Privacy Policy

SpicyAPI (also written Spicy API) has been at spicyapi.com since June 2025, and only there. It is operated by Wayfinity Ltd and is not affiliated with spicyapi.ai or any other service using a similar name.

Last updated: 29 September 2026

🔒 Privacy Commitment

SpicyAPI.com ("SpicyAPI", "we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our API services (the "Services").

1. Data Controller

The data controller responsible for your personal information is:

Service: SpicyAPI.com

Contact Email: contact@spicyapi.com

2. Information We Collect

2.1 Information You Provide to Us

  • Account Information: When you register for an account, we collect your email address and account credentials (such as a hashed password).
  • Payment Information: We use third-party card and cryptocurrency payment processors. We do not store your full credit card details, but we may receive transaction identifiers and summary information.
  • Communications: If you contact us directly, we may receive additional information such as your name, the contents of your message, and any other information you may choose to provide.

2.2 Information We Collect Automatically

  • Usage Data: We collect information about your use of the Services, such as API requests, the endpoints you access, IP addresses, timestamps, and API usage statistics.
  • Device and Technical Information: We may collect information about the device and software you use to access our Services, including browser type and version.
  • Cookies: We use essential cookies for authentication, security, and basic site functionality. We do not use tracking or advertising cookies.

2.3 Content Data

  • API Inputs: We process the text prompts and parameters you submit through the API ("Input") to generate the requested content. The Services do not accept uploaded images or other media, except through character import as described below.
  • Imported Images:Where we have enabled character import on a customer account under Schedule 1 of the Terms of Service, we process the images that customer submits, together with their content hashes, file metadata (such as format, dimensions and any embedded camera data), the results of automated and human screening, and the customer's attestation (time, API key, terms version and any end-user identifier supplied). Customers warrant that imported images are wholly synthetic and contain no personal data. Imported images are analysed by automated vision systems, including to estimate apparent age and to detect photographs and recognisable people, solely to prevent prohibited content and abuse; this analysis is not used to identify anyone except to refuse an image that appears to show a recognisable real person.
  • Generated Content:We store the images, videos and audio the Services generate for you ("Output"), and the characters and voices you create, in your account library, so that you can retrieve them and reuse them as inputs. How long each is kept is set out in section 6.

2.4 Google Sign-In

  • What we receive: If you sign in with Google, we request only the basic scopes (openid, email and profile). Google shares your email address, name, profile picture and a unique Google account ID with us. We do not access your Gmail, Drive, contacts, calendar or any other Google data.
  • How we use it: We use this information only to create your account, sign you in, and contact you about your account. Your email address is stored with your account; your name and profile picture are kept by our authentication provider (Firebase Authentication) and are not used for anything else.
  • Sharing: We do not sell Google user data, use it for advertising, or share it with third parties, except the service providers that host our authentication and database, or where required by law.
  • Retention and deletion: We keep this data while your account is open. You can delete your account and its Google data at any time in Settings, under Security, or ask us to by emailing contact@spicyapi.com. You can also remove SpicyAPI's access at any time from your Google Account settings (myaccount.google.com/permissions).
  • Limited Use: SpicyAPI's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • To Provide and Maintain the Services: To operate our API, process your requests, manage your account, and process payments.
  • To Improve and Analyze the Services: To understand usage patterns, diagnose technical issues, and improve the performance and safety of our API. We may use Input and Output for these purposes.
  • To Communicate with You: To send you service-related announcements, technical notices, security alerts, and support messages.
  • For Security and Fraud Prevention: To monitor for malicious or prohibited activity, to screen imported images, and to enforce our Terms of Service. This includes checking that affiliate referrals are genuine by comparing hashed identifiers of the referred account and the affiliate: network address, a browser cookie, card brand, last four digits and expiry (from our payment processor), and checkout email.
  • To Comply with Legal Obligations: To comply with applicable laws, regulations, and legal processes, such as responding to lawful requests from public authorities.

4. Legal Basis for Processing (for EEA/UK Users)

If you are in the European Economic Area (EEA) or the UK, our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it. We process your data based on:

  • Contractual Necessity: To fulfill our contract with you to provide the Services.
  • Legitimate Interests: For our legitimate interests, such as improving the Service, security, and fraud prevention, provided these are not overridden by your data protection interests.
  • Legal Obligation: To comply with our legal duties.
  • Consent: Where we specifically ask for your consent for a processing activity.

