# Scenepond API 隐私政策
生效日期:2026 年 10 月 8 日 · 版本:1.0
## 1. 责任方与适用范围
本政策说明由个人运营的 Scenepond API(https://open.scenepond.ai)如何处理本服务的个人数据。由本服务运营者负责账户、计费和客服资料的处理;隐私请求发送至 [api-support@scenepond.ai](mailto:api-support@scenepond.ai)。本政策适用于 API 网站及服务,不将主站产品的用途或规则自动引入。
## 2. 收集的数据及用途
- **账户资料**:用户名、邮箱、密码校验数据以及用户实际采用的第三方登录方式提供的资料,用于建立和管理账户、提供用户请求的服务及找回账户。
- **访问与安全资料**:API 密钥、会话、必要登录 Cookie、IP 地址、登录时间及安全事件,用于鉴权、保护账户、限制滥用和排查问题。请勿向客服发送可用凭证。
- **API 输入与生成数据**:提示词、消息、上传或引用的素材,以及模型返回的结果,为完成用户请求而处理。第三方模型会接收请求所需的输入。不要提交无权处理的他人个人数据或秘密。
- **使用和任务记录**:模型、请求 ID、时间、用量、费用、任务状态、错误与安全信息,用于展示使用记录、核对计费、故障排查和处理争议。功能和部署配置可能保存任务、附件或聊天记录;不承诺请求内容绝不留存。
- **订单资料**:订单编号、账户关联、金额、币种、付款状态与退款记录,用于入账、核查和财务记录。本站不要求用户将完整银行卡号、安全码或银行密码发送给客服。
- **客服及举报资料**:用户主动提供的邮箱、问题说明、请求 ID 和证据,用于回复、核查、申诉和安全处置。
账户、API 与订单处理是履行所请求服务所必需的;法定财务记录基于适用的法律义务;安全、故障和争议处理基于保护服务及用户的正当利益,在适用法律要求时进行利益衡量。需要同意的可选处理会另行说明并取得同意,不以本政策授权未披露用途。本站不主动出售个人数据,也不将收到的 API 内容用于训练自有模型。
## 3. 第三方与处理地区
完成请求时,必要内容会发送给实际承接所选模型的服务方。当前配置的渠道包括 [OpenRouter](https://openrouter.ai/privacy) 和 [fal.ai](https://fal.ai/privacy);这不表示其全部模型均可用,具体来源以模型目录和实际调用为准。上游会按其条款和配置处理数据,其保留及模型训练规则不由本站单方面保证。
选择 Waffo Pancake 结账时,付款资料由 Waffo Pancake 及相关支付机构处理,本站接收订单和付款状态用于对账。基础设施包括 Railway 的美国西部托管环境、Cloudflare 的域名和网站基础设施,以及用于客服邮件的飞书。相应供应商可能在多个国家或地区处理必要资料。
数据可能在用户所在国家/地区以外处理。我们限于完成服务及运营所需共享,并遵守适用的数据转移要求;不宣称已签署未经落实的跨境协议或取得未拥有的认证。依法要求、调查欺诈或保护权利时,可能向有权机关提供必要资料。
## 4. Cookie 和安全保护
必要 Cookie 用于登录会话。语言、主题等偏好可能保存在浏览器本地存储中;本 API 网站目前未接入广告跟踪或第三方访问统计工具。阻止必要 Cookie 可能影响登录。清除本地存储可重置偏好。
公开服务使用 HTTPS 传输,服务端对账户和管理操作实施身份验证与权限控制,并限制对运营数据的访问。关键词过滤用于拒绝部分违规请求,具体范围见内容使用政策。任何联网系统均无法保证绝对安全。用户应保护自己的密钥;我们不会以客服处理为由索取密码、验证码或完整银行卡资料。
## 5. 保留与删除
账户资料通常在账户有效期间保留;经核实的关闭或删除请求按下述流程处理。API 用量、任务、错误、安全和订单记录用于对账、故障排查及争议处理,当前没有统一的自动定期清除机制,因此不会承诺调用结束即删除或固定天数后自动清除。仅保留仍有必要的资料;用户可请求查询或删除与账户关联的记录,必要的财务、未决争议及安全调查记录可继续保留至相应义务或需要结束。
客服和举报往来保留至问题处理及相关争议需要结束。删除请求会覆盖我们可控制的存储;备份、供应商或支付机构保留的资料可能需按其周期或法律义务处理,并会在回复中说明。我们不保证能够删除用户已经在第三方公开发布的内容。
## 6. 用户权利和处理方式
发送账户邮箱及请求类型至上述隐私邮箱,可申请访问、更正、导出、删除、限制处理,或在法律适用时反对处理、撤回同意。仅要求与风险相称的账户归属核实;请不要主动发送身份证件、密码或密钥。通常在 5 个工作日内回复受理信息,并在 30 天内完成处理或解释延迟、例外和所需补充信息;适用法律规定更短期限时按其执行。
撤回可选同意不影响撤回前处理的合法性;删除服务所必需的资料可能导致无法继续提供账户功能。用户保留向所在地有权数据保护机关投诉的权利。本服务面向年满 18 周岁的用户;获知未满 18 周岁的用户资料后,可通过隐私邮箱申请核查和删除。重大用途、接收方或保护措施变更会更新本政策并履行适用的通知或同意义务。
---
# Scenepond API Privacy Policy
Effective: October 8, 2026 · Version: 1.0
## 1. Responsibility and scope
This policy explains personal-data processing by the individually operated Scenepond API service at https://open.scenepond.ai. Its operator is responsible for account, billing and support processing. Send privacy requests to [api-support@scenepond.ai](mailto:api-support@scenepond.ai). This policy covers this API site and service, without automatically importing main-site product purposes or rules.
