Privacy Policy

Last updated: 11 September 2026

This policy explains what personal data we collect when you use the Thelsy API service, why we collect it, how long we keep it, and the choices you have.

1. Who we are

Thelsy ("we", "us") operates an API gateway service that provides programmatic access to third-party artificial intelligence models. We are the controller of the personal data described below. Contact: 393516700@qq.com.

2. What we collect

CategoryExamplesWhy
Account data Email address, name, country, password (stored hashed) To create and secure your account
Payment data Plan, billing history, invoice references, tax country To process payments and meet accounting obligations. Card details are collected and stored by our merchant of record — we never see or store card numbers.
API usage metadata Timestamp, API key identifier, model name, token counts, HTTP status, IP address, response time To meter usage and bill correctly, to detect abuse, and to diagnose faults
Support correspondence Emails and messages you send us To answer your request and keep a record of the issue

3. Request content

Your prompts and model responses are transmitted through our gateway to the upstream model provider so that your request can be served. We do not use your prompts or outputs to train models, we do not sell them, and we do not use them for advertising. We may retain a limited record of request content for a short period (up to 30 days) where necessary to investigate abuse, security incidents or billing disputes; otherwise we keep usage records in metadata form only.

4. How we use personal data

We do not sell personal data, and we do not use it for third-party advertising.

5. Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on: performance of a contract (providing the Service), legitimate interests (security, abuse prevention, service improvement), legal obligation (tax and accounting), and consent where required (for example, optional product emails).

6. Who we share data with

7. International transfers

We operate servers in Hong Kong and use service providers located in other countries. Your data may therefore be transferred to and processed in countries other than your own. Where required, we rely on appropriate safeguards such as standard contractual clauses.

8. Retention

9. Security

We use TLS encryption for all traffic, hashed storage of passwords, restricted access to production systems, and periodic backups. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to lodge a complaint with your local supervisory authority. To exercise a right, email 393516700@qq.com. We respond within 30 days.

11. Cookies

Our website and dashboard use only the cookies strictly necessary to keep you signed in and to protect against cross-site request forgery. We do not use advertising or cross-site tracking cookies.

12. Children

The Service is intended for business and professional use and is not directed to anyone under 18. We do not knowingly collect data from children.

13. Changes to this policy

We may update this policy. The current version is always on this page with its "Last updated" date. Material changes will be notified by email or in your dashboard.

14. Contact

Privacy questions or requests: 393516700@qq.com