Skip to content
APMIX.AI

Privacy Policy

Last updated 15 September 2026

apmix.ai is operated by Nomvel (nomvel.com), which is the data controller for everything described here; write to support@apmix.ai for anything about your data. We collect what is needed to run an API subscription and nothing more. This page explains exactly what that is, and what happens to the text you send through the API.

01What we collect

We collect information in three ways: from your sign-in provider, from how you use the API, and from payments.

  • Account: your email address, and the name and avatar shared by Google or GitHub if you sign in with them.
  • API keys: created by you in the dashboard. We store a one-way hash of each key, never the key itself, so we can authenticate your requests without being able to read them back.
  • Usage metering: for every request, the model, the number of input and output tokens, the weighted total, a timestamp, the key that was used, and the tool that made the call as it identifies itself in its own request headers.
  • Support tickets: the subject and messages you write, plus anything you add such as a page name or a request id.
  • Promotions: if you submit a post to claim extra tokens, the link to that post and the social handle you tell us you posted from.
  • Billing: your plan, invoices and payment status. Card details are handled by our payment processor and never touch our servers.
  • Technical logs: IP address, request status and timing, kept briefly for security and debugging.

02Your prompts and completions

The content you send (prompts, files, tool calls) is transmitted to the upstream infrastructure that serves the model you selected so it can produce the answer, and the answer is streamed back to you. Depending on the model, that is either the model's own vendor or an intermediary we buy capacity from; either way it is processed under an API agreement that excludes training on the traffic we send.

apmix does not use your content to train models, does not sell it, and does not keep it beyond what is needed to complete the request. Only metering data described above is retained.

03How we use the data

  • To run the service: authenticate keys, route requests, count usage and enforce plan allowances.
  • To bill you and send receipts, sign-in links and important account emails. We do not send marketing email.
  • To keep the service safe: detect abuse, multiple accounts, leaked keys and attacks.
  • To help you when you contact support.

04Who we share it with

We share data only with the companies that help us deliver the service, and only what they need:

  • The upstream infrastructure serving each model receives the content of the requests you route to it. Models are served either by their vendor (OpenAI, Anthropic, Google, xAI, DeepSeek, Alibaba, Z.ai, Moonshot, MiniMax, Xiaomi, Tencent) or by an intermediary we buy capacity from.
  • Our payment processor handles cards, Apple Pay and Google Pay.
  • Our email provider delivers sign-in links, receipts and support replies.
  • When you sign up, we send only the domain part of your address (never the address itself) to a disposable-mailbox lookup service, to check it is not a temporary inbox.
  • Our hosting and database providers store the data described on this page.

05Cookies and local storage

We set the cookies Auth.js needs to sign you in and keep you signed in, and a cookie remembering the language you chose. Your light or dark theme choice is stored in your browser's local storage. There are no advertising or cross-site tracking cookies, and nothing here follows you to other sites.

06How long we keep it

  • Account data: while your account exists. Deleting your account removes it immediately, along with your keys, usage history, support tickets and promotion submissions.
  • Usage metering: 12 months, so you can review past periods and we can resolve billing questions. Older records are deleted automatically.
  • Support tickets: kept while your account exists, so the history stays readable after a ticket is closed.
  • Billing records: as long as tax law requires.
  • Technical logs: up to 30 days.

07Your rights

You can see, correct, export or delete your data. Most of it is available in the dashboard; for anything else, email support@apmix.ai and we will respond within 30 days. If you are in the EU, UK or a region with similar law, you also have the right to complain to your data protection authority.

08Security

All traffic is encrypted in transit. Access to production data is limited to the people who need it to run the service. API keys are shown in full only once, when created, and can be revoked at any time.

09Changes

If we change this policy in a way that matters, we will tell you by email or in the dashboard before it takes effect. The date at the top shows the current version.