Legal

Privacy Policy

Effective date: 5 June 2026

1. Who we are

phi-cloud (“we”, “us”, “our”) is a stateless AI gateway operated from Switzerland. We provide a single OpenAI-compatible API that routes requests to upstream AI model providers (Infomaniak, Scaleway, Microsoft Azure, Mistral, Anthropic, OpenAI, Google and others — the current list is published in our sub-processor register) while enforcing per-region data residency and a hard PHI gate.

Contact: hello@phi-cloud.com

2. Data we collect

Account & identity data

  • Email address — collected at sign-up (email/password or Google OAuth). Stored by Supabase Auth and used to identify your account.
  • Google OAuth identity — if you sign in with Google, Supabase Auth receives your Google account ID and email. We do not receive your Google password or other Google profile data.
  • Account metadata — stored inside your Supabase Auth user record: your preferred default region (country_code) and Stripe customer ID (stripe_customer_id).
  • API key metadata — for each key you create we store its id, the name you give it, a masked preview (never the full key), and its creation time in a Redis store (Upstash). This lets you list and revoke keys; the key itself is never stored and is shown only once, at creation.

Billing data

  • Payment method, invoices, and subscription state are managed and stored exclusively by Stripe. phi-cloud only stores your Stripe customer ID in your Supabase Auth metadata. We never see or store your card number.
  • Per-call usage cost (in micro-USD) is reported to Stripe as a meter event. We do not store call records, token counts, or prompt/response content.

Request traffic

  • phi-cloud is a stateless proxy. Prompt and response payloads are forwarded to the upstream provider and are never logged or stored by phi-cloud. If a request carries the X-PHI: true header we route it only to a PHI-eligible provider/region pair — we do not inspect or store the content.
  • Transient server logs (IP addresses, HTTP method, path, status code) may be retained for a limited period by our hosting provider (Cloudflare) in accordance with their data-processing terms.

No special categories by default

phi-cloud does not knowingly collect health data, financial records, or other special-category personal data for its own purposes. If your application routes PHI through the API, that data passes through to the upstream provider without being stored or processed by phi-cloud beyond the routing decision.

4. Sub-processors

phi-cloud uses the following third-party sub-processors. Each sub-processor handles data only as instructed and under a data-processing agreement (DPA) or equivalent instrument.

Sub-processorPurposeData locationInstrument
Supabase (supabase.com)Authentication & identity (Auth only — no app tables)EU (AWS eu-central-1)DPA (GDPR Art. 28)
Stripe (stripe.com)Payment processing, billing, subscription managementUS / EUDPA + SCCs
Cloudflare (cloudflare.com)Web hosting & edge compute, network transit, code-execution sandbox, and R2 storage for privately re-hosted generated media (no PHI)Global edge; sandbox pinned per jurisdictionDPA + BAA
Upstash (upstash.com)API key metadata store — key id, name, masked preview, creation time (no PHI, no prompt/response data)UK (London, eu-west-2)DPA (GDPR / UK GDPR / nFADP)
Anthropic (anthropic.com)AI model inference (general routes only — PHI-ineligible until BAA/DPA countersigned)US / EU / globalDPA (GDPR Art. 28) — PHI-ineligible today
OpenAI (openai.com)AI model inference (general routes only — PHI-ineligible until BAA/DPA countersigned)US / EUDPA (GDPR Art. 28) — PHI-ineligible today
Mistral (mistral.ai)AI model inference (general routes only — PHI-ineligible until BAA/DPA countersigned)EUDPA (GDPR Art. 28) — PHI-ineligible today
Infomaniak (infomaniak.com)AI model inference (CH-only routes)Switzerland onlyDPA (nFADP / GDPR)

Upstream AI providers may process prompt data in accordance with their own enterprise data policies. For PHI routes we route only to providers where a BAA or equivalent instrument is in place.

The table above lists the processors behind the account and the core inference paths. The sub-processor register is the complete and authoritative list — it also covers the region-resident OCR/speech, media-generation, retrieval and transactional-email processors — and it is the page we update before engaging anyone new.

5. Data location & retention

  • Account data (email, metadata) is stored in Supabase Auth, hosted on AWS eu-central-1 (Frankfurt). It is retained for as long as your account is active and deleted within 30 days of account deletion.
  • Billing data is retained by Stripe according to their data retention policy and applicable tax/accounting obligations (typically 7 years for invoices).
  • API key metadata (key id, name, masked preview, creation time) is stored in our Redis store (Upstash). It is removed the moment you revoke a key, and all of your keys are purged when you delete your account.
  • Request payloads are not retained by phi-cloud. Upstream provider retention policies apply to data sent to them.
  • Infrastructure logs are retained for a limited period by Cloudflare under their data-processing terms.

6. Security

  • All traffic is encrypted in transit using TLS 1.2+.
  • API keys are self-contained HMAC-signed tokens — phi-cloud never stores issued keys. Compromise of the signing secret would require rotation of all keys simultaneously; the secret is stored only in the deployment environment.
  • Authentication is handled by Supabase Auth (bcrypt password hashing, OAuth PKCE flow).
  • phi-cloud has a minimal attack surface by design: no application database eliminates whole classes of SQL injection and data-exfiltration risk.

7. Your rights

Depending on your jurisdiction, you have the following rights regarding your personal data:

  • Access — request a copy of the data we hold about you.
  • Rectification — correct inaccurate data.
  • Erasure — request deletion of your data (“right to be forgotten”).
  • Portability — receive your data in a machine-readable format.
  • Restriction / objection — restrict or object to certain processing activities.

These rights apply under GDPR (EU), nFADP (Switzerland), UK GDPR, and similar laws. To exercise them, see our Data & Privacy page or email us at hello@phi-cloud.com.

8. How to delete your account

You can delete your account and all associated data at any time from the Account Settings page in your dashboard. Alternatively, see the Data & Privacy page or email hello@phi-cloud.com.

Upon deletion: your Supabase Auth record (email, metadata, API key version) is removed immediately. Stripe retains billing records as required by law. Upstream provider logs are subject to their own retention policies.

9. Cookies & session storage

phi-cloud uses a single session cookie set by Supabase Auth to maintain your login state. No third-party tracking or advertising cookies are set. We do not use analytics cookies.

10. Changes to this policy

We may update this policy from time to time. The effective date at the top of this page will reflect the latest revision. For material changes, we will notify registered users by email.

11. Contact

For privacy-related questions or to exercise your rights, contact us at: hello@phi-cloud.com.

phi-cloud is operated from Switzerland. You have the right to lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) at edoeb.admin.ch or your local supervisory authority.