Legal
Privacy Policy
Last updated: 18 August 2026
1. Who is responsible
UndercutAI operates undercut.pro and is the controller of the personal data described here. For any privacy question or request, write to [email protected].
2. What we do not store
- Prompts, messages, system instructions, files or any other request content.
- Model completions, tool calls or any other response content.
- Conversation history. There is no chat log on our side to hand over, sell or lose.
- Your API key secret. Only a hash and a short prefix are stored, which is why a key is shown once and cannot be recovered.
- Your password. Only a scrypt hash with a per-account salt is stored.
- Card numbers. Card data is entered on our payment provider's page and never reaches our servers.
Request content passes through the gateway only for as long as it takes to relay it to the Provider and return the answer to you. It is not written to our database and is not used to train any model.
3. What we do store
- Account — email address, password hash, account identifier, creation date, referral code and, if you signed up through a link, the referring account.
- Sessions — a hash of the session token, its type, a credential fingerprint and an expiry, so that sessions can be revoked and invalidated on a password change.
- API keys — identifier, label, creation and revocation dates, and a key hash. Never the secret itself.
- Usage records — timestamp, model identifier, protocol, the key used, input, output, cache read and cache write token counts, the rate applied, the pricing version and the resulting cost. No content.
- Billing ledger — top-ups, promotional credit, usage debits, adjustments, and the payment provider reference of each transaction.
- Crypto deposits — the deposit address derived for your account, the chain, asset, amount and transaction reference of each deposit.
- Notification settings — the HTTPS webhook URL you enter for low-balance alerts, if you enable them.
- Abuse protection — rate-limit counters keyed by a hash, not by a readable IP address, plus transient server logs used to detect abuse and diagnose failures.
4. Why we process it
- To perform the contract with you: create and secure your account, issue keys, relay requests, bill usage and process payments.
- For our legitimate interests: prevent fraud and abuse, protect the Service, and keep it reliable.
- To comply with the law: accounting, tax and anti-fraud obligations for payment records.
- With your consent, where consent is the applicable basis, for example if you opt into low-balance webhooks.
5. Who receives data
- AI model providers — receive the content of the request you send, in order to answer it. Their own privacy terms apply to that processing.
- Payment provider (Stripe) — receives the data needed to process a card payment and returns the payment status. We receive only metadata, never card details.
- Email provider (Resend) — receives your email address to deliver verification and sign-in messages.
- Blockchain nodes and explorers — queried for public on-chain data when you fund the balance with crypto.
- Authorities — only where we are legally required to disclose, and only what is required.
We do not sell personal data and we do not share it with advertisers or data brokers.
6. Cookies
We use strictly necessary cookies only: a session cookie that keeps you signed in, the equivalent cookie for the administrative area, and a preference cookie that remembers your chosen interface language. There are no advertising, profiling or third-party analytics cookies on this site, so there is nothing to consent to beyond keeping the site working.
7. Retention
- Account data — for as long as the account exists.
- Sessions — until they expire or you sign out; expired sessions are deleted.
- Pending registrations and sign-in codes — minutes, not days; they are deleted once used or expired.
- Usage and billing records — kept while the account exists and afterwards for as long as accounting and tax law requires.
- Rate-limit counters — until their short window resets.
8. Your rights
Depending on where you live you can request access, correction, deletion, restriction or portability of your data, and object to processing based on legitimate interests. You can export your full usage history yourself at any time as CSV from the dashboard. To exercise any other right, write to [email protected]; we answer within 30 days. You also have the right to complain to your local data protection authority.
Deleting your account removes your account record and everything linked to it, except billing records we are legally required to keep.
9. Security
Passwords are hashed with scrypt and a per-account salt. Session, verification and sign-in tokens are stored only as HMAC hashes with an expiry, and can be revoked server-side. Email confirmation and sign-in links carry their token in the URL fragment so it never reaches HTTP access logs or the Referer header. All traffic to the Service uses HTTPS. No system is perfectly secure, so keep your API keys secret and revoke any key you suspect has leaked.
10. International transfers
Model providers, our payment provider and our email provider may process data outside your country. Where that happens we rely on the safeguards those providers offer, such as standard contractual clauses.
11. Children
The Service is not directed at children and is not intended for anyone under 18. We do not knowingly collect data from children; if you believe a child has created an account, tell us and we will delete it.
12. Changes and contact
We publish the current version of this policy here with its update date and notify registered accounts by email about material changes. Questions: [email protected]. See also our Terms of Service.