Hype API 隐私政策
生效日期:2025年12月5日
感谢您使用 Hype API(以下简称"本服务"或"我们")。我们非常重视您的隐私保护。本隐私政策旨在说明我们如何收集、使用、存储和保护您的个人信息。
本政策适用于以下服务:
使用本服务即表示您同意本隐私政策中描述的数据处理方式。请仔细阅读本政策。
1. 信息收集
1.1 我们收集的信息
当您使用本服务时,我们会收集以下信息:
通过 Discord 认证收集的信息:
- Discord 用户 ID
- Discord 用户名
- 电子邮件地址
API 使用日志:
- 请求时间戳
- 调用的 API 端点
- 错误日志(如有)
- 输入令牌数量(Input Token Count)
- 输出令牌数量(Output Token Count)
- IP 地址(每次请求,无论成功或失败,用于安全、日志记录和滥用防护)
重要说明: 我们不会记录您的请求内容(提示词/prompt)和 API 响应内容。
兑换系统(redeem.hype3808.dev)收集的信息:
- 用户 ID(来自 api.hype3808.dev)
- 访问令牌(Access Token,用于 API 验证,仅在兑换过程中使用)
重要说明:
- 对于所有用户:用户 ID 和访问令牌不会被保存或记录
- 对于默认用户(default):用户 ID 会被保存在数据库中,仅用于记录 24 小时兑换冷却时间
- 兑换系统使用 Cloudflare 作为 CDN 和 DDoS 防护
1.2 Cookies 和类似技术
本服务使用 Cookies 来存储您的登录会话信息,以便您能够保持登录状态并正常使用服务。
1.3 Cloudflare 收集的信息
我们使用 Cloudflare 作为 CDN 和 DDoS 防护服务。Cloudflare 可能会收集以下技术信息;此外,我们会收集并可能记录每次请求的 IP 地址(无论请求是否成功),用于安全、日志记录与滥用防护:
- IP 地址(用于安全防护、流量路由与滥用调查)
- 浏览器类型和版本
- 访问时间戳
- HTTP 请求头信息
这些信息由 Cloudflare 及我们为安全目的收集和处理。Cloudflare 的数据处理受其隐私政策约束;我们可能会为调查或安全分析而保留 IP 记录,保留期限为合理期限以支持安全与法务需要。
1.4 我们不收集的信息
- 我们不记录您的 API 请求内容和响应内容
- 我们不使用任何分析或追踪工具
- 我们不收集您的浏览历史或设备信息
2. 信息使用
2.1 我们如何使用您的信息
我们收集的信息仅用于以下目的:
- 身份验证: 验证您的身份并提供访问权限
- 服务提供: 维护和改进本服务的功能
- 安全保护: 监测和防止滥用、欺诈或非法活动
- 技术支持: 协助解决您可能遇到的问题
- 速率限制: 实施每分钟 2 次请求的速率限制
- 服务优化: 通过使用统计数据改进服务性能
2.2 我们不会将您的信息用于
- 营销或广告目的
- 出售或出租给第三方
- 与未经授权的第三方共享
3. 信息存储与安全
3.1 数据存储
- API 服务(api.hype3808.dev): 数据存储在 DigitalOcean 的虚拟专用服务器(VPS)上,使用 PostgreSQL 数据库
- 兑换系统(redeem.hype3808.dev): 默认用户的兑换冷却时间记录存储在 Neon.tech 托管的 PostgreSQL 数据库中
3.2 数据保留期限
- 只要本服务持续运营,您的账户数据将被保留
- 如果您删除账户,您的数据将被永久删除
- API 使用日志将保留合理期限以维护服务安全和性能
3.3 安全措施
我们采取以下安全措施保护您的数据:
- 数据加密: 传输和存储过程中的数据加密
- 安全服务器: 使用行业标准的安全服务器配置
- 数据库安全: PostgreSQL 数据库采用强密码保护
- 访问控制: 严格限制对用户数据的访问权限
- DDoS 防护: 使用 Cloudflare 提供 DDoS 攻击防护和流量过滤
- CDN 加速: 通过 Cloudflare CDN 提供安全的内容分发
- 定期备份: 定期备份数据以防止数据丢失
尽管我们采取了合理的安全措施,但请注意,没有任何互联网传输或电子存储方法是 100% 安全的。
4. 信息共享与披露
4.1 第三方服务提供商
