Data handling / October 6, 2026
Privacy, with clear boundaries.
Account and verification
Clydex uses Google authentication and a session cookie for account access; it does not offer a Clydex password. Account identity and session records are used to authenticate requests and enforce ownership. Telegram linking and subscription records support promotional eligibility and abuse checks. API keys are stored as verifiable hashes; a complete key is displayed to its owner only when created.
Prompts, responses, and usage
The Clydex gateway is designed not to persist prompt or completion bodies in its request history or normal logs. It keeps the metadata needed for access control, usage, billing, reconciliation, and auditing: request identifiers, model and pool, timing, token counters, status, amounts, and price references.
Generating a response requires processing request content. Details about all services involved in processing, retention periods, training use, and processing locations have not yet been finalized for this notice. The gateway’s storage behavior alone does not establish those terms. Setting store: false is not a promise about all processing or retention.
Payments and transferable codes
Purchase, payment confirmation, fulfillment, redemption, and financial records connect an order to its buyer and a redemption to its redeemer. A credit code needs recoverable encrypted storage so its buyer can view the same code again in protected purchase history. Lookup and redemption use a protected code reference. API keys and credit codes must not be placed in page URLs or ordinary analytics.
A buyer can see their order and the code’s redeemed status. Giving a code to another account does not give the buyer access to that account’s profile or balance. Payment information may be processed by the configured GM Pay service and relevant blockchain network; final processing disclosures are still required.
What a referrer can see
The referral view uses a pseudonymous identifier and shows progress, cumulative funded paid top-ups, and earned commission. This makes the 5% program inspectable. That view does not disclose a referral’s full email address, payment transactions, credit codes, prompts, or responses. A code purchase that has not been redeemed is not counted as a funded top-up in the referral view.
Retention, contact, and privacy requests
Final retention periods, account-deletion and data-request procedures, seller/controller identity, and a verified privacy contact are not yet published. These are launch requirements. This draft does not promise immediate deletion or indefinite retention.
When a support channel is published, start a report with an order/request identifier and correlation ID. Do not share your API key, a credit code, or your prompt by default.
