Skip to main content

Universe Privacy Policy

Last updated: June 5, 2025

Effective date: June 5, 2025


Preface

The operator of the Universe API platform (hereinafter referred to as "we," "us," or "the Platform") recognizes the importance of personal information and privacy protection. This Privacy Policy is intended to inform you about how we collect, use, store, share, and protect your personal information when you use the Universe API service, as well as the rights you are entitled to.

Please read and fully understand this Privacy Policy in its entirety before using this service. If you do not agree with any part of this policy, please discontinue use of the service.


1. Information We Collect

1.1 Account Registration Information

When you register for and use the Universe API service, we may collect the following information:

Information TypeSpecific ContentPurpose of Collection
Basic Account InformationPhone number, email address, username, password (stored encrypted)To create and manage your account
Identity Verification InformationFull name, national ID number, company name, unified social credit codeTo comply with legal and regulatory real-name requirements
Contact InformationMailing address, contact phone numberFor customer service and billing notifications
Payment InformationPayment methods, transaction records, invoice informationTo process top-ups, billing, and invoice issuance

1.2 Service Usage Information

When you use the Universe API service, we may automatically collect the following information:

Information TypeSpecific ContentPurpose of Collection
API Call LogsRequest timestamps, model version invoked, request status codes, token consumptionFor billing, service monitoring, and troubleshooting
Request MetadataAPI Key identifier, request IP address, User-Agent, request frequencyFor security auditing, anti-fraud, and rate limiting management
Console Operation LogsLogin times, user actions, configuration change recordsFor account security auditing and anomalous behavior detection
Device and Network InformationBrowser type, operating system, IP address, network carrierFor service optimization and security protection

1.3 API Input and Output Data

  1. Input Data (Prompt): The text content and request parameters you submit through the API.
  2. Output Data (Completion): The response content generated by the model based on your request.

Important Notice: We process input and output data only for the duration necessary to provide the API service response. For details on how this data is processed, please refer to the "How We Use Information" section below.


2. How We Use Information

2.1 Service Provision and Operations

We use the collected information for the following service purposes:

  1. Account Creation and Management: Processing registration, login, authentication, password recovery, and related operations.
  2. API Service Delivery: Processing your API requests and returning model-generated response results.
  3. Billing and Finance: Billing based on your token consumption, processing top-ups and refunds.
  4. Customer Service: Responding to your inquiries, handling support tickets, and providing technical assistance.
  5. Service Notifications: Sending essential notifications regarding service changes, system maintenance, pricing adjustments, etc.

2.2 Security and Compliance

  1. Security Protection: Detecting and preventing fraud, abuse, unauthorized access, and other security risks.
  2. Compliance Auditing: Conducting information retention and auditing in accordance with legal and regulatory requirements.
  3. Content Security: Performing safety reviews of API inputs and outputs to prevent the generation and dissemination of illegal or non-compliant content.

2.3 Service Improvement

  1. Performance Optimization: Analyzing system operational data to optimize service stability, response speed, and model quality.
  2. Statistical Analysis: Performing de-identification on usage data and conducting overall service usage trend analysis.

Regarding Model Training: We do not use your API input data or output data to train or improve our foundation models. If we introduce a voluntary data improvement program in the future, we will only use de-identified data after obtaining your explicit consent.


3. Cookies and Similar Technologies

When you visit our console website, we may use cookies and similar technologies (such as Local Storage) to:

Cookie TypePurpose
Essential CookiesMaintaining login status, session management, security verification
Functional CookiesSaving your preference settings (e.g., language, theme, etc.)
Analytics CookiesUnderstanding console usage patterns to help improve user experience

3.2 Managing Cookies

You can manage or disable cookies through your browser settings. However, disabling essential cookies may result in certain features not functioning properly.


4. Information Sharing and Disclosure

4.1 No Proactive Sharing

We do not sell, rent, or otherwise proactively share your personal information with third parties for their own marketing purposes.

4.2 Necessary Sharing

We may share your information under the following circumstances:

Sharing ScenarioDescription
Affiliated CompaniesFor the purpose of providing services, we may share necessary information with our affiliated companies. Recipients must comply with equivalent data protection obligations.
Service ProvidersFor the provision of infrastructure services such as payment processing, SMS verification, and cloud storage, we may share necessary information with cooperating third-party vendors.
Legal RequirementsIn accordance with applicable laws and regulations, court orders, government authority requests, or where necessary to safeguard the public interest.
Protection of RightsTo protect the personal or property safety of us or the public from significant harm.

4.3 Information Sharing Principles

  1. All information sharing adheres to the principle of "minimum necessity," sharing only the minimum information required to achieve the intended purpose.
  2. We require third parties who receive your information to assume equivalent protection obligations and prohibit them from using the information for purposes beyond the authorized scope.

