Privacy Policy
Effective October 7, 2026
MR Enterprises runs OneAIPass at oneaipass.com. This page explains what we collect and why. It describes how the service works today; we will update it if that changes.
What we collect
- Account: your email address and a hash of your API key (we cannot recover your key).
- Usage records: for each request, the model, token counts, cost, timestamp and status, used for billing, abuse prevention and your usage page.
- Credit ledger: top-ups, refunds and debits on your balance.
- Payment information: handled by Stripe. We receive a payment confirmation and receipt email, never your card number.
- Technical data: IP address and request metadata in server logs for security and rate limiting.
Your prompts
To answer a request we forward your prompt to the model provider that serves it. That provider handles it under its own terms and privacy policy. Prompts may also be checked by a moderation step before they are sent. [TODO for owner: confirm and state exactly whether prompt and response text is retained on our side, and for how long.]
Cookies and storage
We do not use advertising cookies. If you tick "remember" on the account page, your API key is stored in your browser's local storage on that device; otherwise it is kept only for the browser session. You can forget it with the button on the account page.
Analytics
We use Google Analytics 4 to understand which pages are visited and how people find the site. It runs in Google's Consent Mode with everything switched off by default: until you click "Accept" on the analytics notice, no analytics or advertising cookies are set and Google receives only cookieless pings without any identifier that could recognise you across visits. If you accept, Google Analytics sets first-party cookies (such as _ga) to recognise repeat visits. Advertising features, Google signals and ad personalisation are turned off. Page addresses are sent without query strings, Google Analytics 4 does not log or store IP addresses, and analytics are not loaded at all on the account page or the checkout result pages, so your API key is never sent to an analytics provider.
Your choice is remembered in your browser's local storage. Change analytics choice.
Sharing
We share data only with the providers needed to run your requests, Stripe for payments, Google for site analytics as described above, and our email and hosting providers. We do not sell personal data.
Your choices
You can export your account data and delete your account through the API (/v1/account/export, DELETE /v1/account) or by emailing support@oneaipass.com. Some billing records may be kept where the law requires.
Contact
MR Enterprises, [ENTITY_ADDRESS] · support@oneaipass.com