本服务使用以下第三方服务:
- Discord: 用于用户身份验证
- Auth0: 用于 OIDC 身份验证流程
- DigitalOcean: 用于 API 服务的数据存储和服务托管
- Neon.tech: 用于兑换系统的数据库托管(仅存储默认用户的兑换冷却时间)
- Cloudflare: 用于所有服务的内容分发网络(CDN)和 DDoS 防护
这些第三方服务提供商有其自己的隐私政策,我们建议您查阅:
4.2 法律要求
在以下情况下,我们可能会披露您的信息:
- 遵守法律义务或法律程序
- 响应政府或执法机构的合法请求
- 保护我们的权利、财产或安全
- 防止欺诈或安全威胁
4.3 不会出售数据
我们永远不会出售、交易或出租您的个人信息给第三方用于营销目的。
5. 您的权利
作为用户,您享有以下权利:
5.1 访问权
您有权请求访问我们持有的关于您的个人信息。
5.2 删除权
您有权要求删除您的个人信息。删除账户后,所有相关数据将被永久删除。
5.3 修改权
您有权更新或修改您的个人信息(通过 Discord 账户管理)。
5.4 撤回同意权
您可以随时停止使用本服务并要求删除您的数据。
5.5 如何行使您的权利
要行使上述任何权利,请通过以下方式联系我们:
6. 儿童隐私
6.1 年龄限制
本服务不面向未达到其所在国家或地区法定年龄的儿童。
6.2 家长同意
如果您未达到法定年龄,您必须在家长或监护人的同意和监督下使用本服务。
6.3 儿童数据保护
如果我们发现在未经适当同意的情况下收集了未成年人的信息,我们将采取措施尽快删除该信息。
7. 国际数据传输
由于本服务使用云基础设施,您的数据可能会在您所在国家或地区以外的地方进行处理和存储。使用本服务即表示您同意此类数据传输。
8. 数据保护合规
虽然本服务的运营者位于马来西亚,但我们致力于遵守适用的数据保护法律法规,包括但不限于:
- 马来西亚个人数据保护法(PDPA)
- 其他适用的国际数据保护标准
9. 自动化决策
本服务不使用基于您个人数据的自动化决策或分析。速率限制等技术措施基于使用模式而非个人特征。
10. 隐私政策变更
10.1 更新通知
我们可能会不时更新本隐私政策。重大变更时,我们会通过以下方式通知您:
- 在 Discord 服务器(Odysseia/类脑)中发布公告
- 更新本页面顶部的"生效日期"
10.2 继续使用
在隐私政策更新后继续使用本服务即表示您接受修改后的政策。
11. 联系我们
如果您对本隐私政策有任何疑问、意见或投诉,或希望行使您的数据权利,请通过以下方式联系我们:
我们将在收到您的请求后尽快(通常在 30 天内)回复。
12. 数据泄露通知
如果发生可能影响您个人信息安全的数据泄露事件,我们将:
- 及时评估泄露的范围和影响
- 在合理时间内通知受影响的用户
- 采取措施减轻潜在损害
- 根据法律要求向相关监管机构报告
13. 第三方链接
本服务可能包含指向第三方网站或服务的链接(如 SillyTavern、Discord)。我们不对这些第三方的隐私实践负责。我们建议您查阅这些网站的隐私政策。
14. 业务转让
如果本服务的所有权发生变更(如出售、合并或收购),您的信息可能会作为资产的一部分转让。在此情况下,我们会通知您,且新所有者将继续受本隐私政策的约束。
15. 完整协议
本隐私政策与《Hype API 用户协议》共同构成您与我们之间关于隐私和数据保护的完整协议。
重要提示:
- ✅ 我们仅收集必要的信息(Discord ID、用户名、邮箱)
- ✅ 我们不记录您的请求内容和响应内容
- ✅ 我们使用安全的数据存储和加密措施
- ✅ 您可以随时请求访问、修改或删除您的数据
- ✅ 我们永远不会出售您的数据
您的隐私对我们很重要。如有任何疑问,请随时联系我们。
Hype API Privacy Policy
Effective Date: December 5, 2025
Thank you for using Hype API (hereinafter referred to as "the Service" or "we"). We take your privacy very seriously. This Privacy Policy explains how we collect, use, store, and protect your personal information.
