Legal

Privacy Policy

Last updated: 28 September 2026. This policy explains what data faborapi processes, why, and what control you keep over it.

1. Data controller & contact

faborapi ("faborapi", "we", "us" or "our") operates the low-cost AI API platform available at faborapi.com. faborapi is established in Brussels, Belgium, and acts as the data controller for the personal data described in this policy. Processing is governed by Belgian law and by Regulation (EU) 2016/679 (GDPR).

For any privacy question, request or complaint, contact us at support@faborapi.com.

2. Data we collect

We keep data collection to what the service genuinely needs to work, to be billed correctly and to stay secure.

  • Account data. Your email address, a hashed password (never stored in clear text), your internal user identifier, and — if you sign in with Google — the basic profile information Google returns (email, name, profile picture).
  • Security & location telemetry. Your IP address, the country derived from it, and the date and time of your last sign-in. This is used for account security, fraud prevention, sanctions compliance, and to offer the right currency and payment method.
  • API usage metadata. For each request: the model called, the number of input and output tokens, the timestamp, the amount debited, and the name plus last four characters of the API key used. This is what powers your Usage page and your billing history.
  • Payment data. We do not store card numbers or any banking credentials. Payments are handled entirely by certified providers (Stripe, Manza, PawaPay). We keep only the top-up record: amount, currency, pack, date and transaction reference.
  • Support correspondence. The content of emails you send us, so we can answer and keep a record of the request.

3. Prompts, messages & files

We never train on your data. faborapi does not use your prompts, messages, images, documents or model outputs to train, fine-tune or evaluate any AI model, and we never sell them.

  • Direct relay. Requests sent to the chat completions endpoint are relayed in real time to the upstream AI provider (Anthropic, OpenAI, Google, xAI) for the sole purpose of generating the response you asked for.
  • No prompt content stored. The text of your messages and the content of the model's replies are not written to our database. Only billing metadata (model, token counts, cost, timestamp) is logged.
  • Uploaded files. Files you upload through the files endpoint are kept in private, access-controlled storage, reachable only with your own API key. They stay available until you delete them yourself, or until your account is closed.
  • Your own end users. Where the content you send contains personal data about your users, you are the controller of that data and are responsible for having a lawful basis for sending it.

4. Legal bases for processing

  • Performance of a contract (Art. 6(1)(b) GDPR) — creating and managing your account, issuing API keys, executing API calls, debiting your prepaid balance and displaying your usage.
  • Legal obligation (Art. 6(1)(c) GDPR) — accounting and tax record-keeping, and compliance with international sanctions and export-control regimes.
  • Legitimate interests (Art. 6(1)(f) GDPR) — securing our infrastructure, detecting abuse, preventing fraud and protecting our users, balanced against your rights and freedoms.
  • Consent (Art. 6(1)(a) GDPR) — where we rely on analytics that are not strictly necessary, and which you can refuse.

5. Processors & international transfers

We work with a limited number of carefully selected providers. Each of them processes data only on our instructions, under a data-processing agreement:

  • Cloud hosting, database, authentication and file storage for the platform itself.
  • Payment providers: Stripe (bank cards), Manza (Morocco) and PawaPay (Mobile Money in Africa). They receive the data needed to take and verify your payment; we receive back only the transaction result.
  • Upstream AI providers: Anthropic, OpenAI, Google and xAI, which receive the content of the requests you send so they can generate the response. Their own terms and data-handling practices then apply to that content.
  • Google Analytics, for aggregated audience measurement on our public pages.

Some of these providers are located outside the European Economic Area, in particular in the United States. Such transfers rely on the appropriate safeguards provided by the GDPR, including the European Commission's Standard Contractual Clauses or an adequacy decision.

6. Data retention

  • Account data and transaction history: kept for as long as your account is active, then archived for the period required by Belgian accounting and tax law (normally seven years for invoicing records).
  • Revoked or deleted API keys: the key is disabled immediately and irreversibly, but its label, last four characters and past usage records are kept so your consumption history and billing remain complete and auditable.
  • Uploaded files: kept until you delete them through the API or your account is closed.
  • Security logs (IP address, sign-in events): kept for a limited period proportionate to fraud prevention and security investigation needs.

When you ask us to close your account, we delete or anonymise your personal data except for the records we are legally obliged to retain.

7. Your GDPR rights & supervisory authority

Under the GDPR you have the right to:

  • Access the personal data we hold about you and obtain a copy of it.
  • Have inaccurate or incomplete data corrected.
  • Have your data erased (right to be forgotten), subject to our legal retention obligations.
  • Receive your data in a portable, machine-readable format.
  • Restrict or object to certain processing, and withdraw consent where processing is based on it.

To exercise any of these rights, write to support@faborapi.com. We will reply within one month of receiving your request, as required by the GDPR.

If you believe your data is not handled correctly, you may lodge a complaint with the Belgian Data Protection Authority (Autorité de protection des données / Gegevensbeschermingsautoriteit), Rue de la Presse 35, 1000 Brussels, Belgium.

8. Cookies, analytics & security

  • Strictly necessary cookies and tokens only for the application itself: your authentication session and the encrypted, HTTP-only session cookie protecting the admin portal. Without them, signing in is impossible.
  • Google Analytics is used on our public pages for aggregated audience measurement (pages viewed, approximate origin of traffic). It never has access to your prompts, files, API keys or balance.
  • No advertising, profiling or retargeting cookies. We do not sell, rent or trade your personal data to anyone.
  • Security: all traffic is encrypted in transit with HTTPS/TLS, data is encrypted at rest, API keys are stored as SHA-256 hashes, and sensitive provider credentials are encrypted with AES-256-GCM.

We may update this policy to reflect changes in the service, our providers or the law. The "Last updated" date above always reflects the current version.