Skip to content

Latest commit

 

History

History
148 lines (90 loc) · 8.52 KB

File metadata and controls

148 lines (90 loc) · 8.52 KB

Privacy Policy

Last updated: 10 July 2026

This Privacy Policy explains how LLM7.io (“we”, “us”, “our”) collects and processes your personal data when you use our educational and research-oriented website and API, including dash.llm7.io. We operate from the United Kingdom and comply with the UK GDPR and, where applicable, the EU GDPR. Access to the API requires an API token issued via dash.llm7.io.


1. Controller contact

Controller: LLM7.io (operated by an individual)
Email: support@llm7.io


2. Data we collect

Account & authentication

  • Email address from Google OAuth at sign-in/registration.
  • Minimal OAuth metadata required to verify your sign-in (e.g., email_verified).

Tokens, subscriptions & usage (service operation)

  • Token issuance/revocation, expiry, status.
  • Subscription plan selection/status (e.g., Free, Pro), renewal dates, and applied promotions (e.g., promo codes).
  • Usage counters/quotas and timestamps for rate-limiting, abuse prevention, reliability, and troubleshooting.
  • Basic performance/error metrics.
  • Fraud-prevention signals, such as account, token, usage, billing, payment-status, chargeback, device, network, and security-event metadata used to detect unauthorised payment activity, account farming, limit evasion, or abuse.

Network & security

  • Our edge provider (Cloudflare) may process IP addresses, timestamps, and security/event logs to deliver and protect the service.

Referral Programme

  • If you opt in after opening a referral link, we store the referral code in browser local storage and a first-party .llm7.io cookie for 30 days. If you create a new account during that period, we record the relationship between the referrer and the new account, the registration time, successful referred top-ups, and promotional credits awarded.

We do not intentionally collect special category data. We do not sell personal data.


3. Purposes and legal bases

  • Provide and operate the educational and research-oriented service (account, sign-in, token management, subscriptions, API access, experimentation with LLM workflows, and programmatic interaction with LLM functionality). Legal basis: Contract (Art. 6(1)(b)).

  • Secure, monitor, and improve the service (rate-limits, fraud/abuse prevention, reliability, debugging).
    Legal basis: Legitimate interests (Art. 6(1)(f)).

  • Detect, prevent, investigate, and respond to fraud, unauthorised payment activity, account farming, limit evasion, chargebacks, abuse, and security incidents. Legal basis: Legitimate interests (Art. 6(1)(f)) and, where applicable, Legal obligation (Art. 6(1)(c)).

  • Operate the Referral Programme (store your chosen referral attribution, associate a new account with a referrer, calculate promotional credits, and prevent referral fraud). Legal basis: Consent for browser storage and legitimate interests for the server-side programme record and fraud prevention. You can refuse the attribution prompt or clear the browser storage before registration; a recorded referral relationship cannot be reassigned to another referrer.

  • Legal compliance (e.g., responding to lawful requests).
    Legal basis: Legal obligation (Art. 6(1)(c)).

  • Billing/fulfilment (processing subscription status and promotions; payment is handled by our payment processor—card details are not stored on our servers).
    Legal basis: Contract (Art. 6(1)(b)).

  • Communications (see Section 6).
    Legal basis: Contract (transactional/service emails) and Consent (optional updates), or Legitimate interests where permitted with a clear opt-out.


4. Storage, processors, and international transfers

We use Cloudflare for hosting, storage, networking, and security and act as the data controller while Cloudflare acts as our processor under its DPA and GDPR programme:

Data may be transferred internationally. We rely on appropriate safeguards (e.g., Standard Contractual Clauses and the UK Addendum) as implemented by Cloudflare.


5. Sharing

We share personal data only with:

  • Service providers/Processors (primarily Cloudflare) strictly to operate the service; and
  • Payment processors, card networks, banks, financial institutions, fraud-prevention services, and other parties involved in payment processing or fraud prevention, where necessary to process payments, investigate disputes, prevent abuse, or protect the service and affected parties; and
  • Public authorities, courts, regulators, law enforcement, and other competent bodies if required by law or where we reasonably believe disclosure is necessary and lawful to report, prevent, investigate, or respond to fraud, unauthorised payment activity, security incidents, or other unlawful activity.

6. Communications

We send:

  • Transactional/service emails required to operate your account (e.g., authentication, security notices, incident updates, material changes to the service/terms). These are not marketing and generally cannot be opted out without closing your account.
  • Optional updates and announcements (e.g., new models, features, or changes). You will receive these only with your consent or, where permitted by law, under legitimate interests with a clear opt-out. Every such email includes an unsubscribe link, and you can change preferences at any time.

We do not sell personal data.


7. Retention

  • Email & account data: retained while your account exists.
  • Token/usage logs: retained only as necessary to operate, secure, and account for the service.
  • Deletion: upon verified request or account deletion, we aim to delete or anonymise personal data within 30 days; residual backups are purged within up to 90 days.

8. Your rights

Depending on your location (UK/EEA), you may have rights to access, rectify, erase, restrict, portability, object (for legitimate interests), and to withdraw consent (for consent-based processing).
To exercise your rights, contact support@llm7.io.
You may lodge a complaint with your local authority. In the UK: ICOhttps://ico.org.uk/.


9. Cookies and similar technologies

We use strictly necessary cookies/edge storage for authentication, security, and core operation. Google OAuth and Cloudflare may set cookies required for sign-in and security. We do not use third-party advertising cookies.

Where you open a referral link, we ask for your consent before storing the referral code in local storage and a first-party .llm7.io cookie for 30 days. Refusing consent does not affect ordinary access to the Service, but we cannot apply the referral attribution. You can withdraw consent by clearing the relevant browser storage; this does not remove an attribution already recorded at account creation.


10. Automated decision-making

We use automated rate-limiting, fraud-prevention, and abuse-prevention systems. These systems may temporarily or permanently restrict requests, tokens, accounts, payment profiles, or API access where they detect suspected fraud, unauthorised payment activity, account farming, limit evasion, abuse, or security risks. We may also review these decisions manually where appropriate.


11. Children

The service is not directed to children. If you are under 13 (or the minimum age in your country), please do not use the service. If we learn we have collected data from a child, we will delete it.


12. Changes to this Policy

We may update this Policy. The latest version will be posted here with a new “Last updated” date. Material changes will be communicated reasonably (e.g., site notice). Continued use after updates means you accept the revised Policy.


13. Related documents


14. Contact

Questions or requests: support@llm7.io