Skip to main content

Data policy

What data moves through NapKey

A plain-language description of data required to operate accounts, proxy requests and reconcile prepaid usage.

Account data

NapKey stores your email address, password hash, verification state and account timestamps to operate authentication and account recovery.

Prompts and responses

Prompt and response content passes through the gateway and configured upstream provider. Full prompt payloads are excluded from production request debug logs. Responses API stored-response files contain input, instructions and output; they become eligible for deletion after 30 days and are removed by hourly and startup cleanup. Do not send secrets or regulated data unless your own risk assessment permits it.

Usage metadata

NapKey retains request ID, API key identifier, model, token counts, cost, latency, status and time for billing, support and reconciliation.

Payment records

Top-up orders and bank webhook events retain transaction references, amounts, processing status and reconciliation metadata. Payment payloads are restricted to operational access.

Cookies

The console uses secure session and CSRF cookies for sign-in and request protection. NapKey does not add advertising pixels or third-party behavioral analytics.

Your choices

You can revoke API keys at any time and change your account password. Contact support before sharing sensitive diagnostic material; always redact API keys and credentials.