Privacy
Privacy Policy
How Kanonas collects, uses, shares, protects, and retains information across the web portal, API gateway, model-call traces, provider-key storage, and prepaid billing.
This page is written for the Kanonas web portal and API gateway. It explains how the service handles accounts, provider keys, model requests, usage telemetry, traces, and billing.
Scope
This Privacy Policy explains how Kanonas collects, uses, and shares information when you use the Kanonas website, web portal, documentation, API gateway, billing flows, and related services.
Kanonas routes model requests to upstream providers such as OpenAI, xAI, Anthropic, Gemini, Z.AI, and compatible providers you configure. Upstream providers may process request and response data under their own terms and policies.
Information We Collect
We collect account information from Firebase authentication, such as your user identifier, email address, display name, and authentication state.
We collect configuration and security information needed to operate the gateway, including provider-key status, Kanonas API-key metadata, revoked key records, and authentication events. Provider keys are stored in Google Secret Manager. Kanonas API keys are shown once and stored as hashes.
We collect usage and observability information about model requests, including provider, model, endpoint, request timing, latency, response codes, token counts when available, cache usage, funding source, estimated spend, prepaid debits, API key identifiers, trace IDs, labels, feedback, and routing decisions.
For non-streaming model calls, Kanonas may store request and response payloads for authenticated trace review, debugging, quality review, and account observability. Large payloads may be stored in Cloud Storage and summarized in Postgres.
We collect account audit events for management actions such as provider-key changes, Kanonas API-key creation and revocation, project changes, billing-preference changes, checkout-session creation, and feedback updates.
For prepaid billing, we collect transaction metadata such as checkout session identifiers, customer email where available, top-up amounts, platform fees, ledger entries, balances, and Stripe webhook events. Payment card details are handled by Stripe and are not stored by Kanonas.
How We Use Information
We use information to authenticate users, operate the web portal, route API requests, manage provider keys and Kanonas API keys, record usage, show traces, calculate balances, process prepaid credits, secure the service, investigate errors, prevent abuse, and improve the reliability of the gateway.
We may use prompts, inputs, outputs, trace payloads, labels, feedback, routing decisions, usage records, and operational metadata to debug issues, evaluate model and routing quality, improve Kanonas features, improve product performance, tune heuristics, and develop new product capabilities.
We may use aggregated, de-identified, or derived operational metrics to understand system health, route coverage, costs, abuse patterns, product performance, and customer workflows.
How We Share Information
We share request data with upstream model providers as needed to fulfill API calls you initiate or configure. The provider receiving a request may depend on the model, saved provider keys, managed billing availability, and routing configuration.
We use service providers such as Google Cloud, Firebase, Cloud Storage, Secret Manager, Cloud Run, Firebase App Hosting, and Stripe to host, authenticate, store, secure, bill, and operate Kanonas.
We may disclose information when required by law, to protect rights and safety, to investigate abuse or security issues, or as part of a merger, acquisition, financing, or transfer of assets.
- Kanonas does not sell personal information.
- Kanonas does not use model request payloads for advertising.
- Kanonas does not intentionally share provider keys except as needed to make upstream requests you configure.
Your Controls
You can revoke Kanonas API keys and delete saved provider keys from the Settings page. You can review prepaid balances and usage from the Billing and Console surfaces, and you can review recent model-call traces from the Traces page.
If you need account deletion, export, or correction, contact the Kanonas operator through the channel where you received access or through the account support channel made available in the product.
Retention And Security
We retain information for as long as needed to provide the service, maintain account records, support billing, comply with legal obligations, resolve disputes, enforce terms, and preserve security and audit history.
Kanonas does not offer a zero-data-retention mode. Deleting keys or projects does not remove all historical usage, billing, trace, feedback, audit, security, legal, or operational records that Kanonas retains for the purposes described in this policy.
Kanonas uses technical and organizational safeguards designed to protect account data, provider keys, API keys, billing records, model-call data, and operational logs. No method of transmission or storage is completely secure.
Children
Kanonas is intended for developers, businesses, and technical users. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes
We may update this Privacy Policy from time to time. When we do, we will post the updated version on this page and revise the effective or last updated date.