Last Updated: June 4, 2026
This Privacy Policy explains how VOC AI INC ("VOC AI," "we," "us," or "our") collects, uses, shares, retains, and protects information when you access or use flatkey.ai, related flatkey.ai services, websites, dashboards, APIs, checkout pages, documentation, and support channels.
Operating entity: VOC AI INC, 160 E Tasman Drive, Suite 202, San Jose, CA 95134, United States. Contact: support@flatkey.ai.
1. Scope
This Policy applies to account registration, organization management, purchases, top-ups, delivery, API access, model routing, usage records, billing, refunds, support, security review, and related digital services we provide. Third-party model services, payment service providers, wallets, banks, card networks, cloud services, analytics tools, or other websites process information under their own privacy policies and terms. This Policy does not replace third-party policies.
2. Information We Collect
We may collect information you provide directly, including name, email address, password or authentication information, company name, role, team members, billing address, business information, tax ID, VAT/GST information, invoice information, order information, support messages, refund requests, compliance materials, dashboard settings, and communications with us.
When you use the Services, we may process information relating to service delivery and use, including order number, payment ID, delivery status, balance, credit records, API key name, request ID, timestamp, service selection, model selection, Inputs, Outputs, files, images, code, prompts, usage, deduction amount, price, latency, error logs, routing information, and security events.
We may also automatically collect technical information, including IP address, device identifiers, browser type, operating system, network-inferred location, pages visited, referring URL, session events, login records, clicks and actions, diagnostic logs, crash logs, performance data, anti-fraud signals, and similar information.
We may receive information relating to your account, orders, payments, permissions, usage, security, or support matters from payment service providers, authentication providers, anti-fraud providers, support tools, analytics tools, enterprise customers, team administrators, or third-party service providers.
3. Inputs, Outputs, and Model Processing
Inputs you submit and Outputs you receive may pass through our systems as necessary to provide the Services and may be sent to the relevant model service or technical service to complete the request. Different models and third-party services may have different data processing, logging, training, retention, and security rules. You should review applicable rules before using a particular model and avoid submitting information you are not authorized to submit or sensitive information that is not necessary.
Unless the dashboard, documentation, or order description expressly provides a relevant feature, we do not promise to store full Input or Output history. For troubleshooting, security, metering, refund, dispute, or compliance purposes, we may retain request metadata, error records, usage records, necessary logs, and materials you voluntarily provide in support communications.
We may use aggregated, anonymized, or de-identified information for statistical analysis, capacity planning, cost management, model and service quality analysis, product improvement, risk modeling, and business operations. Such information will not reasonably identify a particular individual.
4. Cookies and Similar Technologies
We use cookies, local storage, pixels, logs, and similar technologies to keep you logged in, protect sessions, remember preferences, complete checkout, detect fraud and abuse, measure visits, monitor performance, troubleshoot issues, and improve the Services. You can control some cookies through browser settings, but disabling cookies may affect login, dashboard, checkout, security, usage statistics, or support functionality.
5. Payment and Order Information
Payments may be processed by Paddle, Stripe, banks, card networks, wallets, local payment method providers, anti-fraud providers, tax providers, invoice providers, or other necessary service providers. We may receive or store payment ID, checkout ID, order number, payment status, authorization status, settlement status, product, amount, currency, tax amount, tax rate, tax jurisdiction, invoice number, receipt number, refund status, chargeback or dispute status, billing address, country, business name, tax ID, billing email, and information needed for support processing.
We do not intentionally store full card numbers, card verification codes, bank account credentials, or wallet credentials in our own systems. Payment method data is processed by the relevant payment service provider according to its security, privacy, and payment network compliance rules. We may retain limited payment metadata, such as payment provider name, payment method type, card last four digits provided by the provider, payment ID, receipt URL, invoice URL, refund ID, and dispute ID for billing, tax, accounting, support, refund, and dispute handling.
6. How We Use Information
We use information to create and authenticate accounts, process orders and payments, deliver service credits, maintain balance and usage records, provide API access, process requests, calculate usage and fees, handle invoices, receipts, refunds, and disputes, send service notices, respond to support requests, troubleshoot issues, detect and prevent fraud, abuse, security incidents, and policy violations, enforce the User Agreement and third-party rules, comply with tax, accounting, audit, legal, and compliance obligations, and protect the rights and safety of VOC AI, users, third-party service providers, payment service providers, and the public.
If you choose to receive marketing, product updates, or event notices, we may use your contact information to send those communications. You may opt out using the unsubscribe method in the email or by contacting us. Service notices, security notices, billing notices, and legal notices are not affected by marketing opt-outs.
