Legal

Privacy Policy

Last Updated: September 30, 2026

Version V2.2 | Effective Date: September 30, 2026 | Last Updated: September 30, 2026

This English version is provided for convenience only. In case of any discrepancy between language versions, the Simplified Chinese version shall prevail.

[Key Points] This Policy explains how BeeHears collects, uses, stores, shares and protects your personal information, and the rights you have. Please pay particular attention to the content marked in bold, especially:

  • The request content you submit will be transmitted for processing to the Upstream Providers that provide model capabilities for the relevant request, most of which are located outside mainland China;
  • For requests processed through certain Channels, the Platform will fully record the request and response content (Content Backup) for billing verification, dispute handling and customer inquiries;
  • The Platform conducts sample-based inspection of request content (Content Safety Sampling); content fragments that match risk rules will be recorded and may result in restrictions on your API Keys (Tokens) or account;
  • Usage Logs and transaction records are retained for as long as the account exists, and for no more than 1 month after account deletion. Where laws and regulations require a longer retention period, that period applies.

By checking the box to agree to this Policy and using the Service, you indicate that you have fully understood and agreed to this Policy.

Article 1 Scope of Application and Personal Information Handler

1.1 This Policy applies to the services provided by the BeeHears platform operator (hereinafter referred to as "we" or the "Platform") through the BeeHears website (ai.beehears.com) and the API endpoints published by the Platform (including acceleration nodes and CDN nodes) (hereinafter referred to as the "Service"). We are the handler of your personal information; our contact information is set out in Article 12.

1.2 Where you submit personal information of others through request content, you shall ensure that you have obtained authorization in accordance with the law or have another lawful basis.

Article 2 Information We Collect and Its Purposes

2.1 We follow the principles of lawfulness, legitimacy, necessity and good faith, and collect and use your information in the following scenarios:

ScenarioInformation collectedPurposes
Registration and loginUsername, password (stored after hashing), email address and verification codes; if you use third-party account login, two-step verification or passkeys, also the corresponding account identifiers and verification credentialsCreating and managing accounts, identity verification, account security
Top-up and paymentOrder number, top-up amount, payment method, payment status and time, redemption code usage records, and the necessary identifiers returned by the payment service provider to complete the paymentCrediting top-ups, reconciliation, refunds, financial and tax compliance
API Key (Token) managementAPI Key name, API Key secret, and restrictions you set, such as Credit limits, available models and IP allowlistsAPI authentication and call control
API calls and billingUsage Logs: request time, Request ID, API Key name, model, Group, processing Channel, itemized usage, fees, duration, whether streaming was used, status and error messages, upstream request identifier; if you enable the "Record IP Address" setting, also the request IPBilling and settlement, usage statistics, reconciliation and objection handling, troubleshooting
Security and risk controlIP address, browser and client information (User-Agent), access and login records, request frequency statistics, risk flagsProtecting account and system security, preventing fraud, abuse and attacks
NotificationsRegistered email address or a separate notification email address you set, and the notification methods and addresses you configure (such as Webhook, Bark, Gotify)Sending verification codes, Credit alerts, price change notices, and service and security notifications
Affiliate program and promotionsInvitation codes, referral relationships, affiliate earnings, check-in and promotion records; payee information when you apply for a withdrawalIssuing and settling rewards, preventing cheating
Customer serviceInquiry content, contact information and related account information you provide via online customer service, email, etc.Verifying identity, handling inquiries, complaints and disputes

2.2 Request content: Request content you submit through the API, such as prompts, context, files, images and audio, as well as response content returned by the upstream, will be processed by the Platform; the processing rules are set out in Article 3.

2.3 We do not require you to provide sensitive personal information. Please do not submit sensitive personal information in request content, such as identity document numbers, financial accounts, biometric data, medical and health information, whereabouts, or personal information of minors under the age of 14; where such submission is truly necessary, you shall ensure that you have obtained the separate consent of the individuals concerned or have another lawful basis, and shall bear the corresponding responsibility yourself.

2.4 The legal bases on which we process personal information include: where necessary for the conclusion and performance of the service agreement to which you are a party; where necessary for the performance of statutory duties or obligations (such as cybersecurity, content security management, and finance and tax); your consent; and other circumstances provided by laws and regulations.

Article 3 Processing of Request Content

3.1 Forwarding for processing. Your request content will be transmitted for processing to the Upstream Provider selected by the Platform for that request (including official APIs of model vendors, cloud service platforms and other third-party model service suppliers). Upstream Providers process and retain request content in accordance with their own terms of service and privacy policies, which may include security review and abuse monitoring. The Platform will not provide your account registration information (such as username, email address and password) to the upstream as request parameters, but information that you yourself include in the request content will be transmitted along with the request.

