MarsAI
Sign in Get Started

Privacy Policy

What we store. Account email, hashed password, social-login identifiers, API key hashes (plaintext keys are never stored), credit balances (Free and Premium), usage logs (model, token counts, latency, status, cost), request metadata needed for billing and abuse prevention, and hashed IPs for audit.

What we don't store. Prompt/response content is not persisted for billing logs. Identical requests may temporarily reuse stored responses to reduce cost and latency.

Third parties. Requests pass to upstream AI providers under their own policies. Social login uses Google, GitHub, Discord, Telegram OAuth. Payments (when enabled) go through Stripe — we never see card numbers.

Security. Provider secrets, SMTP passwords and social secrets are AES-256-GCM encrypted at rest. OAuth tokens and API keys are stored as SHA-256 hashes.

Retention & deletion. Usage logs kept for billing/anti-abuse. Ask via contact or Discord to delete your account; logs required for financial records may persist in aggregate.

Cookies. Session cookie only (httponly, samesite). No ad trackers, no analytics beacons.