Skip to main content

Privacy Policy

For PiAPI websites, APIs, dashboards, and AI services

Last updated: August 27, 2026

This Policy explains how Interastral Peace Limited (doing business as PiAPI) ("PiAPI," "we," or "us") handles personal data when you use piapi.ai and related services. If you use PiAPI for another person or expose it through your application, you are responsible for providing required privacy notices and obtaining a valid legal basis for that data.

1. Data we collect

Account and contact data: Name, email address, account identifiers, organization details, authentication information, preferences, and communications with us.

Billing data: Purchase, invoice, credit, subscription, and transaction records. Payment-card details may be collected directly by our payment provider rather than PiAPI.

AI service content: Prompts, instructions, uploaded images, video, audio, documents, private assets, generated Outputs, and associated task identifiers.

Face and identity-related assets: Images or media submitted for features involving a person's likeness, together with verification status and records needed to operate the Private Asset Library. Such material may be sensitive personal data under some laws.

Technical and usage data: IP address, browser and device details, timestamps, API endpoints, model and parameter selections, request status, token or usage counts, error and diagnostic logs, and security events.

Support and safety data: Support tickets, content reports, evidence, appeals, fraud signals, policy-review records, and communications concerning suspected abuse.

Cookies and analytics: Cookie identifiers and information about interactions with our Site, subject to available browser or consent controls.

Please do not submit personal data that is unnecessary for your task. The content you choose to include in an Input may reveal sensitive information even when PiAPI does not request it.

2. Sources of data

We receive data directly from you, your organization, your application or end users acting through it; automatically from devices and use of the Services; from payment, authentication, model, infrastructure, analytics, and security providers; and from persons submitting support, safety, or rights reports.

3. How we use data

  • Provide, authenticate, meter, bill, maintain, troubleshoot, and improve the Services.
  • Route requests to the selected model or infrastructure provider and return results.
  • Review private assets, operate safety controls, detect fraud or abuse, investigate reports, and enforce our terms.
  • Communicate about transactions, incidents, support, policy changes, and—where permitted—products or promotions.
  • Comply with legal obligations, respond to lawful requests, establish or defend legal claims, and protect users and the public.
  • Analyze aggregate service performance and plan product capacity and reliability.

4. AI processing and customer content

To fulfill a request, PiAPI may transmit Inputs and necessary technical data to the model or infrastructure provider selected by you or required for the requested feature. That provider processes the data to return an Output and may maintain limited logs under its applicable terms, legal duties, and security practices.

We may process prompts, uploads, Outputs, and task metadata to deliver the task, investigate errors, prevent abuse, review reported content, and enforce our policies. Automated safety systems may classify Inputs or Outputs. Where human review is used, access is limited to authorized personnel or service providers with a need to perform those functions.

PiAPI does not sell customer prompts, uploaded private assets, or Outputs. This Policy does not promise that customer content is used to train—or excluded from training by—every third-party model provider; provider-specific terms and product documentation should be reviewed before submitting confidential or sensitive material.

5. Face assets and sensitive data

Features involving faces, voices, likenesses, or identity-related material can involve biometric or other sensitive data depending on the jurisdiction and processing. You must have all required permissions and lawful bases before submission. Private Asset Library verification is a safety and eligibility step, not proof that consent or legal rights exist. We may retain verification status and related audit information for security, compliance, dispute handling, or legal obligations after an asset is removed.

6. Legal bases

Where laws such as the GDPR or UK GDPR apply, we process data as needed to perform our contract with you; pursue legitimate interests such as providing secure, reliable services, preventing abuse, and protecting legal rights; comply with legal obligations; protect vital interests where applicable; or based on consent. You may withdraw consent, but withdrawal does not affect earlier lawful processing.