5. Data Sharing and Disclosure

We do not sell your personal information. We may share your information with the following third parties:

  • Service Providers: We use third-party vendors for hosting, payment processing, content screening (prompts are sent to a classifier operated by TypeSafe AI, Inc. in the United States, which does not train on them, and generated and imported images are analysed by AI vision models run by our infrastructure providers), and analytics. These providers only have access to the information necessary to perform their functions and are obligated to protect it.
  • Legal Requirements:We may disclose your information if required by law, subpoena, or other legal process, or if we have a good faith belief that disclosure is necessary to protect our rights, your safety, or the safety of others. This includes reporting apparent child sexual abuse material and related account information to the National Center for Missing & Exploited Children, the Internet Watch Foundation, law enforcement or other competent authorities.
  • Business Transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction.

6. Data Retention and Deletion

6.1 Account Data: We keep your account information for as long as your account exists. When your account is deleted, we delete it within 30 days, except the records described in sections 6.3 to 6.6, which we must keep.

6.2 Generated Content and Your Library: Output, and the characters and voices you create, are kept for as long as your account exists, so that they remain available to you and can be reused as inputs. Deleting an item through the API or the dashboard removes it from your account and stops it being used as an input; the stored file is deleted when your account is deleted. We also delete Output that is removed under our Acceptable Use Policy or following a valid takedown request. Audio you send for transcription, and the audio and transcripts of live calls, are not stored. We do not use Input or Output to train AI models.

6.3 Request Records: For each API request we keep a record of the time, endpoint, model, status, cost, request parameters, links to the Output and the first 500 characters of the prompt or input text (for chat, of the last message; for transcription, of the transcript). These records are your usage and billing history and our evidence of legal compliance. They are kept for as long as your account exists and for six years after it is closed.

6.4 Moderation and Abuse Records: Records of declined prompts, withheld Output, strikes, abuse reports and takedowns, including the prompt, the screening scores and the content hash, are kept for as long as your account exists and for six years after it is closed, or longer where the law requires it or legal claims are pending. The content hash of withheld Output may be kept on a blocklist for as long as it is needed to refuse the same content again; a hash does not contain the content.

6.5 Imported Images: Imported images and their content hashes, metadata, screening results and attestation records are kept for as long as the character created from them exists and for six years afterwards, or longer where the law requires it or legal claims are pending, as evidence for legal compliance, abuse investigations and the establishment, exercise or defence of legal claims. Images that fail screening are deleted from our content delivery network; their hashes may be kept on a blocklist so the same file is refused again. Where the law requires it, material that appears to be child sexual abuse material, and related account information, is preserved and reported to the competent authorities.

6.6 Payment, Tax and Legal Records: Payment and invoice records, and records of your acceptance of our terms (with the time, IP address and browser), are kept for six years after the end of the financial year they relate to or after your account is closed, whichever is later, or longer where the law requires it.

6.7 Technical Logs:Records of failed API requests are kept for 30 days. Our hosting providers' server logs are kept for up to 12 months for security analysis and troubleshooting.

6.8 Deletion: You can delete your account and associated personal data yourself in Settings, under Security, or ask us to by contacting us. Deleting it signs you out, revokes your API keys and deletes your library straight away, and removes you from our mailing lists; we delete the rest within 30 days, except the records described in sections 6.3 to 6.6, which we keep only for the purposes stated there and delete at the end of those periods.

7. Data Security

We implement industry-standard technical and organizational measures to protect your information. This includes using encryption for data in transit (TLS) and at rest, access controls, and regular security reviews. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

8. International Data Transfers

Your information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country. We ensure that for any transfers of data to countries outside the UK/EEA, we put in place appropriate safeguards, such as Standard Contractual Clauses, to protect your data.

9. Your Data Protection Rights

Depending on your location, you may have the following rights regarding your personal information:

  • The right to access, update, or delete the information we have on you.
  • The right of rectification.
  • The right to object to our processing.
  • The right of restriction.
  • The right to data portability.
  • The right to withdraw consent at any time.

To exercise these rights, please contact us at contact@spicyapi.com. We will respond to your request in accordance with applicable law.

10. Age Restrictions

Our Services are intended exclusively for users who are 18 years of age or older. We do not knowingly collect personal information from individuals under 18. If we become aware that we have collected such information, we will take steps to delete it promptly.

11. Supervisory Authority

If you have concerns about our data practices, we encourage you to contact us first. However, you have the right to lodge a complaint with a data protection supervisory authority. For UK residents, the relevant authority is the Information Commissioner's Office (ICO).

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date. We encourage you to review this Privacy Policy periodically.

13. Contact Us

If you have any questions about this Privacy Policy, please contact us at: contact@spicyapi.com