Version 1.0 · Effective 29/08/2026 · The Vietnamese text is the binding version; this English text is a reference translation
The TexAPI service at texapi.dev. Our corporate details are being finalised and will be published on this page. For personal-data enquiries: support@texapi.dev with the subject line [DỮ LIỆU CÁ NHÂN].
For account data, payment data and usage metadata, TexAPI is the party that determines the purposes and means of processing. For the request content you send through the API: if that content contains the personal data of other people — your customers, your staff — then you are the controller of that data and TexAPI processes it on your instructions, which is the API call itself. The obligation to inform those people and to uphold their rights is yours; TexAPI cannot discharge it for you, because TexAPI does not know who they are and does not keep the content.
When you create an account: email address, display name, password (only an scrypt hash is stored, never the password itself), workspace name. If you sign in with Google/GitHub/Discord: the identifier, email address, name and avatar that provider returns.
When you sign in: IP address, User-Agent, time of last activity — so that you can review sessions yourself and revoke any you do not recognise, under Account → Security.
When you call the API, one row per call. Stored: IP address; the country inferred from that IP using a dataset installed on the server (no outside service is called); the model identifier; the endpoint path; the status code and error code; latency; the number of input/output/cached tokens; the cost and the pricing receipt; the organisation ID and API key ID; the timestamp. Not stored: prompt content, response content, files and images you upload, tool definitions and tool-call content.
When you top up: the amount, the method, the order ID, the payment gateway’s reference, the exchange rate, the status, the gateway fee. TexAPI does not store card numbers, cardholder names, the last 4 digits, the CVV or billing addresses — you enter those directly on the payment gateway’s own page and TexAPI never sees them.
When you connect a tool on your own computer: the machine name, the operating system, the tool version, the list of AI tools installed on that machine, and the IP address and country at the time of connection. The machine details are self-reported by the tool running on your computer.
When you submit a support ticket: your name, the reply-to email address, the category, the subject, everything you write in the body, your IP address, your User-Agent.
When you use the website: only the cookies listed in section 11. No analytics tools, no tracking pixels, no advertising cookies — that conclusion has been verified against the whole source tree and dependency tree; it is not merely a promise.
Granting access and keeping your account working, carrying out the API calls you request, billing and keeping the ledger, sending transactional email, answering support — on the basis of performance of the contract. Account security, preventing abuse and fraud, enforcing limits — on the basis of legitimate interests, which are also your own interests. Content moderation and meeting lawful requests from the competent authorities — on the basis of legal obligation. Retaining the ledger and supporting records — on the basis of legal obligations in accounting and tax.
TexAPI does not use your data to train AI models (TexAPI trains no models at all), build behavioural profiles for marketing, sell or rent to third parties, or advertise. TexAPI runs no advertising and does no email marketing.
Your request is scanned by a keyword filter running inside the TexAPI process, then forwarded in full to the model provider, then the response is normalised and its tokens counted, then it is returned to you, and then the content is discarded. Only one metadata row is written, and that row has no column capable of holding content.
The filter scans at most 40,000 characters of text that you wrote; it skips the system prompt and anything the model generated; and it does not send your content to any outside party for analysis.
One automated decision. When the number of exact-match violations reaches 3, the account is suspended automatically. You have the right to ask for review by a human; if it was a false alarm, TexAPI lifts the suspension and deletes the violation, answering within 03 business days.
The complete list. There is no one else.
The specific identity of the upstream providers is not published, for reasons of commercial confidentiality. TexAPI will give you that identity within 07 days if you ask in writing at the address in section 1 — no charge, and no questions about why.
Two categories are kept long-term, and TexAPI says plainly why. The wallet ledger is retained because of accounting and tax obligations and to settle refund disputes — it holds transaction data only, no content, and you can see your whole ledger. The operations staff action log is protected by the database so that it cannot be modified or deleted, precisely so that a staff member cannot erase their own tracks; the parts that may contain customer email addresses are masked automatically from every staff member without permission to view personal data.
You have the right to be informed, to access, to receive a copy, to correct, to delete, to restrict processing, to object to processing based on legitimate interests, to withdraw your consent, to ask for human review of an automated decision, and to complain.
Most of this data you can see directly in the Dashboard. For any other request: email us from your registered address at support@texapi.dev with the subject line [DỮ LIỆU CÁ NHÂN]. TexAPI answers within 15 days for requests to access, delete and object; 07 days for correction, restriction and withdrawal of consent; 03 business days for a request to review an automated decision. No charge, and no questions about why. TexAPI does not ask you for identity documents in order to verify you — doing that would mean collecting more data to handle a request about data.
The entire content of your requests is transferred outside Vietnam for the model to process. This is not something you can change and still use the service.
What TexAPI does to reduce that, and this part is real: your IP address is deliberately stripped before forwarding, along with 24 other proxy and browser headers; no customer identifier is attached; your API key is never forwarded; the country is inferred from a dataset installed on the server, so your IP does not have to be sent out to be looked up. What goes out is content separated from identity.
What you should do: do not send through TexAPI any sensitive personal data, health data, biometric data, payment account details, or data that your own legal obligations forbid you from transferring abroad. This is not TexAPI escaping responsibility — it is the information you need in order to decide for yourself. If you are subject to a data localisation obligation, TexAPI in its current configuration is not suitable for that kind of data.
Passwords are hashed with scrypt, with a salt unique to each password. API keys are stored as a hash only and cannot be read back — if the database were read without authorisation, your keys could not be reconstructed from it. Session tokens are stored as a hash only. Provider secrets and two-factor authentication secrets are encrypted with AES-256-GCM. Staff permissions follow the principle of least privilege, and every action that changes data leaves a trail that cannot be altered. There is no facility for signing in on a customer’s behalf.
If there is an incident: TexAPI starts investigating and containing it within 24 hours of becoming aware of it, and notifies you no later than 72 hours after confirming it — stating which data was affected, what TexAPI has done, and what you should do. TexAPI undertakes not to conceal an incident that affects you, including where the cause was TexAPI’s own negligence.
TexAPI is a service for developers, is not directed at children, and does not knowingly collect children’s data. The service is not for anyone under 16. If TexAPI learns that an account belongs to someone below that age, TexAPI deletes the account and the associated data.
Five cookies, all of them either technically necessary or a display preference you set yourself: texapi_session (sign-in session, httpOnly, 30 days), texapi_oauth_state and texapi_oauth_link (request-forgery protection during social sign-in, 10 minutes), texapi_legal_accepted (remembers that you ticked the consent box, across the redirect round trip, 10 minutes), and tex-locale (display language, 1 year).
There are no advertising cookies and no analytics tools, so there is no consent banner. API access with an sk-texapi-… key uses no cookies at all.
Adding a new purpose of processing, adding or changing a third party that receives data, or changing the categories of data transferred abroad: 30 days’ advance notice and a fresh request for your consent, together with a summary of what changed — not just a link to the new version. Changes required by law may take effect immediately, with the reason stated. If you do not accept a change that disadvantages you, you have the right to stop using the service and to ask for a refund of the unused balance.