01 / Scope
Who and what this Policy covers
This Privacy Policy applies to information handled by the operator of WorldGate (“WorldGate,” “we,” “us,” or “our”) through the website, registration and login flows, dashboard, API gateway, support channels, billing features, and related services at worldgateapi.com.
It does not govern an independent third party’s own products or websites. When you use an upstream AI model, authentication platform, analytics tool, or payment method, that provider may process information under its own privacy terms as well.
02 / Collection
Information we collect
Information you provide
- Account information: email address, account identifier, authentication records, and account security settings.
- Billing information: billing country, selected payment method, top-up amount, currency conversion data, invoice and transaction identifiers, payment status, wallet address or payer information returned by a processor where applicable, and related support records. We generally do not receive full card, bank, PayPal, or other payment credentials.
- Support and security communications: your email, message, attachments, and any information you choose to provide when asking for help or reporting an issue.
Information generated by use
- API and usage records: account and key identifiers, key name, endpoint, selected model, input/output/cache/total token counts, calculated cost, request status, latency, and timestamps.
- Technical records: IP address, user agent, request metadata, network and error information, security events, rate-limit state, and logs needed to operate and defend the Service.
- Website analytics: page views, referring page, approximate location derived from IP, device/browser information, and conversion events such as registration-link clicks. Analytics events are designed not to include prompt content or API keys.
- Fraud-prevention information: network-derived fingerprints, payment reconciliation data, promotion eligibility signals, and evidence relevant to suspected abuse.
We may also receive information from providers involved in authentication, infrastructure, analytics, payments, currency conversion, model routing, or fraud prevention.
03 / API content
Prompts and model outputs
To provide the API, WorldGate receives your request content and transmits it to the infrastructure serving the selected model. Responses pass back through our gateway to you. This processing can include messages, system instructions, files or encoded data included in a supported request, tool definitions, and model output.
WorldGate’s account usage ledger is designed to store metering data—not prompt or response text. Request content is nevertheless processed in transit by our runtime and the relevant upstream provider. Infrastructure and upstream providers may temporarily process or retain request data for security, abuse prevention, debugging, or legal compliance under their own terms and configurations.
Do not submit passwords, private keys, payment credentials, health records, government identifiers, children’s data, or other sensitive information unless you have a lawful basis, have assessed the upstream provider, and have implemented safeguards appropriate to the risk.
04 / Use
Why we use information
- create and authenticate accounts, issue and revoke API keys, and provide the dashboard and API;
- route requests, return outputs, measure tokens, calculate charges, reserve and settle usage, apply promotions, and maintain balances;
- process, confirm, reconcile, and support top-ups and payments;
- monitor availability, diagnose failures, improve compatibility, and understand aggregate service use;
- prevent fraud, abuse, credential compromise, prohibited activity, chargebacks, and attacks;
- communicate about support, security, transactions, material service changes, and policy updates;
- comply with law, enforce our Terms of Service, establish or defend legal claims, and protect users, providers, WorldGate, and the public; and
- create aggregated or de-identified statistics that no longer reasonably identify an individual.
We do not sell personal information for money. We do not use prompt or response text to build advertising profiles. If those practices change, we will update this Policy before applying the change.
05 / Legal bases
Grounds for processing
Where data-protection law requires a legal basis, we rely on one or more of the following: performance of our contract with you; our legitimate interests in operating, securing, improving, and protecting the Service; compliance with legal obligations; protection of vital interests where applicable; and consent when required. You may withdraw consent at any time, without affecting earlier lawful processing.
If you use WorldGate for an organisation and submit personal information in API content, you generally decide the purpose and means of that submission and are responsible for notices, legal bases, rights requests, and any processor agreement required by law.
07 / Transfers
International processing
WorldGate serves users internationally and relies on providers operating in multiple countries. Your information may therefore be processed outside your country, including where privacy laws differ. Where required, we use recognised transfer mechanisms or other safeguards and assess the circumstances of the transfer.
08 / Retention
How long information is kept
We keep information only for as long as reasonably necessary for the purposes described here, including providing the Service, maintaining transaction and usage records, resolving disputes, preventing fraud, enforcing agreements, and meeting tax, accounting, or legal duties.
- Account, balance, API-key metadata, and usage records are generally retained while the account is active and for a reasonable period afterward.
- Payment and invoice records may be retained for the period required by financial, tax, anti-fraud, and dispute obligations.
- Security and diagnostic logs are generally retained for shorter operational periods unless an event requires longer investigation.
- Support records are retained while useful to resolve the request and establish what action was taken.
Retention may be extended for a legal hold, active dispute, fraud investigation, or binding legal requirement. Backup deletion may occur on a delayed cycle.
09 / Your choices
Access, correction, deletion, and objection
Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection; withdraw consent; or complain to a data-protection authority. These rights can be limited—for example, where records must be retained for security, billing, legal claims, or law.
Send a request from your account email to support@worldgateapi.fun. We may verify your identity and authority before acting. If an authorised agent submits a request, we may require proof of authorisation and direct verification with the account holder.
You can revoke API keys from the dashboard, limit website storage through browser controls, and stop analytics requests using supported browser or network privacy controls. Blocking essential authentication storage may prevent the dashboard from working.
10 / Security
Safeguarding information
We use technical and organisational measures intended to protect information, including credential signing, access controls, row-level data separation, request and concurrency limits, transport security, restrictive browser headers, payment verification, logging, and credential revocation. Our Security page describes these controls and how to report a vulnerability.
No internet service is completely secure. You are responsible for protecting account credentials and keeping API keys in trusted server-side environments. Notify us promptly if you suspect compromise.
11 / Children
Not directed to children
The Service is intended for developers and organisations and is not directed to children under 13. We do not knowingly collect personal information directly from a child under 13. Users below the age of legal majority must have permission and supervision from a parent or legal guardian. If you believe a child provided personal information improperly, contact us so we can investigate.
12 / Changes
Updates to this Policy
We may update this Policy as the Service, providers, or law changes. We will post the revised version here, change the effective date, and provide additional notice where required. Material changes apply prospectively.
13 / Contact
Privacy requests and questions
Email support@worldgateapi.fun. Identify the account involved and the country or region relevant to your request. Never include a password, full API key, authentication code, or payment credential.