Privacy Policy

Version 1.6.0Effective: September 15, 2026

한국어 버전 보기

1. Introduction

BROZ Corp. ("Company," "we," "us," or "our") operates everyais, a multi-cloud AI API gateway service available at everyais.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By accessing or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Account Information

When you register for an account, we collect:

2.2 Payment Information

Payment processing is handled by third-party processors (Polar.sh and Hecto Financial). We do not store your full credit card number or payment credentials. We receive transaction confirmation data such as payment status, amount, and transaction ID.

2.3 API Usage Data

When you use our API, we collect:

Usage logs do not include prompt or response bodies.

2.4 AI Input/Output Data

We do not collect prompts, completions, or generated media as a dataset. Bodies are held only as a 24-hour cache so you can retrieve outputs (presigned URLs). When that cache expires they are irrecoverably deleted from our databases and object storage. We do not use them for training, analytics, or any purpose other than delivering that request.

2.5 Device & Technical Data

We automatically collect technical information including browser type, operating system, IP address, device type, and referring URLs when you visit our website.

2.6 Cookies & Tracking

We use essential cookies for authentication and session management. Google Tag Manager and Google Analytics 4 are loaded only after explicit analytics consent; no cookieless analytics ping is sent before consent. Analytics covers acquisition, page, CTA, content, and completed lead interactions. It excludes user IDs, payment amounts, API keys, prompts, responses, and server-side activation events. You can reject or withdraw consent at any time through the "Privacy settings" control.

Analytics and advertising are optional. Privacy settings lets you allow or reject both together. Previously saved preferences remain in effect until you update them. Google consent states default to denied (analytics_storage, ad_storage, ad_user_data, ad_personalization), with ads_data_redaction enabled. GTM is loaded only after analytics consent. Advertising consent permits remarketing and first-payment conversion measurement, including the consented gclid, gbraid, or wbraid click identifier, transaction ID, purchase value and currency through Google Data Manager. everyais encrypts click identifiers and retains them for up to 90 days. Email, phone, address, API keys, prompts and responses are not sent for this measurement. Withdrawing advertising consent deletes local advertising identifiers and updates your account; if the account update fails, Privacy settings displays a retry control. Refusal does not affect API access.

2.7 Enterprise Inquiries

The inquiry form collects purpose, company name, business email, message, and consent version, plus optional contact name, budget range, and adoption timeline. It does not collect a telephone number.

3. How We Use Your Information

We use the information we collect to:

4. Data Retention

Data TypeRetention Period
Account dataDuration of account + legal retention period
AI input/output bodies (prompts, responses, media)Max 24-hour cache, then fully deleted. Not collected.
API usage logs90 days (model, tokens, time, cost — no bodies)
Anonymous marketing events90 days
Activation journey and server events24 months after last activity
Closed/spam inquiry PII180 days after last activity
Google Analytics data14 months
Payment recordsPer applicable tax and financial law

5. Data Sharing & Third Parties

We share your data only as necessary to provide the Service:

5.1 AI Cloud Providers

Your API input data (prompts) is forwarded to the selected AI provider for processing. These providers include AWS Bedrock, Google Gemini API, Nebius, Meta, and Z.AI. Each provider processes data according to their own privacy policies.

For Z.AI model requests, we entrust API input and output processing to JINGSHENG HENGXING TECHNOLOGY PTE.LTD (Z.AI) to perform inference and deliver results. API content is processed in real time without storage or use for model training. We do not consent to its use for model development or improvement.

5.1.1 Community suppliers (processing entrusted)

If you opt in to community supply, that request's inference may be entrusted to a third-party community supplier. This is off by default. You can turn it on or off (opt out) in dashboard settings at any time. We enter into a DPA with each supplier; they must delete prompts immediately after processing and must not store or train on them. On everyais, prompt and response bodies are still not collected and are fully deleted after the 24-hour cache.

We do not provide your input or output data to any provider for AI model training or retraining unless you explicitly opt in. The default is "not provided".

Some providers offer heavily discounted models ("training-tier models") on the condition that they may use inputs and outputs to train their own models. You can choose this by turning on "Allow training-tier models" in account settings. Even then, what is provided for training is limited to the inputs and outputs of requests you sent to a training-tier model by name while that setting was on. It does not apply to requests to any other model, nor to requests made before you turned it on. Requests made with an organization API key follow the organization setting, not the individual one. Training-tier models are labelled in the catalogue and model pages; accounts that have not opted in do not see them listed and are refused if they call them.

⚠️ This choice is only partially reversible. Turning the setting off stops future requests from being used for training, but content already incorporated into a trained model cannot be recalled. Do not use it for requests containing confidential or personal data.

Separately, certain models are subject to retention requirements mandated by the model provider:

ProviderUsed for model trainingProvider-side retention
AWS BedrockNoNot stored
AWS Bedrock — Claude Fable 5 (that model only)NoUp to 30 days, shared with the model provider (Anthropic) and subject to human review — a condition required by the model provider
Google Gemini APINoUp to 55 days, solely for policy-violation detection
Nebius Token FactoryNo (opt-out applied)Not stored (opt-out applied)
Z.AI Model APINoAPI input and output content is not stored; real-time processing only
Meta Model API (standard tier)NoPer the provider's own policy
Meta Model API — training-tier models (those models only)Yes — limited to requests you sent to those models while you had "Allow training-tier models" turned on. Off by default (opt-in)Per the provider's own policy

5.2 Payment Processors

Payment data is processed by Polar.sh (global payments) and Hecto Financial (Korean domestic payments). We do not store your full payment credentials.

5.3 Infrastructure Providers

We use AWS for cloud infrastructure and Vercel for web hosting. Subject to your optional-data consent choices above, Google LLC processes limited website analytics through GTM and GA4, plus consented remarketing and first-payment conversion data through Google Data Manager. These providers may process data in the United States or other provider processing regions.

5.4 No Sale of Personal Data

We do not sell, rent, or trade your personal information to third parties for marketing or advertising purposes.

6. International Data Transfers

Your data may be processed in multiple regions depending on the AI provider selected:

We implement appropriate safeguards to protect your data during international transfers, including encryption in transit (TLS) and at rest.

Z.AI API processing follows its API Services DPA and Additional Terms for API Services. Separate retention conditions may apply to data other than API content, such as account or payment data.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

To exercise any of these rights, please contact us at portal@everyais.com. We will respond to your request within 30 days.

8. Data Security

We implement industry-standard security measures to protect your data:

9. Children's Privacy

Our Service is not intended for individuals under the age of 14. We do not knowingly collect personal information from children under 14. If we learn that we have collected personal data from a child under 14, we will take steps to delete such information promptly.

10. Changes to This Policy

v1.6.0, effective September 15, 2026: added Z.AI processing, disclosure, Singapore transfers, and API content retention and training conditions.

We may update this Privacy Policy from time to time. Changes will be identified by an updated version number and effective date. We will notify you of material changes through the Service or via email. Your continued use of the Service after the effective date constitutes your acceptance of the updated policy.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us:

BROZ Corp.

  • Email: portal@everyais.com
  • Address: 5F #503, 465 Dongdaegu-ro, Dong-gu, Daegu, Republic of Korea
  • Business Registration No.: 288-81-02136