## 2. Data and purposes
- **Account information:** username, email, password-verification data and information supplied through sign-in methods actually used, for registration, account management, requested services and account recovery.
- **Access and security:** API keys, sessions, necessary login cookies, IP addresses, login times and security events, for authentication, account protection, abuse prevention and troubleshooting. Do not send usable credentials to support.
- **API and generation data:** prompts, messages, uploaded or referenced material and model results, to complete requests. Third-party models receive inputs required for the request. Do not submit personal data or secrets you lack authority to process.
- **Usage and task records:** model, request ID, time, quantities, charges, task status, errors and safety information, for usage history, billing reconciliation, troubleshooting and disputes. Enabled features and deployment settings may store tasks, attachments or chats; we do not promise that request content is never retained.
- **Orders:** order references, account association, amounts, currencies, payment status and refund records, for crediting, reconciliation and accounting. Support does not request full card numbers, card security codes or banking passwords.
- **Support and abuse reports:** email, descriptions, request IDs and evidence voluntarily supplied, for replies, investigation, appeals and safety enforcement.
Account, API and order processing is necessary to perform the requested service. Applicable financial-record duties arise from legal obligations. Safety, troubleshooting and dispute handling serve legitimate interests in protecting users and the service, with balancing where required. Optional processing requiring consent is disclosed and consent obtained separately. This policy does not authorize undisclosed uses. We do not actively sell personal data or use received API content to train our own models.
## 3. Recipients and locations
Necessary request content is sent to the service actually handling the selected model. Configured channels include [OpenRouter](https://openrouter.ai/privacy) and [fal.ai](https://fal.ai/privacy). Not every model on those platforms is available; actual sources follow the model catalog and routing. Upstreams process data under their own terms and configuration; we cannot unilaterally guarantee their retention or training practices.
When Waffo Pancake checkout is selected, Waffo Pancake and the relevant payment institutions process payment details. We receive order and payment status for reconciliation. Infrastructure includes Railway hosting in the western United States, Cloudflare domain and website infrastructure, and Feishu for support email. These providers may process necessary data in multiple countries or regions.
Data may be processed outside your country or region. Sharing is limited to service and operational needs and subject to applicable transfer requirements. We do not claim unimplemented transfer agreements or certifications. Necessary information may be disclosed to competent authorities where legally required, to investigate fraud or protect rights.
## 4. Cookies and protection
Necessary cookies support login sessions. Language and theme preferences may be stored in browser local storage. This API site currently has no advertising tracking or third-party visitor analytics integration. Blocking necessary cookies may prevent sign-in; clearing local storage resets preferences.
Public services use HTTPS. Server-side authentication and permissions control account and management actions, and access to operational data is restricted. Keyword filtering rejects some prohibited requests as described in the Acceptable Use Policy. No connected system is absolutely secure. Protect your own keys. Support does not request passwords, verification codes or full card details.
## 5. Retention and deletion
Account information is generally retained while an account is active; verified closure or deletion requests follow the process below. API usage, tasks, errors, security and order records support reconciliation, troubleshooting and disputes. There is currently no uniform automatic periodic purge, so we do not promise deletion immediately after a call or after a fixed number of days. Data is retained only while needed. You may request access or deletion of account-linked records; necessary financial records and information needed for unresolved disputes or security investigations may remain until the relevant obligation or need ends.
Support and report correspondence is retained until resolution and associated dispute needs end. Deletion covers storage we control. Backups and provider or payment-institution records may follow their own cycles or legal duties, which will be explained in our response. We cannot guarantee removal of content you have publicly posted with third parties.
## 6. Rights and requests
Send your account email and request type to the privacy address above to seek access, correction, export, deletion, restrictions, or objection and withdrawal of consent where applicable. Account verification is proportionate to the request's risk. Do not proactively send identity documents, passwords or keys. We normally acknowledge requests within five business days and resolve them or explain delays, exceptions and needed information within 30 days. Shorter applicable statutory deadlines take precedence.
Withdrawal does not affect lawful processing already completed. Deleting information necessary for service may prevent continued account functions. You retain rights to complain to a competent local data-protection authority. This service is intended for users aged 18 or older; contact the privacy address to investigate and remove information concerning a younger user. Material purpose, recipient or protection changes will be reflected here with legally required notices or consent.
加载中…