← Back to Legal

Privacy Policy

Effective date: April 19, 2026 · Last updated: April 19, 2026

1. Who We Are (Data Controller)

Hlias Staurou, an individual operating from Athens, Greece, is the data controller for personal data processed through the AetherCode Coder API (the "Service").

Contact: hliasstaurou@gmail.com

This Policy explains what data we process, why, on what legal basis, how long we retain it, and your rights under the EU General Data Protection Regulation (GDPR) and Greek Law 4624/2019.

2. Scope

This Policy applies to personal data processed when you:

It does NOT cover data processed by RapidAPI (which handles account registration, authentication, billing, and payment). RapidAPI is a separate data controller with its own privacy policy at rapidapi.com/privacy.

3. What We Process

3.1 Request content (Input)

The text of prompts you submit ("messages"), your chosen parameters (model, temperature, max_tokens, etc.), and HTTP headers attached by RapidAPI or by you directly. Prompts may contain personal data if you choose to include it; we ask that you do not submit third-party personal data without a legal basis.

3.2 Response content (Output)

The code and text returned by upstream language-model providers in response to your Input, plus internal metadata such as verification gate results, heal attempts, and timing.

3.3 Technical metadata

3.4 What we do NOT process

4. Why We Process (Purposes and Legal Basis)

PurposeData usedGDPR legal basis
Generate and return code in response to your promptInput, parameters, headersContract performance (Art. 6(1)(b))
Bill you per request (via RapidAPI)Consumer ID, request count, planContract performance (Art. 6(1)(b))
Operate the ATLAS verifier and HYDRA healer on outputOutput (transient)Contract performance (Art. 6(1)(b))
Detect abuse, rate-limit violations, fraudMetadata, counts, request patternsLegitimate interest (Art. 6(1)(f))
Respond to your support emailsEmail content, email addressLegitimate interest (Art. 6(1)(f))
Comply with legal obligationsAs requiredLegal obligation (Art. 6(1)(c))

5. Retention Periods

DataRetentionWhere
Prompt content (Input)Not persistently stored beyond request lifetimeRAM only
Generated code (Output)Not persistently stored beyond request lifetime (except truncated excerpt in observability trace, 30 days)Langfuse
Metering events (metadata only, no prompt content)90 daysOrigin server (JSONL)
Observability traces (hashed/truncated content)30 daysLangfuse
Cloudflare edge logsPer Cloudflare policyCloudflare
Support emails24 monthsEmail provider

We retain aggregated, non-identifying statistics (e.g., total monthly requests per provider) indefinitely for capacity planning.

6. Third-Party Processors and International Transfers

To deliver the Service, we share data with the following processors. Data transferred outside the European Economic Area (EEA) is protected by Standard Contractual Clauses, adequacy decisions, or equivalent safeguards under GDPR Chapter V.

ProcessorRoleLocationWhat is shared
Cloudflare, Inc.Edge/CDN, Worker hosting, KV storeGlobal edge (EU nodes used for EU traffic)Full request/response, metadata
Hetzner Online GmbHServer hosting (Frankfurt, Germany)Germany (EEA)Full request/response, metadata
DeepSeekLLM inferenceChinaPrompt content, generated code
Google (Gemini API)LLM inferenceUnited States / EU regionalPrompt content, generated code
Moonshot AI (Kimi)LLM inferenceChinaPrompt content, generated code
OpenRouterLLM inference routingUnited StatesPrompt content, generated code
Langfuse (self-hosted)ObservabilityGermany (our server)Hashed/truncated metadata
RapidAPI (Nokia Inc.)Marketplace, auth, billingUnited StatesAccount data, usage counts

Important: If you do not want your prompts transmitted to providers outside the EEA (e.g., DeepSeek in China or OpenRouter in the US), do not submit sensitive personal data through the Service. We select the upstream provider automatically based on availability, cost, and quality routing; you cannot currently pin a specific provider.

7. Your Rights (GDPR)

If you are located in the EU or UK, you have the following rights:

To exercise any of these rights, email hliasstaurou@gmail.com. We respond within 30 days.

8. Security

We apply the following technical and organizational measures:

No system is perfectly secure. In the event of a personal data breach affecting EU residents and posing a risk to their rights, we will notify the Hellenic DPA within 72 hours as required by GDPR Art. 33.

9. Children

The Service is intended for developers aged 18 or older. We do not knowingly collect data from children under 16. If you believe a minor has submitted data, contact us and we will delete it.

10. Automated Decision-Making

The Service does not make decisions producing legal or similarly significant effects on you within the meaning of GDPR Art. 22. Automated routing, verification, and healing are operational functions, not decisions about your person.

11. Changes to This Policy

We may update this Policy. The "Last updated" date at the top reflects the most recent revision. Material changes will be announced at least 30 days in advance by updating this page and, where feasible, via the API listing on RapidAPI.

12. Contact

Questions, complaints, or data-subject requests: hliasstaurou@gmail.com

Data Controller: Hlias Staurou, Athens, Greece