3.2 Content Backup. For requests processed through certain Channels (selected by the Platform based on the needs of dispute handling, quality verification and service assurance), the Platform will fully record the request content and response content (any portion exceeding the size set by the Platform will be truncated), and will record metadata such as the Request ID, user ID, API Key ID, model, Channel, API path, response status, upstream request identifier and session identifier. Backup content is uploaded to the Platform's remote backup storage via encrypted transmission protocols and is used only for: handling objections and disputes raised by you or Upstream Providers regarding billing, usage and service quality; responding to your inquiries; verifying Channel and service quality; and cooperating with relevant authorities in accordance with the law. Access to and download of backup content are restricted to the Platform's highest-privilege administrators.

3.3 Content Safety Sampling. To fulfill its obligations regarding the management of online information content security and to prevent illegal or non-compliant use, the Platform will sample, at a certain ratio, request content sent to APIs such as the chat, completion and embedding APIs, and compare it against risk rules. Samples are temporarily stored together with information such as the Request ID, username, API Key, model, Channel, IP address and User-Agent; where a rule is matched, the Platform will record the matched content fragment and related information for review, increase the sampling ratio for that account's requests for a certain period, up to full inspection, and may automatically disable the relevant API Keys through the system or, after review, restrict or ban the account. Sampling does not affect the normal processing of requests. With respect to disabling decisions made automatically by the system, you may, through the means set out in Article 12, request that we explain the reasons and apply for manual review.

3.4 Except in the circumstances described in this Policy and as otherwise required by laws and regulations, the Platform will not use your request content to train models, nor will it sell your request content.

Article 4 Cookies and Local Storage

4.1 We use session cookies to maintain your login status, and use browser local storage to save cached user information, interface and language preferences, invitation codes, etc., to enable basic functions. We currently do not use third-party advertising cookies.

4.2 The online customer service widget on the website may use cookies or local storage in accordance with its service rules.

4.3 You may clear or refuse cookies through your browser settings, but this may prevent you from logging in or make some functions unavailable.

Article 5 Sharing, Entrusted Processing, Transfer and Public Disclosure

5.1 We will not sell your personal information. Only in the following circumstances will we, in accordance with the principle of minimum necessity, provide your personal information to third parties or entrust them to process it:

  • (1) Upstream Providers: see Article 3;
  • (2) Payment service providers: when you top up, the payment service provider (subject to what is displayed on the top-up page) processes payment information, and we do not collect sensitive payment information such as bank card numbers or payment passwords;
  • (3) Email delivery service providers: to send verification codes and notifications, we will provide them with your email address and the email content;
  • (4) Cloud service and network service providers: including server, storage and Content Backup storage service providers; when you access the Service through a CDN or acceleration node, requests will be transmitted via the corresponding network service provider (such as Cloudflare) and the Platform's relay servers;
  • (5) Online customer service providers: to process information you submit through online customer service;
  • (6) Reconciliation and dispute handling: to verify billing, troubleshoot failures or handle disputes with Upstream Providers, we may provide them with necessary information about the relevant requests, such as the Request ID, time, model, usage and status, which generally does not include your account identity information; where it is truly necessary to provide request content, this is limited to the requests involved in the dispute;
  • (7) As required by laws and regulations, litigation, arbitration, or administrative or judicial authorities.

5.2 For service providers entrusted with processing personal information, we will agree with them, in accordance with the law, on the purposes and methods of processing and their protection obligations.

5.3 Where personal information needs to be transferred due to a merger, division, dissolution, declaration of bankruptcy or other reasons, we will inform you of the recipient's name and contact information and require the recipient to continue to comply with this Policy; if the recipient changes the purposes or methods of processing, it will obtain your consent again.

5.4 Except as required by laws and regulations or with your separate consent, we will not publicly disclose your personal information.

Article 6 Cross-Border Transfer

6.1 Most of the models available through the Service are provided by overseas model vendors or service providers (such as OpenAI, Anthropic, Google, xAI and cloud service platforms authorized by them), and the Platform's servers, relay nodes and backup storage may also be located outside mainland China (including but not limited to countries or regions such as the United States and Hong Kong, China). When you use the Service, your request content, the parameters necessary for processing requests, and the account and log information listed in Article 2 may be transmitted, stored and processed outside mainland China.

6.2 The categories of overseas recipients and the purposes, methods and types of information of the processing are set out in Article 3 and Article 5. You may, through the means set out in Article 12, learn from us about the specific recipients, and exercise with us the rights you are entitled to under the law in respect of overseas recipients.

