This policy explains how Ling.AI collects, uses, stores, shares, and protects information when you use the website, console, token packages, and API gateway.
1. Scope
This Privacy Policy applies when you visit Ling.AI, create or sign in to an account, use the user console, buy or view packages, create API keys, call the API gateway, view billing, or use related support services.
This policy does not apply to third-party websites, upstream model providers, downstream applications, or external services you integrate. Their handling of information follows their own privacy policies and terms.
2. Personal information we collect
Account information: email, username, password hash, login state, review status, account permissions, packages, balance, API key metadata, allowlists, language preference, and contact information you provide.
Call and billing information: request IDs, timestamps, models, endpoints, input and output usage, charges, balance changes, package deductions, error codes, task status, usage logs, balance logs, quota, and reconciliation records.
Technical and security information: IP address, User-Agent, necessary request header fields, device and browser data, access path, session state, captcha result, rate-limit signals, risk-control events, system logs, and diagnostics.
API content information: to complete model calls, billing, troubleshooting, and security audit, the platform may process prompts, context, files, multimodal inputs, model parameters, upstream responses, and errors. Do not submit sensitive personal information, trade secrets, or regulated data unless you are authorized to do so.
3. How we use information
We use information for account registration and login, authentication, API key verification, model calls, provider routing, balance and package deductions, billing display, usage statistics, troubleshooting, risk control, security audit, support, and service improvement.
We process information on a minimum-necessary basis and try to avoid long-term retention of request content when it is not needed. Retention periods for logs, cache, audit records, and billing records may vary by system configuration, legal requirements, and dispute needs.
We do not sell your personal information. We do not disclose it to unrelated third parties except to provide the service, with authorization, to comply with law, to handle security events, or to protect legitimate rights.
4. Third-party processing and forwarding
To complete AI model requests, the platform may forward necessary request content, context, files, model parameters, and authentication-related information to upstream model providers, cloud infrastructure, network services, storage services, or security services based on routing strategy.
Third-party model providers may process inputs and outputs according to their own policies. You should confirm that your data is suitable for processing by the relevant provider and provide any necessary notice and consent in your downstream product.
When required by law, regulation, judicial order, or administrative request, the platform may provide necessary information as required.
5. Cookies and local storage
The platform may use cookies, sessions, local storage, or similar technologies for login state, language preference, security checks, captcha, CSRF protection, and basic access statistics.
You can manage cookies through browser settings, but disabling necessary cookies may break login, console, registration, captcha, or security functions.
6. Security
The platform uses access controls, key management, log audit, transport security, permission isolation, anomaly monitoring, and necessary masking measures to protect information.
No internet service can be absolutely secure. You should also protect your account, password, and API keys, restrict key scope, and promptly delete or rotate keys that may be exposed.
If an information security event may affect your rights, the platform will take remedial action and notify affected users through reasonable means as required by law.
7. Your rights
Subject to applicable law, you may request access, correction, copy, export, deletion, withdrawal of authorization, account closure, restriction or refusal of certain processing, or an explanation of personal information handling rules.
To protect account security, the platform may require identity verification before handling these requests. Information that must be retained by law, is necessary for contract performance, billing audit, dispute handling, security risk control, or cannot be immediately deleted for technical reasons may be retained or restricted as necessary.
8. Minors
The platform is primarily intended for developers, companies, and organizations with appropriate legal capacity. Minors should use the service only with guardian consent and supervision.
If you believe personal information of a minor was submitted without proper authorization, contact us through the support channel published on the platform.
9. Updates and contact
The platform may update this policy for service, legal, compliance, upstream-policy, or data-handling changes. Material changes will be announced through the website, console, notice, or another reasonable method.
Continuing to use the service means you understand the updated policy. If you do not agree, stop submitting personal information or using the relevant service.
To exercise personal information rights or ask privacy questions, contact us through the support, administrator, or service channel published on the platform.