Privacy Policy

Last Updated: August 1, 2026 · Effective Date: August 1, 2026 · Version 3.1

Quick Navigation

CTIM AI ("we," "our," or "us") is committed to protecting the privacy and security of your personal information. This Privacy Policy ("Policy") describes how we collect, use, disclose, process, and protect information obtained through our AI API gateway service, website, and related platforms (collectively, the "Service"). This Policy is incorporated into our Terms of Service and applies to all Users, visitors, and other individuals whose personal data we process.

By accessing or using the Service, you consent to the data practices described in this Policy. If you do not agree with the terms of this Policy, you should not access or use the Service. We encourage you to read this Policy carefully and review it periodically, as it may be updated from time to time.


1. Introduction and Scope

1.1 This Policy applies to all personal data collected, processed, and stored by CTIM AI in connection with the operation of our Service. This includes data collected through our website, API endpoints, dashboard interfaces, customer support channels, and any other means by which you interact with our Service.

1.2 CTIM AI acts as a data controller for personal data collected directly from Users for the purposes of account management, billing, service provision, and communication. For Customer Content — the data, prompts, queries, and materials submitted to the Service via API — CTIM AI acts as a data processor, processing such data solely on behalf of and in accordance with the instructions of the User.

1.3 This Policy does not apply to the data practices of Model Providers or other third-party services accessible through or linked from the Service. Each Model Provider operates under its own privacy policy and data handling practices, which Users are encouraged to review independently. CTIM AI is not responsible for the privacy practices of these third parties.

1.4 If you are using the Service on behalf of an organization, this Policy applies to the personal data of individuals within that organization whose information is provided during account registration or in connection with Service use. The organization is responsible for ensuring that individuals whose data is provided have been informed of and consent to the processing described in this Policy.


2. Information We Collect

2.1 We collect the following categories of information in connection with the Service:

2.1.1 Account and Registration Information

When you register for an account, we collect:

  • Email address (required for account creation and communication)
  • Organization or company name (if provided)
  • Contact name or display name (if provided)
  • Phone number (optional, for account recovery or enterprise accounts)
  • Billing address (if required for invoiced enterprise accounts)
  • Tax identification number (if required for tax compliance)

2.1.2 Service Usage Data

When you use the Service, we automatically collect:

  • API Key identifiers and associated access patterns
  • Request timestamps, response timestamps, and latency measurements
  • Model identifiers and provider information for each request
  • Token counts for input and output content
  • Request volume, frequency, and rate limit utilization
  • Error codes, status codes, and failure reasons
  • IP addresses associated with API requests (for security and abuse detection)
  • Browser type, operating system, and device information for dashboard access
  • Dashboard navigation patterns and feature usage analytics

2.1.3 Payment and Billing Information

For Users with paid accounts, we collect:

  • Account balance and transaction history
  • Payment method information (processed by our payment service providers)
  • Billing records, including invoices and receipts
  • Promotional credits, trial allowances, and discount information
  • Usage-based cost calculations and projections

2.1.4 Communication Data

When you communicate with us, we collect:

  • Email correspondence content and metadata
  • Support ticket content, attachments, and resolution status
  • Chat transcript data (if you interact with our AI chat assistant)
  • Feedback, survey responses, and feature request submissions
  • Lead inquiry information submitted through our contact forms

2.1.5 Technical and Log Data

Our systems automatically generate:

  • Server access logs, including request paths and response sizes
  • Security event logs, including authentication attempts and access control decisions
  • Performance metrics and system health indicators
  • Error logs and diagnostic information for troubleshooting

2.1.6 We do not collect or store the actual content of your API requests (Customer Content) beyond what is necessary to route the request to the appropriate Model Provider and to generate a response. Customer Content is processed in transit and is not persisted in our storage systems, except as may be required for debugging specific incidents with your consent or as inherently required by Model Provider terms.


