# Privacy Policy — AuCore

> AuCore Privacy Policy — what we collect, how prompts are handled, and your rights.

Source: https://ai.aunuhost.bond/privacy

Legal

# Privacy Policy

Last updated 25 August 2026 · Operated by AuR AI (&ldquo;AuCore&rdquo;, &ldquo;we&rdquo;, &ldquo;us&rdquo;).

In short: we store the minimum needed to run a metered API — your account record, a hash of your key, and request metadata. Prompt and output bodies are not stored. We never sell your data and never train models on your content.

## 1. Who we are

AuCore is operated by AuR AI, the data controller for the account and usage data described below. For content you send through the API, you are the controller and we act as your processor.

## 2. What we collect

| Category | Examples | Purpose | Retention |
| --- |--- |--- |--- |
| **Account** | Name, email, plan, status, expiry | Issue and manage your key | Account life + 30 days |
| **Credentials** | Hashed API key, encrypted provider credentials | Authenticate requests | Until rotated or deleted |
| **Request metadata** | Timestamp, model, endpoint, token counts, latency, status | Quota, analytics, abuse detection | 7 / 30 / 90 days by plan |
| **Prompt & output** | Message content | Relayed for inference only | Not stored by AuCore |
| **Security logs** | Failed auth, rate-limit hits, admin actions | Protect the platform | 90 days |
| **Support requests** | Name, email, plan, message text | Answer your request — only after you tick the consent box | 120 days |
| **Secondary keys & webhooks** | Named key hashes, your webhook URLs | Multi-key access, event delivery | Until you remove them |

We do not use advertising cookies or third-party trackers. Your browser stores your key and cached profile locally so the dashboard works; clearing site data removes them.

## 3. Prompt content

Prompts and completions pass through the Service in memory and are forwarded to the selected model provider. We do not write message bodies to storage. Only metadata such as token counts, model, latency and status is recorded.

## 4. Legal bases

- **Contract** — issuing keys, metering usage, providing dashboards.
- **Legitimate interests** — security, abuse prevention, capacity planning, aggregate analytics.
- **Legal obligation** — tax, accounting and lawful requests.
- **Consent** — support requests (you tick the consent box on the form; the platform rejects requests without it), optional communications, withdrawable at any time.

## 5. Sharing

- **Cloud infrastructure providers** — edge hosting, compute and storage used to run the Service.
- **Model providers** (for example OpenAI, Anthropic, Google, Meta) process prompt content to generate output. Requests may be routed to whichever independent inference route currently serves your chosen model.
- **Email delivery provider** — support tickets are relayed to our support inbox through a transactional email service; the ticket content and your reply-to address are processed solely to answer your request.
- **Your webhook endpoints** — when you register webhooks, event payloads are delivered to URLs you control. You are the controller of any data your endpoints receive.

We do not sell personal data and do not share it for cross-context behavioural advertising. Disclosure to authorities occurs only where legally required, and we resist overbroad demands where lawful.

## 6. International transfers

Because the Service runs on a global edge network, data may be processed outside Indonesia, including in the United States and the European Union. Transfers rely on the safeguards offered by our providers, including standard contractual clauses where applicable.

## 7. Security

- TLS everywhere; no plaintext endpoints.
- API keys are stored as salted hashes, never in plain text.
- Prompt and completion bodies are never persisted — only usage metadata is kept.
- Administrative access is restricted and every privileged action is written to an audit log.
- Rate limiting on authentication attempts and least-privilege access to data stores.

No system is perfectly secure. If we discover a breach affecting your data, we will notify affected accounts and, where required, regulators without undue delay.

## 8. Your rights

Subject to applicable law you may request access, correction, deletion, export, restriction of processing, or object to processing based on legitimate interests. Contact us via the support page; we respond within 30 days and may ask you to verify control of your key or registered email. You may also lodge a complaint with your local data protection authority.

## 9. Children

The Service is not directed to children under 13, or the higher local minimum age. We do not knowingly collect their data; contact us for removal if you believe we have.

## 10. Changes

Material changes are announced on this page and by email where we hold your address, at least 14 days before taking effect. The &ldquo;last updated&rdquo; date above reflects the current version.

---

Questions? Reach us on the [support page](https://ai.aunuhost.bond/support). See also our
 [Terms of Service](https://ai.aunuhost.bond/terms) and [security overview](https://ai.aunuhost.bond/security).
