Last updated: 7 September 2026
In short: we keep request metadata (timestamp, model, token counts,
latency, request_id) because that is what billing is built on. Prompt and
completion bodies are not kept long-term. Your requests are processed by third-party
infrastructure whose retention we do not control — so we don't claim “zero
logging”.
1. Who controls your data
LajuAPI — a sole proprietorship based in Indonesia — is the controller of the personal data described on this page. Contact: support@lajuapi.com.
2. What we collect
- Account data. Your email address and display name. If you sign up with Google we receive these from Google; we never receive your Google password.
- Request metadata. Timestamp, model name, input and output token
counts, latency, status, and
request_id. This is what billing and abuse handling are computed from. - Transaction records. Top-ups and balance deductions. Payments are handled by payment providers; we do not store card numbers or payment credentials.
- Technical logs. IP address and basic browser/client information, for security, abuse prevention, and diagnosing faults.
- Prompt and completion bodies. Held only briefly as a debugging window when something fails, then discarded. They are not used to train models and are not sold.
- Contact-form messages. The name, email, topic and message you send from the contact page. They are delivered to our inbox through Cloudflare's infrastructure, along with the country code of the request for spam prevention. The form sets no cookies and sends nothing beyond what you type.
3. Why we process it
To run the service you asked for, meter and bill usage, protect the service from abuse, meet legal and accounting obligations, and answer your questions and complaints. The grounds are performance of our contract with you, our legal obligations, and our legitimate interest in keeping the service secure.
4. Third parties that process your data
- Model infrastructure providers. Your request content is forwarded to the model providers behind the service so it can be processed. They have their own retention policies, which are outside our control. For that reason, do not send highly sensitive data — health records, full identity documents, or someone else's trade secrets — through this service.
- Payment providers. They process your payments and receive the data needed to do so.
- Server infrastructure providers. They host the servers this service runs on.
- Sign-in provider (Google). If you choose to sign in with Google.
We do not sell your personal data and do not share it for anyone else's marketing. Some of the providers above are outside Indonesia, so data may be processed across borders as far as running the service requires.
5. Cookies and tracking
The public site lajuapi.com sets no tracking cookies, no third-party
analytics, and no advertising scripts. It may store two functional preference cookies
(laju_lang, laju_currency) with Domain=.lajuapi.com,
Path=/, Secure, and SameSite=Lax so marketing pages
and the app remember language and display currency. Those cookies carry no account identity
and are not used for advertising. The dashboard at app.lajuapi.com uses
additional cookies required to keep you signed in.
6. How long we keep it
- Prompt and completion bodies: a short debugging window only, then discarded.
- Request metadata and transaction records: for as long as the account is active, and afterwards as long as needed for accounting, dispute resolution, and legal obligations.
- Account data: deleted after the account is closed, except what we must retain under the line above.
7. Security
Access to the production database is restricted, traffic to our service is encrypted with TLS, and API keys are stored in a form we cannot read back after they are created. No system is risk-free; if an incident affects your personal data we will notify you as required by applicable law.
8. Your rights
Under Indonesian Law No. 27 of 2022 on Personal Data Protection, you have the right to know what we process, obtain a copy, have inaccurate data corrected, request deletion, withdraw consent, and object to certain processing.
Send requests to support@lajuapi.com from the email address registered on your account. We aim to respond within a reasonable time, normally no more than 30 days.
9. Children
This service is not intended for anyone under 18, and we do not knowingly collect their personal data.
10. Changes to this policy
We may update this policy. The “last updated” date at the top of the page reflects the version in force, and we will notify active users by email about material changes.
This page is also available in Bahasa Indonesia.