3. How We Use Your Information

3.1 We use the information we collect for the following purposes:

3.1.1 Service Provision and Operation

  • Authenticating and authorizing API access using API Keys
  • Routing API requests to appropriate Model Provider endpoints
  • Metering token usage and calculating associated charges
  • Maintaining account balances and processing transactions
  • Providing usage analytics and reporting through the dashboard
  • Enforcing rate limits and usage quotas associated with your account tier
  • Monitoring service health and performance metrics

3.1.2 Security and Abuse Prevention

  • Detecting and preventing unauthorized access, fraud, and abuse
  • Investigating security incidents and suspected policy violations
  • Implementing and maintaining security controls and access restrictions
  • Identifying and blocking malicious IP addresses or request patterns
  • Conducting security assessments and vulnerability testing

3.1.3 Communication and Support

  • Responding to support requests, inquiries, and feedback
  • Sending service-related notifications, including security alerts and maintenance notices
  • Communicating changes to the Service, Terms, or this Privacy Policy
  • Providing technical documentation, guides, and educational resources
  • Following up on leads and inquiries submitted through contact forms

3.1.4 Service Improvement and Analytics

  • Analyzing aggregate usage patterns to optimize service performance and routing
  • Identifying popular models and providers to guide service expansion decisions
  • Evaluating feature usage to prioritize development efforts
  • Generating anonymized, aggregated statistics for business intelligence

3.1.5 Legal and Compliance

  • Complying with applicable legal obligations and regulatory requirements
  • Responding to lawful requests from government authorities and law enforcement
  • Enforcing our Terms of Service and protecting the rights and safety of CTIM AI, our Users, and the public
  • Maintaining records for accounting, tax, and audit purposes

3.2 We do not use Customer Content to train, fine-tune, or improve our own AI models, machine learning systems, or services. Customer Content is processed solely for the purpose of fulfilling your API requests as instructed by you.



5. Information Sharing and Disclosure

5.1 We do not sell, rent, or trade your personal information to third parties. We share information only as described in this Policy or with your explicit consent.

5.1.1 Model Providers

When you submit an API request to the Service, the content of that request (Customer Content) is transmitted to the selected Model Provider for processing. Model Providers have their own privacy policies and data handling practices that govern how they process the data they receive. We encourage you to review the privacy policies of the Model Providers whose models you access through the Service.

5.1.2 Service Providers and Processors

We engage third-party service providers to perform functions on our behalf, including but not limited to:

  • Payment processing and fraud prevention services
  • Cloud hosting and infrastructure providers
  • Email delivery and communication platforms
  • Analytics and monitoring services
  • Customer support ticketing systems
  • Security and threat intelligence services

These service providers are contractually obligated to process personal data only in accordance with our instructions and to implement appropriate security measures. We do not authorize them to use personal data for their own purposes.

5.1.3 Legal Requirements

We may disclose personal data if required to do so by law or in response to valid requests by public authorities, including court orders, subpoenas, or regulatory inquiries. We may also disclose personal data to protect the rights, property, or safety of CTIM AI, our Users, or the public, or to investigate or prevent fraud, security issues, or other illegal activities.

5.1.4 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of all or substantially all of CTIM AI's assets, personal data may be transferred as part of the transaction. We will notify Users of any such change in ownership or control of personal data through the Service dashboard and email notification, and the acquiring entity will be required to honor this Policy unless you consent to a different arrangement.

5.1.5 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified data that does not reasonably identify any individual with business partners, researchers, and the public for purposes such as market analysis, industry reporting, and service benchmarking. Such data cannot be used to identify you individually and is not subject to this Policy once fully anonymized.


6. Data Retention

6.1 We retain personal data for as long as your account is active or as needed to provide the Service to you. After account termination or closure, we retain certain data as follows:

  • Account and Billing Records: Retained for a minimum of seven (7) years from the date of the relevant transaction, as required for tax, accounting, and audit compliance purposes. This includes transaction history, invoices, payment records, and account registration details.
  • Usage Metadata: Retained for a period of twenty-four (24) months from the date of collection for the purposes of usage analytics, trend analysis, and service optimization. After this period, usage metadata is aggregated and anonymized for statistical purposes.
  • Communication Records: Support tickets, email correspondence, and chat transcripts are retained for a period of twenty-four (24) months from the date of the last interaction, to enable continuity of support and quality assurance.
  • Security and Access Logs: Retained for a period of twelve (12) months from the date of generation, to enable security incident investigation and compliance auditing.
  • Lead and Marketing Data: Information submitted through contact forms and lead generation channels is retained until the individual requests deletion or opts out of further communication, or for a maximum period of thirty-six (36) months from the date of submission, whichever is earlier.

