Legal information
Privacy policy
Updated: June 2, 2026
Codex API processes only the data needed to run accounts, API access, balance accounting, security, and user support.
Operator and contacts
Service operator: Codex API Staging. Jurisdiction: Российская Федерация.
For privacy and deletion requests, contact support: https://t.me/VIDADS_RU_SUPPORT.
Data we process
Account data: email, optional name, role, creation date, password hash, and signed browser session.
API access data: key prefix, SHA-256 key hash, status, creation/revocation dates, and raw key when repeat display is enabled in the dashboard.
Billing and audit data: token balance, usage events, request ID, route, model, status, latency, error code, and charged amount.
Integrations: Telegram proof for bonuses, referral links, and operator balance adjustments.
AI image data: prompts are sent to the upstream provider for generation, and generated files may be cached temporarily for download.
Data we do not store by default
Gateway request logs do not store full prompt or response bodies by default.
Chat history stays in the user's client unless that client is configured differently.
Why we process data
To create accounts, verify passwords, issue API keys, authorize gateway requests, and protect access.
To calculate usage, charge balances, display logs, diagnose errors, and prevent abuse.
To handle support requests, balance adjustments, refunds, bonuses, and referral operations.
Processors and providers
AI model requests are sent to upstream providers that technically process request content to return model output.
Hosting, database, Telegram, and payment/support channels may process data only within their operational role.
Retention
Accounts, keys, balances, and usage ledgers are stored while needed for the account, financial accounting, security, or obligations.
Temporary AI image assets are removed according to the configured cache lifetime or storage maintenance.
Backups and infrastructure logs are removed according to the production retention schedule.
User rights
A user may request access to their data, correction of profile data, API key revocation, account deletion, or review of a disputed operation.
If a request affects financial accounting, security, or mandatory logs, some data may be retained until the required period ends.