stripe customer and subscription identifiers
- Usage metadata: token counts, model, provider, latency, cost, HTTP status
- Audit events: key create/revoke, member changes, signup
- Optional analytics cookies (GA4) if you consent via the cookie banner
- Site traffic: IP address, approximate location (country/region/city), device, operating system, browser, screen size, and language, recorded for every page visit and visible only to platform admins
3. Provider keys
Provider API keys you vault are encrypted at rest with AES-256-GCM. Virtual keys are stored as SHA-256 hashes only; the raw value is shown once.
4. Legal bases & retention
We process data to provide the service (contract), secure accounts (legitimate interest), and meet legal obligations. Usage logs are retained for billing and reporting; you may request deletion of account data subject to legal holds.
5. Subprocessors
See our DPA & subprocessors page (Stripe, Resend, hosting). A fuller security overview is on /security.
6. Your rights
Depending on your region you may request access, correction, export, or deletion. Contact abdullahyoussef.com.
7. International transfers
Infrastructure may be hosted in the EU or US depending on deployment. Enterprise customers can discuss residency requirements with us.
Developer-oriented privacy notes also live in Docs → Privacy.