6.2 You may request deletion of your personal data at any time by contacting us at the address provided in Section 14. We will process deletion requests within thirty (30) days, subject to our obligations to retain certain data for legal, regulatory, tax, or legitimate business purposes as described above.

6.3 Backups and archived copies of data may persist for a period after deletion from active systems, consistent with our backup retention schedules. Such data is not accessible for routine processing purposes and is protected by the same security measures applied to active data.


7. Data Security

7.1 CTIM AI implements comprehensive technical and organizational security measures designed to protect personal data against unauthorized access, accidental loss, alteration, disclosure, or destruction. Our security program includes, but is not limited to:

  • Encryption in Transit: All data transmitted between Users and the Service is encrypted using TLS 1.2 or higher. API endpoints require HTTPS connections and reject unencrypted traffic.
  • Credential Protection: API Keys are stored using cryptographic hashing algorithms and are never stored in plaintext. Access to API Key values in our systems is restricted to authorized systems and personnel on a need-to-know basis.
  • Access Controls: Internal access to User data is governed by role-based access control (RBAC) policies, requiring multi-factor authentication for administrative access and logging all access events for audit purposes.
  • Infrastructure Security: Our hosting infrastructure is maintained by reputable cloud service providers with industry-standard security certifications. Servers are configured with hardened operating systems, regular patching, and network-level firewalls.
  • Monitoring and Detection: We deploy automated monitoring systems to detect anomalous access patterns, potential security threats, and unauthorized access attempts in real-time. Security events are logged and reviewed by our security team.
  • Incident Response: We maintain an incident response plan that defines procedures for identifying, containing, investigating, and remediating security incidents. Affected Users are notified in accordance with applicable legal requirements.
  • Regular Assessment: We conduct periodic security assessments, including vulnerability scanning, configuration reviews, and penetration testing, to identify and address potential weaknesses in our security posture.

7.2 While we implement commercially reasonable security measures, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee the absolute security of your personal data, and you acknowledge that you provide data at your own risk. You are responsible for implementing appropriate security measures in your own applications, including secure storage of API Keys and protection against unauthorized access.

7.3 In the event of a confirmed security breach involving personal data, we will notify affected Users and applicable regulatory authorities within the timeframes required by applicable law. Notifications will include a description of the incident, the categories of data affected, the likely consequences, and the measures taken or proposed to address the breach.


8. Your Rights and Choices

8.1 Depending on your jurisdiction and applicable data protection laws, you may have the following rights with respect to your personal data:

  • Right of Access: You have the right to request a copy of the personal data we hold about you. This includes the categories of data processed, the purposes of processing, the recipients of the data, and the retention period. We will respond to access requests within thirty (30) days, providing the data in a commonly used electronic format.
  • Right to Rectification: You have the right to request correction of inaccurate or incomplete personal data. You may update certain information directly through the Service dashboard, or by contacting us with the specific corrections required.
  • Right to Erasure ("Right to be Forgotten"): You have the right to request deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent, or where the data was processed unlawfully. This right is subject to our legal obligations to retain certain data as described in Section 6.
  • Right to Restriction of Processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, including while we verify the accuracy of the data, where the processing is unlawful but you oppose erasure, or where you need the data for the establishment, exercise, or defense of legal claims.
  • Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller, where technically feasible. This right applies to data you have provided to us and data we have processed based on your consent or for contractual performance.
  • Right to Object: You have the right to object to the processing of your personal data based on legitimate interests or for direct marketing purposes. Where you object to processing based on legitimate interests, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims.
  • Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal and does not affect processing based on other legal grounds.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in your jurisdiction if you believe your personal data has been processed in violation of applicable data protection laws.

8.2 To exercise any of these rights, please contact us at support@ctimsoft.com. We will respond to your request within thirty (30) days, and may request additional information to verify your identity before fulfilling the request.

8.3 We do not charge a fee for exercising these rights, except where requests are manifestly unfounded, excessive, or repetitive, in which case we may charge a reasonable administrative fee or decline to act on the request.


9. International Data Transfers

9.1 CTIM AI operates as a globally accessible service. Your personal data may be transferred to, stored, and processed in countries other than the country in which you are located. These countries may have data protection laws that differ from those in your jurisdiction.

