Legal

Privacy Policy

This Policy explains how BFC AI Gateway collects, uses, discloses, stores, and otherwise processes personal data in connection with the Services.

Last updated: August 24, 2026

1. Overview

This Privacy Policy describes how BFC AI Gateway collects, uses, stores, discloses, and otherwise processes information about people who access our website, APIs, dashboards, playgrounds, documentation, and related services (collectively, the “Services”).

This Policy applies when we process personal data as a controller for our own business operations. If you access the Services through an enterprise account or another customer-controlled environment, we may process certain personal data on that customer's behalf, subject to its instructions and applicable agreements.

2. Information We Collect

We collect information you provide, information collected automatically through your use of the Services, information received from third parties, and information generated or inferred while operating the Services. This may include:

  • Account and contact information, including your name, email address, company, role, billing contacts, and support communications.
  • API and service data, including prompts, uploaded files, request metadata, routing selections, model usage logs, job identifiers, and output retrieval events.
  • Technical information, including IP address, browser, device and operating-system information, timestamps, referrers, network details, and application logs.
  • Billing and transaction information, including subscription tier, credit usage, invoices, payment status, tax data, and limited information from payment processors.
  • Integration and third-party information, including identity-provider data, fraud-prevention signals, and account verification information where applicable.

3. Information We Collect Automatically

When you use the Services, we and our service providers may automatically collect device, usage, and diagnostic information needed to operate and secure them. This may include session identifiers, activity and latency logs, feature usage, API consumption patterns, system traces, and data from cookies or similar technologies used for authentication, analytics, performance measurement, visitor identification, and product improvement.

4. How We Use Information

We use personal data to provide, operate, maintain, secure, support, bill for, and improve the Services; communicate with you; comply with law; enforce our agreements; and protect the Services, users, and third parties. Uses may include:

  • Creating and managing accounts, organizations, and API access.
  • Routing and processing AI requests, including through third-party suppliers where applicable.
  • Monitoring performance, availability, abuse, reliability, security incidents, and billing accuracy.
  • Responding to support requests, technical notices, onboarding questions, and account communications.
  • Providing invoices, usage reports, fraud checks, credit controls, tax handling, and payment administration.
  • Analyzing usage, improving product features, and evaluating new infrastructure or supplier integrations.
  • Sending marketing communications where permitted by law and subject to your choices.

5. AI Inputs, Outputs, and Supplier Processing

Prompts, media, files, references, and other inputs submitted through BFC AI Gateway may be processed by us and relevant third-party model suppliers to provide the requested service or output.

Because the Services operate as a routing and integration layer, some requests may be sent to third-party infrastructure, model hosts, or service providers selected according to your workflow, product settings, contractual arrangements, or system routing logic. You are responsible for using the Services lawfully and for having authority to submit the relevant content.

6. Cookies and Similar Technologies

We and our service providers use cookies, local storage, pixels, SDKs, scripts, and similar technologies for authentication, session continuity, security, analytics, visitor identification, preference storage, marketing measurement, and service functionality.

You can control certain cookies through browser settings or available consent tools. Disabling them may affect sign-in, dashboard functions, performance analysis, or other features.

7. How We Disclose Information

We may disclose personal data to service providers, infrastructure partners, model suppliers, payment processors, professional advisers, enterprise customers, affiliates, and others as needed to operate the Services or comply with legal obligations, including:

  • Vendors and contractors supporting hosting, storage, analytics, visitor identification, communications, support, fraud prevention, observability, and payments.
  • Model and infrastructure providers needed to fulfill routed requests or integrated services.
  • Enterprise customers or administrators controlling an account, workspace, billing relationship, or organizational environment you use.
  • Regulators, courts, law enforcement, or other parties where required by law or reasonably necessary to protect rights, safety, or the Services.
  • Potential buyers, investors, or counterparties in a merger, financing, acquisition, or reorganization, subject to appropriate confidentiality protections.

8. Data Retention

We retain personal data for as long as reasonably necessary to provide the Services, maintain records, support customers, comply with legal obligations, resolve disputes, enforce agreements, and protect the Services. Retention periods depend on the information type, account configuration, enterprise agreements, legal requirements, fraud and billing needs, and ongoing operational requirements.

9. International Data Transfers

BFC AI Gateway and its service providers may process personal data in multiple countries. Where required, we use measures intended to support lawful transfers, such as contractual safeguards, organizational controls, or other legally recognized transfer mechanisms.

10. Your Choices and Privacy Rights

Depending on where you live and how you use the Services, you may have rights to access, correct, delete, or port data; object to or restrict processing; withdraw consent; or appeal certain privacy decisions. You may also manage account details, communications preferences, and some cookie settings through available browser, dashboard, or account controls.

  • Unsubscribe from marketing emails using the message link or by contacting us.
  • Request access to, correction of, or deletion of certain personal data, subject to legal exceptions and operational limitations.
  • If you are an enterprise user, direct certain requests to the organization controlling the relevant account or workspace.

11. Security

We use administrative, technical, and organizational measures intended to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure. No security measure is perfect, and we cannot guarantee absolute security.

12. Children’s Privacy

The Services are not directed to children and are not intended for people who are not legally permitted to enter into our Terms or use the Services under applicable law. We do not knowingly collect children's personal data in violation of applicable law.

13. Changes to This Privacy Policy

We may update this Policy from time to time. For material changes, we may provide notice through the Services, by email, through a dashboard, or by updating the effective date above. The updated Policy applies to your ongoing use after it becomes effective.

14. Contact Us

For questions about this Policy, privacy rights, data processing under an enterprise relationship, or a privacy request, contact us at contact@bayareafoundersclub.com.