Legal
Privacy Policy
Version 2026-10-11 · Effective 11 October 2026
What personal data we process when you use Milkxi, why, on what legal basis, for how long, where, and who processes it for us.
01Who is responsible
This policy covers Milkxi: the website, the dashboard and the API. For the personal data described here, QWEST Ι.Κ.Ε. is the controller, which means that we decide why and how it is processed and answer for it.
- Legal name
- QWEST Ι.Κ.Ε. (QWEST P.C.)
- Legal form
- a private company (Ιδιωτική Κεφαλαιουχική Εταιρεία) under the laws of Greece
- Registered office
- Aristotelous 11-15, 104 32 Athens, Greece
- General Commercial Registry (Γ.Ε.ΜΗ.)
- 189031301000
- VAT number
- EL803084930
- aristogiannisphilippis@gmail.com
We have not appointed a data protection officer, because the law does not require one of a company of our size and activity. Write to the address above about anything in this policy, with “Privacy” in the subject so that it reaches the right person quickly.
02Your prompts and completions
We don't store your prompts or completions.
What you send to the API is passed to the model to produce the answer, and the answer is passed back to you. Neither is written to a database, a log or a backup by us. The provider that runs the model for us, which is in the list in clause 5, processes them in memory to produce the answer; it does not keep them, and it does not use them to train models. Prompts and answers travel to and from the United States, where the model runs (clause 4).
If what you send includes personal data about other people, such as the messages of the users of your own product, you are the controller of that data and we process it on your instructions, under the Data Processing Agreement.
03What we collect, why, and on what legal basis
For each kind of personal data, this clause says what it is, why we process it, and the legal basis for it under Article 6(1) of the General Data Protection Regulation (GDPR). How long we keep each kind is in clause 6.
Your account
Your name, your email address, your password (stored as a hash we cannot reverse), whether your address has been verified, the workspaces you belong to with your role in each, and the record of the terms you accepted when you signed up: which version of the terms and of this policy, when, and from which address.
Purpose: to provide the service you signed up for, to sign you in, to let your team find you, and to show what was agreed between us. Legal basis: Article 6(1)(b) GDPR, the contract between us, and, for the record of acceptance, Article 6(1)(f) GDPR, our legitimate interest in being able to show what was agreed.
Usage metadata
For each request to the API we record that it happened and what it cost: the time, the workspace and the API key, the model, the service tier and the interaction tone, whether the answer was streamed, the number of tokens in and out, the cost, how long it took, and whether it succeeded or with which error. Not the request itself, and not the answer. After 90 days we keep only daily totals of requests, tokens and cost for each key and model, which are the usage history you see in the dashboard.
Purpose: to charge for the service correctly, to show you your usage and your spending, to answer questions about a request, and to keep the service secure. Legal basis: Article 6(1)(b) GDPR, the contract, and Article 6(1)(f) GDPR, our legitimate interest in billing correctly and keeping the service secure.
Billing
Your top-ups, your balance, the credits that requests have used, refunds, and the payments behind them. Payments are taken by our payment processor on its own pages, where it collects your card details, your billing address and, if you buy as a business, your VAT number: we never see your card number (clause 5). We keep the amount, the date, the tax, the identifier of the payment, and the email address the receipt was sent to.
Purpose: to take payment, to credit your workspace, to send you a receipt and a confirmation, to handle refunds and disputes, and to keep the accounting records the law requires. Legal basis: Article 6(1)(b) GDPR, the contract, and Article 6(1)(c) GDPR, our legal obligations under tax and accounting law.
Security and audit
When you sign in or use the dashboard, we process your IP address and the kind of browser you use, to keep sessions safe and to limit sign-in attempts. Requests to the site and to the API are logged with their metadata and the address they came from. Changes made in a workspace, such as creating a key, buying credits or inviting a member, are written to an audit log with who made them and from which address, which the owners and admins of the workspace can read.
Purpose: to keep the service and your account secure, to prevent fraud and abuse, and to show the members of a workspace who changed what in it. Legal basis: Article 6(1)(f) GDPR, our legitimate interest in a secure service and the interest of a workspace in an accountable one.
We email you to verify your address, to reset your password, when someone invites you to a workspace, to confirm a purchase, and to tell you about changes to the service or to the terms. When you write to us, we keep your message and our answer for as long as it takes to deal with it and to show what was said. We send no marketing email.
Purpose: to run your account and to answer you. Legal basis: Article 6(1)(b) GDPR, the contract, and Article 6(1)(f) GDPR, our legitimate interest in answering the people who write to us.
Cookies and browser storage
We use only what the site needs to work, which the law calls strictly necessary: a cookie that keeps you signed in, your choice of theme in the local storage of your browser, and, while you use the playground, a short-lived key in the session storage of the tab. We use no analytics, no advertising and no tracking, and we set no third-party cookies. The pages of our payment processor set cookies of their own, under its policy. No consent is asked for, because none of this is used for anything but providing the service you asked for.
What you have to give us
To open an account you have to give a name, an email address and a password. To buy credits you have to give our payment processor a card, a billing address and, for a business in another EU country, a VAT number. Nothing else is required, and we ask for nothing else. We do not collect special categories of personal data, and we ask you not to send any through the API unless you have a lawful basis to.
