Data policy
What data moves through NapKey
A plain-language description of data required to operate accounts, proxy requests and reconcile prepaid usage.
Account data
NapKey stores your email address, password hash, verification state and account timestamps to operate authentication and account recovery.
Prompts and responses
Prompt and response content passes through the gateway and configured upstream provider. Full prompt payloads are excluded from production request debug logs. Responses API stored-response files contain input, instructions and output; they become eligible for deletion after 30 days and are removed by hourly and startup cleanup. Do not send secrets or regulated data unless your own risk assessment permits it.
Usage metadata
NapKey retains request ID, API key identifier, model, token counts, cost, latency, status and time for billing, support and reconciliation.
Payment records
Top-up orders and bank webhook events retain transaction references, amounts, processing status and reconciliation metadata. Payment payloads are restricted to operational access.
Cookies
The console uses secure session and CSRF cookies for sign-in and request protection. NapKey does not add advertising pixels or third-party behavioral analytics.
Your choices
You can revoke API keys at any time and change your account password. Contact support before sharing sensitive diagnostic material; always redact API keys and credentials.