7. Careful Handling of Information
We limit internal access based on business need and personnel responsibilities, and use permission management, logging, reasonable encryption, monitoring, backups, and audit processes to protect account, order, payment, usage, and support information. For refunds, chargebacks, abnormal calls, security incidents, or compliance review, we may keep more detailed records and perform additional review.
We will not ask you in support communications to provide complete payment credentials, passwords, plaintext API keys, or other unnecessary sensitive credentials. If troubleshooting requires screenshots or logs, you should redact unrelated sensitive information. If materials contain unnecessary sensitive information, we may ask you to submit a redacted version.
We use reasonable efforts to limit information sharing to what is relevant for providing the Services, processing payments, completing requests, troubleshooting issues, calculating bills, handling refunds, responding to disputes, meeting legal requirements, or protecting service security.
8. How We Share Information
We may share information with service providers that help us operate the Services, including hosting, databases, caching, networking, logging, monitoring, security, authentication, email, customer support, analytics, payment, tax, invoice, receipt, anti-fraud, compliance, audit, and professional advisory providers.
To complete service delivery, API requests, model calls, or technical processing, we may send necessary User Content, request information, account identifiers, usage information, and metadata to model services, API platforms, cloud providers, gateway providers, or other third-party platforms. Third parties process related information under their own terms, privacy policies, data processing rules, and use policies.
We may also disclose information when required by applicable law, subpoenas, court orders, government requests, tax authorities, payment network rules, audit requirements, or regulatory requirements, or to investigate fraud, chargebacks, payment disputes, abuse, security incidents, policy violations, infringement, sanctions risk, or to protect rights, property, safety, and service integrity.
If we are involved in a merger, acquisition, financing, restructuring, asset sale, bankruptcy, or similar transaction, information may be disclosed or transferred as part of that transaction. The recipient should continue to process information according to applicable law and the protection principles reflected in this Policy.
9. Retention
We retain information for as long as necessary to provide the Services, maintain account and order records, deliver service credits, calculate usage and billing, handle refunds and disputes, comply with tax and accounting obligations, prevent fraud and abuse, support security, meet audit and compliance requirements, and protect rights.
Account information is generally retained for a reasonable period after account closure. Order, tax, invoice, accounting, and dispute records may be retained longer as required by law or payment network rules. Security logs, diagnostic logs, and technical records are retained as needed for operations, security, and troubleshooting.
API request, error, and usage records may have different retention periods depending on feature, log type, security need, and compliance requirement. We retain such records within the scope necessary to provide the Services, troubleshoot issues, calculate bills, handle refunds, respond to disputes, prevent abuse, and meet legal requirements.
When information is no longer needed, we delete, anonymize, or restrict further processing according to applicable law and business processes.
10. International Transfers
VOC AI is located in the United States. We, our service providers, payment service providers, and third-party service providers may process information in the United States, Europe, Asia, or other countries and regions. Data protection laws in those locations may differ from the laws where you are located. We will use appropriate cross-border transfer safeguards where required by applicable law.
11. Security
We use administrative, technical, and organizational measures such as access controls, permission management, logs, reasonable encryption, monitoring, backups, audits, and internal processes to protect information. No system can be guaranteed absolutely secure. You are also responsible for protecting your account, password, email, devices, API keys, access credentials, payment account, and related service credentials.
If you believe your account, API key, payment method, or data has been accessed or used without authorization, contact us immediately.
12. Your Choices and Rights
You may update some account, billing, and team information in the dashboard. Depending on your location and applicable law, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, opt-out of certain data sharing, or to complain to a regulator.
We may need to verify your identity before processing a request. We may also retain certain information where allowed or required by applicable law, such as tax, accounting, security, risk control, payment, dispute, audit, compliance, or legal records.
We do not intentionally sell personal information for money. If applicable law treats certain advertising, analytics, or data sharing as a "sale" or "sharing," you may contact us to exercise any applicable opt-out rights.
13. Children's Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information to us, contact us so we can review and, where appropriate, delete it.
14. Policy Updates
We may update this Privacy Policy from time to time. Material changes may be notified through the website, dashboard, email, or other reasonable means. The updated Policy applies to information processing activities after the update.
15. Contact
For privacy questions, data requests, security reports, or data protection inquiries, contact support@flatkey.ai or write to VOC AI INC, 160 E Tasman Drive, Suite 202, San Jose, CA 95134, United States.
All of the above contents shall be subject to the English version.