How we handle your data. Short version: we collect almost nothing.

No Tracking

This website and the API use no cookies, no analytics, no fingerprinting, and no third-party trackers. We do not use Google Analytics, Meta Pixel, or any equivalent service. There is no tracking code on any page.

Identity and Authentication

Your API key is generated client-side in your browser and stored in localStorage. The server never receives your raw key. We store only a SHA-256 hash of the key, from which a decentralized identifier (DID) is derived. No email address or password is collected or stored.

What We Log

For billing and abuse prevention, each API request generates a metadata record containing: timestamp, model used, token count, and cost. We do not log prompt content, completion content, or any part of your input/output data.

No Training on Your Data

Your inputs and outputs are never used for training, fine-tuning, or improving any model. api.mutual.ai is a routing gateway — it does not host or train models.

Payment Processing

Payments are processed through Pabbly Subscriptions, a PCI-compliant payment platform. We do not store credit card numbers or payment credentials on our servers.

Hosting

This service is operated and hosted in Germany by mesh. GmbH, Friedrichshafen.

Your Rights (GDPR)

Under the General Data Protection Regulation, you have the right to:

Access — request a copy of data we hold about your identity
Rectification — correct inaccurate data
Erasure — request deletion of your data
Portability — receive your data in a machine-readable format

To exercise these rights, contact info@mesh.email.

Supervisory Authority

You have the right to lodge a complaint with the competent data protection authority:

Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
www.baden-wuerttemberg.datenschutz.de