Allow optional cookies for referral attribution, visit analytics, and Google Ads purchase measurement.
Data Minimization · Security AuditingLast updated: 2026-10-09
Privacy Policy
How model-request content, transaction and usage records, security evidence, and upstream processing differ, including redaction, encryption, retention, and your rights.
Terms, Prohibited Uses and Safe-Use Commitment
Guishu provides LLM API aggregation and relay services for llm-token.cn and llm-agent.cc through cloud providers, Token factories and computing platforms. These rules apply to all models, languages, purchases, top-ups and downstream apps. Chinese law and other applicable mandatory law prevail. The platform audits content. Necessary evidence may include input text or context, with rule-based redaction, encryption and restricted review. We do not promise zero retention, full anonymization or screening of every input and output. Upstream providers have separate policies.
Policy version: 2026-10-09.v1
Content Privacy and Safety
Minimal processing, transparent audit boundaries
We do not archive every conversation as chat history or use request content for our own model training or advertising profiles. Security audits may retain encrypted necessary request evidence and metadata. This is not a promise that no user data is stored.
Necessary onlyBusiness and usage records
Redacted / encryptedSecurity evidence
Restricted accessRecorded review actions
01
Scope and Model Requests
This policy applies to both llm-token.cn and llm-agent.cc. Guishu provides LLM API aggregation and relay services connecting cloud providers, Token factories, and computing platforms.
Prompts, conversation context, files, images, and other inputs are processed as needed to forward requests, perform content audits, and return responses. We do not provide a default archive of all conversations; security-audit records are described separately below.
We do not use this request content for our own model training, advertising, or user profiling. Do not submit state secrets, trade secrets you are not authorized to process, others’ private information, or unnecessary sensitive personal information.
02
Necessary Business and Usage Records
Email addresses, account identifiers, order numbers, payment status, plans, credited quota, delivery, and support records are used to provide service, investigate orders, issue refunds, and manage risk.
Order-linked policy version, document fingerprint, displayed language, site, confirmation method and server time record the notice and acceptance for the specific order. Scrolling or checking a box is not automatic immunity from liability.
API key information needed for validation, delivery, and top-ups is handled using fingerprints, masking, or encryption as appropriate. Plaintext display on public pages is limited by time and access conditions.
Call time, model, Token usage, response status, latency, request identifiers, and service-relevant IP, device, or security-event information support billing, quota reconciliation, diagnostics, and abuse prevention. These metadata records are distinct from content-audit evidence.
03
Content Audits, Redaction, and Encrypted Evidence
The platform has a content-audit mechanism. Rule matches, sampling, reports, appeals, or security incidents may require retention of request evidence, risk categories, enforcement outcomes, request identifiers, and context. Evidence can include input text, not only statistical metadata.
Recognized credential fields and some embedded data are redacted according to technical rules. Security evidence is encrypted; the management interface shows event metadata by default. Access to evidence requires authorization and records the operator, reason, and access action.
Automated redaction has limits and cannot guarantee removal of every personal detail in free text. Encrypted material can still be decrypted under authorized conditions, so encryption or masking is neither complete anonymization nor zero retention.
Audit data is used only as necessary for safety, abuse prevention, complaints and disputes, system maintenance, and legal duties. If model-assisted review is enabled, necessary request content or context may be sent to the upstream service performing review. This does not imply that every request has completed model or human review.
04
Upstream Services and Disclosure
Necessary content is sent to the upstream service for the selected model. Model providers, cloud providers, Token factories, and computing platforms process data under their own applicable policies, service terms, and legal duties. We cannot promise zero retention on their behalf.
Payment, notification, and infrastructure services process information as needed for transactions, delivery, operations, and safety. Processing abroad requires any notices, consent, or other procedures applicable to the actual data flow. This policy is not blanket authorization for any cross-border transfer.
We do not sell or rent model-request content. When legally required to provide information to competent authorities, we verify the requirement and limit disclosure to what is legally necessary.
05
Retention and Deletion
Account, order, payment, usage, security-log, and audit-evidence records are retained according to their purposes and applicable legal periods, then deleted or anonymized as required. Legally required network, transaction, and security records are not subject to a promise to erase everything at the end of a request.
The audit system supports separate evidence and metadata retention settings and cleanup. Applicable law, effective configuration, and incident needs determine the period. Ongoing complaints, disputes, or legal preservation duties may require extended retention of necessary records.
This policy does not claim a single retention period for every data category. Contact privacy support to ask about the categories, purposes, and applicable periods for your information.
06
Optional Measurement and Advertising
Optional Google Ads measurement on the international site is enabled after consent to measure visits that result in purchases. It may include campaign parameters, click identifiers, order number, amount, and currency. We do not send your email address or API key to Google Ads.
Model-request content is not used for advertising measurement. You can change optional measurement through the site’s privacy choices; declining it does not remove legally necessary order or security records.
07
Access and Your Rights
Contact [email protected] to request access, a copy, correction, supplementation, or deletion of your personal information, or to withdraw consent to applicable optional processing. We perform necessary identity checks and respond under applicable law.
Legal retention requirements, security incidents, or unresolved transaction disputes may limit immediate deletion; we will explain the applicable reason. Send only necessary order or request identifiers, never full API keys, passwords, or unrelated sensitive material.
If policy changes materially affect processing purposes, methods, or data categories, we will provide required notice and follow other applicable legal procedures.
Still have questions?
Reach our support team directly for anything about purchases, top-ups, delivery, or orders.