Data Policy
Last updated: 2026-07-24
This Data Policy explains how HuiLink processes, stores, and protects your data when you use our service. We are committed to transparency about our data practices.
Data Collection
We collect only the data necessary to operate our service:
- Account Data: Email address, hashed password (argon2id), OAuth provider IDs, name, avatar URL
- API Usage Metadata: Model name, token count, timestamps, request ID
- Billing Data: Payment records, transaction IDs, balance history
- Technical Data: IP address (30-day retention), User-Agent, error logs (anonymized)
- Support Data: Email correspondence and chat transcripts
Data Processing
Your data is used for the following purposes:
- Forwarding API requests to upstream LLM providers (transient, not stored)
- Usage calculation, invoicing, and payment processing
- Rate limiting, fraud detection, and abuse prevention
- Aggregate usage analytics and error monitoring
Data Sharing
Your API requests are forwarded to the upstream LLM provider you select. Payment data is handled by PCI-DSS compliant processors (Stripe, Epay, WeChat Pay). We never share data for advertising.
Data Retention
We retain different categories of data for specific periods:
- Account data: Until account deletion
- API usage metadata: 12 months
- API request/prompt content: Not stored (transient proxy only)
- Payment records: 7 years (tax compliance)
- IP address and logs: 30-90 days
- Support chat transcripts: 90 days
Your Rights
You can access, export, or delete your data at any time via the Dashboard or by contacting us. Account deletion requests are processed within 30 days.
Contact
For data policy inquiries, contact us at bradyliuy@gmail.com