Privacy policy

This policy covers the APIpk website, model tests and channel submissions. The maintainer uses this information to provide requested features, maintain the site and respond to feedback. Contact shanye1402@gmail.com about privacy.

Updated:

Browsing and preferences

Public prices and samples do not require an API key. Changing language or currency sets the apipk-language or apipk-currency cookie for one year to remember your choice. You can clear these cookies in your browser. Language suggestions also use browser language and country information supplied by the hosting platform.

The channel audit tool stores scope, view, model and currency preferences in browser localStorage until site data is cleared. These settings do not contain API keys.

Model tests and API keys

The key you enter is held in the current page’s memory, without being written to cookies, localStorage or the site database. Changing the API address clears the key. The site does not restore keys after you reload or leave the page.

When you generate an image, your browser sends the API address, key, model, prompt and image size to our server. The server handles the key during that request and forwards it in the Authorization header to your selected image provider. This requires our server to receive the key; it is not a direct browser-to-provider call.

The current generation implementation does not persist keys, prompts or generated images, or intentionally log request bodies, authorization headers or raw provider responses. This does not guarantee that hosting, network or provider services keep no logs. Their processing and retention follow their policies. Use keys with limited permissions and balances and avoid sensitive content.

Images and visual analysis

Returned images, prompts and comparisons are displayed in page memory. Your browser requests remote image URLs from the image host, which receives that request. Downloading images or exporting reports creates files on your device. Reports may include prompts, provider addresses, models and analysis results; protect these files.

Automatic visual analysis is currently restricted to authorized administrators. When enabled and run, the site sends the prompt, a reduced preview of the generated image and any reference preview to the configured vision service. The default is Volcengine Ark; check the service displayed on the page. The current analysis implementation does not write these inputs or results to the site database. The vision service handles received content under its own policies.

Visits and feature analytics

The site loads the Umami script from umami.hotbee.cn to measure visits and feature use. Analytics may include page URLs and query parameters, titles, referrers, browser, device, language and region information. Do not put keys, private prompts or other sensitive information in URLs or query parameters.

Our custom feature events attach only public model, provider, quote or specification identifiers, not keys, prompts, search text or other form input. Umami documentation describes its default analytics as cookieless. The site still uses the preference cookies described above and collects analytics data. A fixed retention period for this analytics instance has not been published.

Channel submissions and contacting us

For channel submissions, the database stores the full URL, hostname, time, record ID, notification status and a SHA-256 hash of the request source identifier and current date for deduplication, rate limiting and review. When Cloudflare supplies the relevant header, the source identifier is the request IP. Hashing does not make information impossible to identify. Do not include keys, private invitation credentials or personal data in submitted URLs.

When Feishu notifications are configured, the URL, hostname, time and ID are sent to the maintainer’s Feishu bot for review; the rate-limit hash is not sent. Submission records have no automatic expiry and remain stored for review and deduplication. Email the record ID or URL to request correction or deletion. Email or WeChat services also process your contact details and messages when you contact the maintainer.

Other services, retention and choices

Hosting, databases, analytics, image hosts, selected image providers, vision services and notification services may process data in different regions. Network requests may include IP addresses, timestamps and request metadata. The site has not verified every service’s regional log or backup retention and does not promise a common retention period or storage location.

You can clear cookies and site storage, block the analytics script using browser tools, skip model tests or avoid submitting channels. Blocking preference storage may prevent your choices from being remembered. Contact the maintainer to request access, correction or deletion of submissions and feedback held by the site. We may need to verify the record belongs to you and explain any specific reason a request cannot be fulfilled or a record must be retained. Do not send API keys for identity verification.

Updates and contact

We update the content and date of this page when features or processing change. Providers publish their own policies. Contact shanye1402@gmail.com about this policy, data handling or deletion requests.

Umami data documentation ↗