7. When we disclose data

We may disclose relevant data to model and API providers, cloud hosting and content-delivery providers, payment processors, authentication providers, analytics and communications providers, customer-support and security vendors, professional advisers, and corporate transaction counterparties. We may also disclose data to authorities or other parties when reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate fraud or abuse, or enforce agreements. Providers receive only data reasonably needed for their functions and are subject to contractual or legal obligations where required.

8. International transfers

PiAPI is operated by a Hong Kong company and uses providers in multiple countries. Your data may be processed outside your country, where privacy laws may differ. Where required, we use recognized safeguards for restricted transfers, such as contractual protections, adequacy decisions, or another lawful transfer mechanism.

For transfers from the European Economic Area (EEA), the United Kingdom, or Switzerland to a country without an applicable adequacy decision, we use an approved safeguard such as the European Commission's Standard Contractual Clauses and, where applicable, the UK Addendum or International Data Transfer Agreement. We use supplementary measures where required and can provide information about the applicable safeguard on request.

9. Retention and deletion

We retain each category only as long as reasonably necessary for the purposes described here, including service delivery, account administration, billing and tax records, security, abuse prevention, backup cycles, dispute resolution, and legal compliance. Retention can vary by product, provider, account status, and legal hold. Deletion requests may not remove information that must be retained or data already de-identified or aggregated. Removing data from active systems may take time to propagate through backups.

10. Security

We use administrative, technical, and organizational measures designed to protect personal data, including access controls and security monitoring appropriate to the service. No transmission or storage system is completely secure. You are responsible for protecting API keys, limiting permissions, securing customer applications, and avoiding unnecessary sensitive data in prompts or logs.

11. Your privacy rights

Depending on your location, you may have rights to request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review of certain automated decisions. Under the GDPR or similar laws, these include:

  • Rectification: correction of inaccurate or incomplete personal data.
  • Erasure: deletion of personal data, subject to lawful retention exceptions.
  • Restriction: limitation of processing in circumstances provided by law.
  • Objection: objection to processing based on legitimate interests or for direct marketing, where applicable.

You may also have the right to opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or certain profiling. PiAPI does not sell personal data for money. To exercise a right, email support@piapi.ai. We may verify identity and authority, and authorized agents may be required to provide proof. You may appeal a denied request by replying to our decision. You may also complain to your local data-protection authority.

12. Do California residents have specific privacy rights?

California Civil Code Section 1798.83, also known as the "Shine The Light" law, permits our users who are California residents to request and obtain from us, once a year and free of charge, information about categories of personal information (if any) we disclosed to third parties for direct marketing purposes and the names and addresses of all third parties with which we shared personal information in the immediately preceding calendar year. If you are a California resident and would like to make such a request, please submit your request in writing to us using the contact information provided below.

If you are under 18 years of age, reside in California, and have a registered account with Services, you have the right to request removal of unwanted data that you publicly post on the Services. To request removal of such data, please contact us using the contact information provided below and include the email address associated with your account and a statement that you reside in California. We will make sure the data is not publicly displayed on the Services, but please be aware that the data may not be completely or comprehensively removed from all our systems (e.g., backups, etc.).

13. Cookies and communications

We may use essential cookies for authentication, security, preferences, and service operation, and analytics or marketing technologies where permitted. Browser controls can block or delete cookies, but essential features may stop working. You may unsubscribe from marketing using the link in a message; service, security, billing, and legal notices may still be sent.

14. Children

The Services are not directed to children and may be used only by adults who meet the eligibility requirement in our Terms. Do not submit a minor's personal data, likeness, or content unless the processing is lawful, necessary, age-appropriate, and supported by valid authorization. We may delete data and suspend accounts when we learn of unauthorized child data or exploitation.

15. Changes and contact

We may update this Policy to reflect changes in our Services, providers, or legal requirements. We will post the revised date and may provide additional notice for material changes. Privacy questions and rights requests may be sent to support@piapi.ai. The data controller for PiAPI's own service operations is Interastral Peace Limited, registered in Hong Kong.