6.3 By actively choosing a model provided by an overseas service provider and submitting a request, you give your separate consent to the provision of the corresponding information overseas for the purpose of processing that request. We will perform the relevant obligations for the outbound transfer of personal information in accordance with the requirements of laws and regulations.

Article 7 Retention Periods

7.1 Unless otherwise provided by laws and regulations, we retain your information for the period necessary to achieve the purposes described in this Policy, and the retention periods for each category of information are as follows:

Information categoryRetention period
Account informationFor as long as the account exists; after account deletion, handled in accordance with Clause 7.2
Top-up and transaction recordsRetained for as long as the account exists; for no more than 1 month after account deletion
Usage Logs (billing records)Retained for as long as the account exists; for no more than 1 month after account deletion, for settlement, reconciliation and dispute handling
Content Backup search index30 days by default, automatically deleted upon expiry
Content Backup bodyRetained in accordance with the Platform's storage policy then in effect, for dispute handling and customer inquiries
Content Safety Sampling samples30 days by default
Risk rule match recordsRetained in accordance with the Platform's settings then in effect
Server operation and security logsRetained in accordance with the Platform's settings then in effect
Customer service recordsRetained in accordance with the Platform's settings then in effect

7.2 After you delete your account, we will stop providing services to you, and your account information will no longer be used for providing services, marketing or other routine business processing. Top-up and transaction records and Usage Logs are retained for no more than 1 month after account deletion for settlement, reconciliation and dispute handling that has not yet been completed, and are then deleted or anonymized. Where laws and regulations require a longer retention period, they are retained for that period. During the retention period above, they will not be processed except for storage and the adoption of necessary security protection measures.

Article 8 Security Measures

8.1 We adopt security measures appropriate to the Service, including: HTTPS encrypted connections for the Platform's website and API endpoints; storage of account passwords after processing with an irreversible hashing algorithm; role- and permission-based tiered management of the administration backend, with internal personnel's scope of data access restricted in accordance with the principle of minimum necessity, and access to and download of the Content Backup body restricted to highest-privilege administrators; and uploading of Content Backups to backup storage via encrypted transmission protocols.

8.2 The Internet environment is not absolutely secure, and we cannot guarantee the absolute security of information. Please properly safeguard your account password and API Keys, and promptly disable or replace them if you discover any disclosure.

8.3 In the event of a personal information security incident, we will, in accordance with the law, promptly inform you of the incident, its possible impact, the handling measures taken or to be taken, and suggestions on precautions you can take, and will report to the competent authorities.

Article 9 Your Rights

9.1 You have the following rights in accordance with the law:

  • (1) Access and copy: view account information, API Keys, Usage Logs, and top-up and Credit records in the Console; where the Platform provides an export function, you may export Usage Logs yourself;
  • (2) Correction and supplementation: modify your display name, email address, password, notification settings, etc. in your personal settings; other information may be corrected by contacting us;
  • (3) Deletion: request the deletion of your personal information in statutory circumstances such as where the purpose of processing has been achieved, we cease to provide services, you withdraw your consent, or we process it in violation of laws or regulations;
  • (4) Withdrawal of consent: withdraw your consent by contacting us; withdrawal does not affect processing carried out on the basis of your consent before the withdrawal;
  • (5) Account deletion: delete your account yourself in your personal settings, or contact us to delete it;
  • (6) Request that we explain the rules for processing personal information, or, where the conditions are met, request that your personal information be transferred to a handler designated by you.

9.2 Content Backup and Content Safety Sampling are necessary measures taken by the Platform for billing verification, dispute handling, and security and compliance, and no option to disable them separately is provided; if you do not agree, please stop using the Service.

9.3 We will respond within 15 working days after verifying your identity. We may be unable to respond in circumstances provided by laws and regulations, such as those involving national security, public security, criminal investigation, or litigation and enforcement, or where responding to the request would cause serious harm to the lawful rights and interests of others.

Article 10 Minors

10.1 The Service is intended for adults aged 18 or above and for enterprise and institutional users; if you are a minor, please do not register for or use the Service. We do not actively collect personal information of minors under the age of 14; if we discover that such information has been collected inadvertently, we will delete it promptly.

Article 11 Updates to this Policy

11.1 We may revise this Policy from time to time and will publish the updated version and its update date on this page. For material changes involving the purposes or methods of processing, the types of information, etc., we will notify you in advance through on-site announcements or email; if you continue to use the Service after the changes take effect, you shall be deemed to have agreed to the updated Policy.

Article 12 Contact Us

  • Contact email: [email protected] (matters relating to personal information protection may also be addressed to us via this email)

If you are dissatisfied with our response, or believe that our personal information processing activities have infringed your lawful rights and interests, you may file a complaint or report with the competent authorities, or bring a lawsuit before the people's court having jurisdiction.

Privacy Policy