Privacy Policy

Last updated: July 17, 2026

1. What we collect

Account data: your email address, a hashed password (or the email from your Google account if you sign in with Google), and your language preference.

Usage metadata: per-request token counts, model names, latency, status codes, and hashes of prompt-prefix blocks — used to compute hit rates, savings, and waste.

Provider API keys you register, encrypted at rest with AES-256-GCM and used only to forward your requests.

Billing data: your payment method is held by our payment processors (Stripe, or Toss Payments for Korean users) as a token. We never see or store full card numbers.

2. What we do not collect

We do not store the content of your prompts or responses. The one exception is the optional keep-alive feature: when you enable it, we store your prompt prefix — the system prompt, tools, and messages up to the last cache breakpoint — encrypted with AES-256-GCM, solely to re-warm your provider cache. Disable the toggle (or revoke the key) and the stored prefix is deleted immediately.

3. Why we process it

To operate the proxy and your dashboard, to compute performance-based fees, to send transactional email (verification, receipts) and — unless you opt out — a periodic savings report, and to keep the Service secure.

4. Retention

Account data is kept while your account exists. Request metadata is kept for as long as needed to provide analytics and billing history. When you delete your account, associated personal data is deleted or irreversibly anonymized within 30 days, except where law requires longer retention (e.g., billing records).

5. Sharing and processors

We do not sell personal data. We share data only with processors needed to run the Service: cloud hosting, payment processors (Stripe, Toss Payments), and our transactional email provider. Each processes data only on our instructions.

6. Security

All traffic is encrypted in transit (TLS). Provider keys and opt-in prompt prefixes are encrypted at rest with AES-256-GCM. For the hosted service, access to production data is restricted to a minimal set of operators.

7. Your rights

You can access, correct, export, or delete your data. Keys, provider keys, cards, and the account itself can be deleted directly in the console; for anything else, email support@caching.ai and we will respond promptly. You can opt out of report emails with one click in any report.

8. International users

The Service is operated from the Republic of Korea. By using it you understand your data is processed there and by the processors listed above.

9. Changes and contact

We will post updates to this policy here and, for material changes, notify you on the site or by email. Contact: support@caching.ai.

Caching.ai — Cut AI costs 90%