Dazzi AI File Manager
Sign in
LEGAL

Privacy Policy

Effective October 10, 2026

This policy explains what NomaDamas ("we", "us"), a business based in South Korea, collects when you use Dazzi AI File Manager at https://api.dazziapp.com and its API (the "Service"), why we collect it, and the choices you have. We are the controller of the personal information described here.

1. Information we collect

Information you give us

  • Account details: your email address. If you sign in with GitHub, Google or Apple we also receive the name, email address and profile image that provider shares with us.
  • Content you send to the models: the prompts, files, instructions, tool definitions and tool results you send to /v1/responses, and the text you send to /v1/embeddings and /v1/rerank. We forward this content to our model provider to produce a response. We do not store the content of your requests or the model's responses in our database.
  • API keys: the name you give a key and when it was created and last used. We store only a one-way hash of the key itself, so we cannot show it to you again.
  • Payment information: handled by our payment processor (see Section 4). We receive your plan, the status of your subscription, your billing email and a customer identifier. We never see your full card number.

Information collected automatically

  • Usage records: for each model request, your account, the model used, the type of request, the number of input and output tokens, the cost, a request identifier and a timestamp. We use these to enforce your plan's credits and show your usage.
  • Session data: when you sign in on the web, we store a session record with its expiry time, your IP address and your browser's user-agent string.
  • Rate-limit counters: a counter per account (and, for the desktop sign-in endpoint, per IP address) for the current minute, used to protect the Service from abuse.
  • Server logs: our hosting provider records request metadata (such as time, path, status and IP address) and error messages from our application. Error messages can include your internal account identifier.

What we do not collect

We do not run advertising, analytics or tracking scripts, and we do not use third-party tracking cookies. We do not sell personal information and we do not share it for cross-context behavioral advertising.

2. How we use information

  • to create and secure your account, send sign-in codes and authenticate API keys;
  • to provide the Service: route your requests to models, meter usage against your plan and process subscriptions;
  • to communicate with you about your account, security and billing (we do not send marketing email);
  • to detect, investigate and prevent abuse, fraud and violations of our Acceptable Use Policy;
  • to comply with law and to establish or defend legal claims.

3. Cookies

We use only the cookies that are strictly necessary to keep you signed in on the website: a session cookie set when you sign in, and short-lived cookies used during social sign-in to prevent forgery. We set no cookies before you sign in and none for advertising or analytics. The API (/v1) does not use cookies; it uses API keys.

4. Who we share information with

We share information only with the service providers listed on our Subprocessors page, who process it for us:

  • OpenRouter receives the content of your model requests and routes them to the model provider you select (for example Anthropic, OpenAI, DeepSeek, Z.ai, Alibaba or Xiaomi). Those providers have their own data-retention and training policies, and some may retain request content. Because the Service routes through OpenRouter's default provider selection, do not send information you are not comfortable sharing with these providers.
  • Creem acts as our merchant of record and payment processor for subscriptions. Creem is an independent controller of your payment information under its own privacy notice.
  • Resend delivers our sign-in code emails.
  • Vercel hosts the Service, and Neon hosts our database.
  • GitHub, Google and Apple authenticate you if you choose to sign in with them.

We may also disclose information if required by law or to protect the rights, safety or property of users, the public or us, and to a successor in a merger, acquisition or sale of assets, subject to this policy.

5. Retention

  • Account and usage records are kept while your account is open and deleted or de-identified after you delete your account, except where we must keep them (for example billing records for tax and accounting).
  • Sessions last up to 7 days and are extended while you use the Service. Sign-in codes expire after 10 minutes and are stored only as a hash.
  • Request content is not retained by us. How long our providers keep it is governed by their policies.

6. Security

We protect information with encryption in transit (HTTPS), hashed storage of API keys and sign-in codes, per-account rate limiting and access controls on our systems. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Your choices and rights

You can see your usage and manage or revoke API keys in the dashboard. To access, correct, export or delete your personal information, or to close your account, email privacy@dazziapp.com. We will respond within 45 days, or sooner where the law requires. We will not discriminate against you for exercising these rights.

United States residents (California and other states)

Residents of California and other US states with privacy laws may have the right to know what personal information we collect, to request access, correction and deletion, to obtain a portable copy, and to opt out of the sale or sharing of personal information and of targeted advertising. We do none of the latter, so there is nothing to opt out of. You may use an authorized agent to submit a request; we may need to verify your identity and the agent's authority. If we deny a request you may appeal by replying to our decision.

Other regions

If you are in the European Economic Area, United Kingdom or South Korea, you may also object to or restrict processing and lodge a complaint with your local data protection authority. Our legal bases are performing our contract with you, our legitimate interests in securing and improving the Service, compliance with law, and consent where we ask for it.

8. International transfers

We operate from South Korea, and our providers process information in the United States and other countries. By using the Service you understand that your information will be transferred to and processed in countries whose data-protection laws may differ from those where you live.

9. Children

The Service is not directed to children under 13 (or under 16 where local law sets a higher age), and we do not knowingly collect their personal information. If you believe a child has given us information, contact us and we will delete it.

10. Changes

We may update this policy. We will post the new version here with a new effective date and, for material changes, notify you by email or in the Service.

11. Contact

NomaDamas, South Korea · privacy@dazziapp.com

Privacy PolicyTerms of ServiceAcceptable UseRefund PolicySubprocessors

Dazzi AI File Manager is operated by NomaDamas, South Korea. Questions: support@dazziapp.com