Privacy policy

Last updated: August 15, 2026

konata is run by an individual, called “we” or “the operator” in this policy. You can contact us at [CONTACT EMAIL].

This policy explains what data konata collects, why we collect it, and what happens to it. We have kept it short and specific so it is easy to read.

What we collect

Account details. We store the username you choose and a hash of your password. We never store the password itself. If you sign in with Telegram, we also store your numeric Telegram ID. We do not ask for or store your email address, phone number, or real name.

API tokens. We store the API tokens you create to use the gateway, along with each token’s name, expiry date, and spending limits.

Usage records. Each billed request creates a ledger entry. It records the model used, token counts (input, output, cache reads, and cache writes), the rates charged, which of your API tokens was used, and the time of the request. These entries make up the usage history in your dashboard.

Payment records. For each top-up, we store the amount, processing fee, payment status, and the payment processor’s invoice ID. We never see or store card numbers, wallet addresses, or other payment credentials. The payment processor handles those details entirely on its side.

Short-lived operational data. Like any internet server, we see the IP address that sends a request. We do not store it permanently. We use it only in short-lived, memory-style storage to limit request rates and prevent abuse, such as repeated login attempts or flooding. These records expire automatically within minutes or hours. They are never written to our permanent database or logs.

Cookies. We use a session cookie to keep you signed in for 30 days, a language preference cookie, and a timezone cookie so we can show dates in your local time. During Telegram sign-in, we also use short-lived cookies to secure the OAuth process. We do not use analytics cookies, advertising cookies, or trackers of any kind.

What we choose not to collect

The gateway forwards your API requests (prompts) and the model’s responses. It briefly processes them in memory so it can route requests and count tokens for billing. We never write prompt or response content to our database, disk, or logs. Your usage history shows models and token counts, but never content.

There is one exception: the built-in chat interface at [LINK]. If you use it, we store your conversations so you can return to them later. You can delete individual chats from the chat interface at any time. Deleting your account also deletes your chat history.

We do not change your traffic

Your requests and responses pass through the gateway as-is. Neither we nor our Partners inject or change content, instructions, or tool calls in either direction. Some AI gateways have been caught adding fake tool calls to model responses to take control of users’ machines. konata does not do this and never will.

The only exception is a change in format. If your client and the model use different API formats, the gateway translates between them. This changes how the request or response is represented, not its content.

Who we share data with

Model providers. We forward your API requests to the upstream AI provider serving the model you chose, such as Anthropic, OpenAI, or one of our Partners. We send the request body exactly as you provided it. We do not attach your identity, username, or account details.

The content itself may still include identifying details that you put there. For example, some coding tools add your email address or git identity to the prompts they send. The provider processes the content you send under its own terms and privacy policy.

Partners. Some models are served through partners. These are third parties that operate upstream provider accounts used by the gateway. A partner may have its own privacy policy, but the same promises apply on its side: partners never store prompt or response content and do not try to identify the person behind a request.

We do not attach account identity to traffic sent through a partner. Only identifying details in the content itself could reveal who you are, and partners do not inspect content for that or for any other reason.

Cloudflare. We use Cloudflare Turnstile on sign-in and registration pages to block bots. Cloudflare receives your IP address when it verifies the challenge.

Telegram. If you sign in with Telegram, the standard OAuth exchange takes place with Telegram. We store only your Telegram ID. We use your Telegram display name once to suggest a username, but we do not store it.

Payment processor. When you top up your account, the payment processor receives the payment amount and an opaque order ID. We do not send your username or any other account details.

We do not sell your data, share it with advertisers, or use it for anything other than running the service. We do not use third-party analytics.

How long we keep data

  • We keep your account details, API tokens, usage records, and payment records for as long as your account exists.
  • You can delete your account from your profile page. This immediately and permanently removes your account, tokens, balance, usage history, and payment records from the live database.
  • We keep encrypted backups for disaster recovery. They expire on a rolling schedule, and the longest-lived backups are kept for up to 12 months. Deleted data disappears from the backups as they expire.
  • If you used a promo code, we keep an anonymized redemption marker after account deletion. This code-to-identity link is used only to prevent the same code from being redeemed twice.

Security

All traffic is encrypted while it travels over the network. We store passwords as salted argon2 hashes. Only the operator can access production systems.

Your rights and choices

Your dashboard shows everything the service knows about you: your profile, tokens, and full usage and payment history. You can delete your account and all its data at any time without contacting us. For anything else, including data export requests or questions, contact [CONTACT EMAIL].

Changes to this policy

If we change this policy, we will publish the new version on this page and update the date above. We will announce material changes on the site.