This policy applies to the following services:
By using the Service, you agree to the data processing methods described in this Privacy Policy. Please read this policy carefully.
1. Information Collection
1.1 Information We Collect
When you use the Service, we collect the following information:
Information Collected via Discord Authentication:
- Discord User ID
- Discord Username
- Email Address
API Usage Logs:
- Request timestamps
- API endpoints called
- Error logs (if any)
- Input Token Count
- Output Token Count
- IP address (for each API request, successful or failed; collected for security, logging and abuse prevention)
Important Note: We do NOT log your request content (prompts) or API response content.
Information Collected by Redemption System (redeem.hype3808.dev):
- User ID (from api.hype3808.dev)
- Access Token (for API verification, used only during redemption process)
- IP address (collected for each redemption attempt, successful or failed)
Important Notes:
- For all users: User ID and Access Token are NOT saved or logged (except where noted for cooldown tracking)
- For Default Users only: User ID is saved in the database solely to track the 24-hour redemption cooldown
- IP addresses from redemption attempts may be logged and retained for security and abuse investigations
- The Redemption System uses Cloudflare as CDN and DDoS protection
1.2 Cookies and Similar Technologies
The Service uses Cookies to store your login session information so you can remain logged in and use the service normally.
1.3 Information Collected by Cloudflare
We use Cloudflare as our CDN and DDoS protection service. Cloudflare may collect the following technical information; in addition, we collect and may retain IP addresses for each request (successful or failed) for security, logging and abuse prevention:
- IP addresses (for security protection, traffic routing, and abuse investigation)
- Browser type and version
- Access timestamps
- HTTP request header information
This information is collected and processed by Cloudflare and by us for security purposes. Cloudflare's data processing is governed by its privacy policy; we may retain IP records for a reasonable period to support security investigations and legal compliance.
1.4 Information We Do NOT Collect
- We do not log your API request content or response content
- We do not use any analytics or tracking tools
- We do not collect your browsing history or device information
2. Information Usage
2.1 How We Use Your Information
The information we collect is used solely for the following purposes:
- Authentication: Verify your identity and provide access
- Service Provision: Maintain and improve service functionality
- Security Protection: Monitor and prevent abuse, fraud, or illegal activities
- Technical Support: Assist in resolving issues you may encounter
- Rate Limiting: Implement 2 requests per minute rate limit
- Service Optimization: Improve service performance through usage statistics
2.2 We Will NOT Use Your Information For
- Marketing or advertising purposes
- Selling or renting to third parties
- Sharing with unauthorized third parties
3. Information Storage and Security
3.1 Data Storage
- API Service (api.hype3808.dev): Data is stored on DigitalOcean Virtual Private Servers (VPS) using PostgreSQL database
- Redemption System (redeem.hype3808.dev): Default users' redemption cooldown records are stored in a PostgreSQL database hosted on Neon.tech
3.2 Data Retention Period
- Your account data will be retained as long as the Service continues to operate
- If you delete your account, your data will be permanently deleted
- API usage logs will be retained for a reasonable period to maintain service security and performance
3.3 Security Measures
We take the following security measures to protect your data:
- Data Encryption: Encryption during transmission and storage
- Secure Servers: Industry-standard secure server configurations
- Database Security: PostgreSQL database with strong password protection
- Access Control: Strict limitations on user data access
- DDoS Protection: Using Cloudflare for DDoS attack protection and traffic filtering
- CDN Acceleration: Secure content delivery through Cloudflare CDN
- Regular Backups: Regular data backups to prevent data loss
Although we take reasonable security measures, please note that no method of Internet transmission or electronic storage is 100% secure.