5. Information Storage and Security

5.1 Storage Location

Your personal information and API data are stored on servers located within the People's Republic of China. If cross-border data transfer is required for business purposes, we will conduct the corresponding security assessment procedures in accordance with the law and obtain your consent.

5.2 Retention Periods

Data TypeRetention Period
Account InformationRetained for the duration of the account; upon cancellation, retained for the minimum period required by law
API Call LogsRetained for no more than 180 days (for billing and troubleshooting purposes)
API Input/Output DataProcessed only transiently during service response; not retained long-term (unless otherwise required by law)
Console Operation LogsRetained for no more than 180 days
Transaction RecordsRetained for at least 5 years as required by applicable laws and regulations

5.3 Security Measures

We employ industry-standard security measures to protect your information, including but not limited to:

Security MeasureDescription
Transmission EncryptionAll API communications and console access are transmitted using TLS encryption
Storage EncryptionSensitive data (e.g., passwords) is stored in encrypted form; passwords use irreversible hashing algorithms
Access ControlStrict data access permission management; only authorized personnel may access relevant data when necessary
Security AuditsRegular security assessments and vulnerability scans
Incident Response PlanEstablished emergency response mechanism for data security incidents

Although we have implemented reasonable security measures, please understand that the internet environment is not 100% secure. In the event of a personal information security incident, we will promptly notify you in accordance with applicable laws and regulations.


6. Your Rights

Under applicable laws and regulations, you have the following rights regarding your personal information:

6.1 Access and Copy

You have the right to access your account information, billing records, and API usage records through the console. If you need to obtain a copy of your personal information, please submit a request through our customer service channels.

6.2 Correction and Supplementation

When you find that the personal information we hold about you is inaccurate or incomplete, you have the right to request correction or supplementation. You can modify certain information yourself through the account settings in the console, or contact us for assistance.

6.3 Deletion

You have the right to request that we delete your personal information under the following circumstances:

  1. The processing purpose has been achieved or can no longer be achieved;
  2. We have ceased providing the service or the retention period has expired;
  3. You have cancelled your account;
  4. You have withdrawn your consent and there is no other lawful basis for processing.

Information that is required to be retained by applicable laws and regulations will be deleted or anonymized upon expiration of the statutory retention period.

For information processing activities conducted based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the validity of processing activities carried out prior to the withdrawal.

6.5 Account Cancellation

You have the right to cancel your account at any time. Please note the following before cancellation:

  1. Please ensure that your account balance has been zeroed out or properly handled;
  2. After cancellation, your API Key will become invalid and API services will be terminated immediately;
  3. Your personal information will be deleted or anonymized in accordance with applicable laws and regulations;
  4. Account cancellation is irreversible.

6.6 Response Timeframe

We will respond to your rights request within 15 business days of receipt. If we are unable to complete the request within this period due to reasonable causes, we will explain the situation and extend the processing period as appropriate (up to a maximum of 30 business days).


7. Protection of Minors

  1. This service is intended for developers and enterprise users. If you are a minor under the age of 18, please read this policy under the guidance of a guardian and use this service only with the consent of your guardian.
  2. We do not knowingly collect personal information from minors. If we discover that information from a minor has been collected without guardian consent, we will promptly delete it.
  3. If a guardian discovers that a minor has been using this service without consent, please contact us to address the matter.

8. Updates to This Privacy Policy

  1. We may revise this Privacy Policy from time to time. The updated policy will be published on the platform.
  2. For material changes that involve a substantial reduction of your rights, we will notify you in advance through platform announcements, console messages, or email.
  3. If you continue to use this service after the Privacy Policy is updated, you will be deemed to have accepted the updated Privacy Policy. If you do not agree with the updates, you should discontinue use of the service.

Material changes include but are not limited to:

  • Changes to the purposes of personal information processing;
  • Changes to the types of personal information being processed;
  • Significant changes to how personal information is used;
  • Changes to cross-border transfers of personal information;
  • Substantial changes to data security protection measures.

This Privacy Policy is formulated in accordance with, among others, the following laws and regulations:

  • Cybersecurity Law of the People's Republic of China
  • Data Security Law of the People's Republic of China
  • Personal Information Protection Law of the People's Republic of China
  • Interim Measures for the Management of Generative Artificial Intelligence Services
  • Measures for the Administration of Internet Information Services
  • Regulations on Classified Protection of Cybersecurity

10. Contact Us

If you have any questions, comments, or suggestions regarding this Privacy Policy, or if you wish to exercise any of the rights described above, please contact us through the following channels:

  • Platform Console: Log in to the console and submit a support ticket
  • Technical Support: Refer to FAQ for assistance

We will respond to your request as soon as possible upon receipt.


Thank you for your trust in Universe. We remain committed to protecting your privacy and data security.