04Where your data is stored
Everything we store is held in the United States, by our hosting provider, in the region named in clause 5; its backups are kept there too. Your prompts and answers travel there to be answered. Our payment processor processes payment data in the United States and in Ireland.
A transfer of personal data from the European Economic Area to the United States is safeguarded in two ways. Each of the two companies in clause 5 is certified under the EU-U.S. Data Privacy Framework, which the European Commission has found to give adequate protection (its decision of 10 July 2023). In addition, our agreement with each of them includes the standard contractual clauses of the European Commission, so that the transfer stays lawful should the Framework ever cease to apply. You may ask us for a copy of the clauses.
05Who receives your data
These companies process personal data on our behalf, as our processors:
- Amazon Web Services, Inc. — hosts the site, the API and the database, runs the model that answers requests, and sends our email. Location: United States (the us-east-1 region, in Northern Virginia). Transfer safeguard: certified under the EU-U.S. Data Privacy Framework; its data processing addendum includes the standard contractual clauses of the European Commission.
- Stripe, Inc. and Stripe Payments Europe, Limited — takes payments: it collects card details, the billing address and the tax ID on its own pages, charges the card and emails the receipt. Location: United States and Ireland. Transfer safeguard: Stripe, Inc. is certified under the EU-U.S. Data Privacy Framework; its data processing agreement includes the standard contractual clauses of the European Commission.
Our payment processor is a processor for us when it takes a payment, credits it to you and sends the receipt. For its own duties, such as preventing fraud and complying with the laws that apply to payments, it decides for itself what it does with the data it collected, and is then a controller in its own right, under its own privacy policy, which its checkout pages link to.
Beyond these, we disclose personal data only to the members of your own workspace, who see your name and email address and, if they are owners or admins, what you did in it; to public authorities, where the law requires it or to establish or defend a legal claim; to our professional advisers, under confidentiality; and to a company that takes over the service or our business, of which we tell you in advance. We do not sell personal data, and we show no advertising.
06How long we keep it
We keep personal data for as long as the purpose it was collected for needs it, and then for as long as the law requires:
| What | How long | Why |
|---|---|---|
| Your account: name, email address, password (as a hash), the workspaces you belong to, and the record of the terms you accepted | Until you close your account, and then for 7 days in backups. The record of the terms you accepted is kept for as long as a claim about the agreement could be brought. | To provide the service, and to show what was agreed |
| Per-request usage records | 90 days | To bill correctly, to answer questions about a request, and to keep the service secure |
| Daily usage totals, the credit ledger and the audit log of a workspace | While the workspace exists | Your usage history, your balance, and who changed what |
| Accounting records: payments, refunds, receipts and invoices | At least five years from the end of the year of the payment, as Greek tax and accounting law requires | A legal obligation |
| Sessions, with the address and the kind of browser they were opened from | Until you sign out, or 7 days after the session was last used | To keep you signed in, and to keep sessions safe |
| Server logs: the metadata of requests to the site and to the API, with the address they came from | 30 days | To keep the service secure and to find faults |
| Backups of the database | 7 days | To restore the service after a failure |
When a period ends, the data is deleted or made anonymous. Data that is in a backup is deleted when the backup is.
07Your rights
Under the GDPR you have the right:
- to know whether we process personal data about you, and to get a copy of it;
- to have data that is wrong corrected;
- to have your data deleted, where we have no legal duty or overriding reason to keep it;
- to have its processing restricted while a dispute about it is settled;
- to receive the data you gave us in a machine-readable form, and to have it sent to another provider where that is technically possible;
- to object to processing we base on our legitimate interests, on grounds of your own situation, after which we stop unless we show compelling grounds to go on.
To use any of these rights, write to the address in clause 1. We may ask you to confirm that you are who you say you are. We answer within one month of receiving your request; where a request is complex, we may take up to two months more, and we tell you so within the first month. Using your rights costs nothing.
Some of this you can do yourself: the dashboard shows and exports your usage, its settings page changes your name and your password, and an owner can delete a workspace there (clause 11 of the Terms of Service).
If you think we process your data unlawfully, you may complain to a supervisory authority: in Greece, the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens, Greece, www.dpa.gr; or the authority of the EU country where you live or work. We would be glad to hear from you first, so that we can put things right.
08Automated decisions
We make no automated decision about you that has legal or similarly significant effects. The limits of the service, such as the rate limits and the daily cap of a new workspace, apply to everyone by the same published rule and decide nothing about you as a person.
One thing happens automatically: a payment that is disputed with the card issuer suspends the workspace it was paid for, until a person at Milkxi has reviewed the dispute (clause 11 of the Terms of Service). Write to us if you think a suspension is wrong.
09Children
The service is for adults: you must be at least 18 years old to create an account. We do not knowingly collect personal data from children. If we learn that an account belongs to a child, we close it and delete the data.
10Changes to this policy
When this policy changes, we update this page and the version and date at its top. When a change matters to you, such as a new purpose or a new recipient, we also tell you by email or in the dashboard, 30 days before it takes effect where we can.
11Contact
If you have a question about this policy or your data, write to aristogiannisphilippis@gmail.com.