4. Information Sharing and Disclosure
4.1 Third-Party Service Providers
The Service uses the following third-party services:
- Discord: For user authentication
- Auth0: For OIDC authentication flow
- DigitalOcean: For API service data storage and hosting
- Neon.tech: For Redemption System database hosting (stores only default users' redemption cooldown)
- Cloudflare: For Content Delivery Network (CDN) and DDoS protection for all services
These third-party service providers have their own privacy policies, which we recommend reviewing:
4.2 Legal Requirements
We may disclose your information in the following circumstances:
- Compliance with legal obligations or legal processes
- Response to legitimate government or law enforcement requests
- Protection of our rights, property, or safety
- Prevention of fraud or security threats
4.3 No Data Sales
We will never sell, trade, or rent your personal information to third parties for marketing purposes.
5. Your Rights
As a user, you have the following rights:
5.1 Right to Access
You have the right to request access to personal information we hold about you.
5.2 Right to Deletion
You have the right to request deletion of your personal information. After account deletion, all related data will be permanently deleted.
5.3 Right to Modification
You have the right to update or modify your personal information (through Discord account management).
5.4 Right to Withdraw Consent
You can stop using the Service at any time and request deletion of your data.
5.5 How to Exercise Your Rights
To exercise any of the above rights, please contact us through:
6. Children's Privacy
6.1 Age Restrictions
The Service is not intended for children who have not reached the legal age in their country or region.
6.2 Parental Consent
If you have not reached legal age, you must use this Service under the consent and supervision of a parent or guardian.
6.3 Children's Data Protection
If we discover that we have collected information from minors without appropriate consent, we will take steps to delete such information as soon as possible.
7. International Data Transfers
Because the Service uses cloud infrastructure, your data may be processed and stored outside your country or region. By using the Service, you consent to such data transfers.
8. Data Protection Compliance
Although the Service operator is located in Malaysia, we are committed to complying with applicable data protection laws and regulations, including but not limited to:
- Malaysia Personal Data Protection Act (PDPA)
- Other applicable international data protection standards
9. Automated Decision-Making
The Service does not use automated decision-making or profiling based on your personal data. Technical measures such as rate limiting are based on usage patterns rather than personal characteristics.
10. Privacy Policy Changes
10.1 Update Notifications
We may update this Privacy Policy from time to time. For significant changes, we will notify you through:
- Announcements on the Discord server (Odysseia)
- Updating the "Effective Date" at the top of this page
10.2 Continued Use
Continued use of the Service after Privacy Policy updates indicates your acceptance of the modified policy.
11. Contact Us
If you have any questions, comments, or complaints about this Privacy Policy, or wish to exercise your data rights, please contact us through:
We will respond to your request as soon as possible (typically within 30 days).
12. Data Breach Notification
If a data breach occurs that may affect the security of your personal information, we will:
- Promptly assess the scope and impact of the breach
- Notify affected users within a reasonable timeframe
- Take measures to mitigate potential harm
- Report to relevant regulatory authorities as required by law
13. Third-Party Links
The Service may contain links to third-party websites or services (such as SillyTavern, Discord). We are not responsible for the privacy practices of these third parties. We recommend reviewing the privacy policies of these websites.
14. Business Transfers
If ownership of the Service changes (such as through sale, merger, or acquisition), your information may be transferred as part of the assets. In such cases, we will notify you, and the new owner will continue to be bound by this Privacy Policy.
15. Complete Agreement
This Privacy Policy, together with the Hype API User Agreement, constitutes the complete agreement between you and us regarding privacy and data protection.
Important Highlights:
- ✅ We only collect necessary information (Discord ID, username, email)
- ✅ We do NOT log your request content or response content
- ✅ We use secure data storage and encryption measures
- ✅ You can request access, modification, or deletion of your data at any time
- ✅ We will never sell your data
Your privacy is important to us. If you have any questions, please feel free to contact us.