Epithre
Legal

Privacy Policy

Last updated: 2026-05-11 · Version 1.0

Summary

Epithre does not log or persist the content of your API requests or responses. We store only billing metadata (token counts, timestamps, costs) — never your prompts, never the generated text, never the images.

What we collect

CategoryExamplesRetention
Account dataEmail, hashed password, name (optional)Account lifetime + 30 days
API keysSHA-256 hash, prefix (first 12 chars), name, scopesAccount lifetime; revoked keys 90 days
Usage eventsTimestamp, model, endpoint, token counts, cost, latency, HTTP status — no content90 days
Billing eventsTopups, refunds, signup credits, adjustments7 years (tax/audit)
Audit logAdmin actions, key creation/revocation, suspensions365 days
Session dataJWT issued at login; stored in your browser localStorage24h (auto-expire)

What we DO NOT collect

How we use data

Third parties

Your prompts and outputs do flow through Epithre infrastructure (FastAPI gateway → backend inference servers in Jakarta data center). No third-party AI provider (OpenAI, Anthropic, Google, etc.) is in the request path. Our models are self-hosted.

For payment processing during the alpha period: we exchange invoices via email. Payment is via bank transfer or other methods you arrange directly with us — no payment processor sees your billing details unless you choose to use one. Stripe / Midtrans integration is planned for general availability.

Your rights

Data location

All servers physically located in Jakarta, Indonesia. We do not transfer data outside Indonesia.

Security

No system is perfectly secure. If you discover a vulnerability, please email hello@epithre.com with subject "Security disclosure".

Changes

We will email you 14 days before any material change to this policy.

Contact

hello@epithre.com