9.2 Where personal data is transferred from the European Economic Area (EEA), the United Kingdom, or other jurisdictions with data transfer restrictions to countries that have not been deemed to provide an adequate level of data protection, we implement appropriate safeguards to protect your data, including:

  • Standard Contractual Clauses (SCCs) approved by the relevant regulatory authorities
  • Adequacy decisions issued by the European Commission or equivalent bodies
  • Binding Corporate Rules, where applicable
  • Additional technical and organizational measures, including encryption and access controls

9.3 You may request information about the specific safeguards in place for international transfers by contacting us at the address provided in Section 14.


10. Children's Privacy

10.1 The Service is not directed to individuals under the age of sixteen (16) or the applicable age of digital consent in your jurisdiction, whichever is higher. We do not knowingly collect personal data from children. If you are a parent or guardian and believe that your child has provided personal data to us through the Service, please contact us immediately, and we will take steps to delete such data from our systems.

10.2 If we become aware that we have inadvertently collected personal data from a child without appropriate consent, we will take immediate steps to delete that data and terminate the associated account.


11. Cookies and Similar Technologies

11.1 Our website and dashboard may use cookies, local storage, and similar technologies to enhance your experience, maintain session state, and collect usage analytics. The types of technologies we use include:

  • Essential Cookies: These are required for the operation of the Service, including maintaining your authenticated session, remembering your language preferences, and ensuring the security of the dashboard. These cookies cannot be disabled as they are necessary for the Service to function.
  • Analytics Cookies: These help us understand how visitors interact with our website by collecting anonymized information about page views, navigation patterns, and feature usage. We use this information to improve the Service and user experience. Analytics cookies do not collect personally identifiable information.
  • Functional Cookies: These enable enhanced functionality and personalization, such as remembering your display preferences, language settings, and dashboard layout choices. If you do not allow these cookies, some or all of these services may not function properly.

11.2 You can control and manage cookies through your browser settings. Most browsers allow you to refuse or delete cookies, though doing so may affect the functionality of the Service. For information on how to manage cookies in your browser, please refer to your browser's help documentation.

11.3 We do not use cookies for advertising or marketing purposes on our website or dashboard. We do not share cookie data with third-party advertising networks or tracking services.


12. Third-Party Links and Services

12.1 The Service may contain links to third-party websites, services, or resources that are not owned or controlled by CTIM AI, including Model Provider websites, documentation pages, and community forums. This Policy does not apply to any third-party websites or services, and we are not responsible for their privacy practices, content, or availability.

12.2 We encourage you to review the privacy policies of any third-party websites or services you visit through links from the Service before providing any personal information.

12.3 Model Providers whose models are accessible through the Service have their own privacy policies and terms of service that govern the processing of data submitted to their models. CTIM AI does not control and is not responsible for the privacy practices of Model Providers. We recommend reviewing each Model Provider's privacy policy before submitting Customer Content to their models.


13. Changes to This Policy

13.1 CTIM AI may update this Privacy Policy from time to time to reflect changes in our data practices, legal requirements, or Service functionality. We will notify Users of material changes through the Service dashboard, email notification, or a prominent notice on our website at least fourteen (14) days before the effective date of the changes.

13.2 Non-material changes, such as clarifications, corrections, formatting updates, or updates to contact information, may be made without prior notice. The "Last Updated" date at the top of this Policy indicates when the Policy was most recently revised.

13.3 Your continued use of the Service after the effective date of a revised Policy constitutes your acceptance of the revised Policy. If you do not agree with the changes, your sole remedy is to discontinue use of the Service and terminate your account before the effective date.

13.4 We maintain an archive of previous versions of this Policy. If you would like to review a prior version, please contact us at the address provided in Section 14.


14. Contact Us

14.1 If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us through any of the following channels:

Email: support@ctimsoft.com

Telegram: @ctimlucas

14.2 We will respond to privacy-related inquiries within five (5) business days. For requests involving the exercise of your data protection rights, we will respond within thirty (30) days, as described in Section 8.

14.3 For Users in the European Economic Area, our designated point of contact for privacy matters is available at the email address above. You also have the right to lodge a complaint with a supervisory authority in your jurisdiction at any time.

This Privacy Policy was last reviewed and updated on August 1, 2026. We conduct regular reviews to ensure compliance with evolving legal requirements and industry best practices.