Privacy Policy

What we collect, how we use it, and where your content is forwarded. See also the Terms of Service.

This English text is a translation provided for convenience. The Chinese version prevails in the event of any discrepancy — read it here.

Effective 10 June 2026 · version v1.0

This policy explains how Model Plaza (model.dflop.top, operated by Zhanshen Digital Technology — "we", "us") collects, uses and protects your information. Using the service means accepting this policy.

1. What we collect#

Account information: your registration email, and the account identifier, display name and avatar returned by a third-party sign-in such as Google. We never store your password for a third-party account.

Usage and billing data: metadata for each API or playground call — the model, usage in tokens, images or seconds, the cost, a timestamp, which API key was used, where the request came from — used for billing, reconciliation, abuse prevention and improving the service.

What you submit:

  • The request and response bodies of gateway API (/v1/*) calls are not persisted. They pass through our servers while being forwarded, and what remains is the usage metadata above;
  • Playground conversations (chat, image, video and so on) keep their messages and outputs under your account so you can review history and hold multi-turn conversations; you can delete a conversation at any time;
  • Knowledge-base documents and their compiled output live in object storage, reachable only by your account (and any team members you authorise);
  • Generated image and video files live in object storage so we can show them to you and let you download them.

Payment information: top-ups are handled by Stripe. We keep only the order amount and status and never touch or store your card number.

Technical logs: server access logs and error diagnostics (collected through Sentry), for troubleshooting and security auditing.

2. How we use it#

  • To provide and maintain the service (forwarding model requests, storing conversations, charging usage);
  • For security (detecting abuse, credential stuffing and attempts to dodge billing);
  • To improve the service (usage analysis at an aggregate statistical level; we do not profile individuals from their content);
  • We do not sell your personal information, and we do not use your content to train models of our own.

3. Forwarding to third-party model upstreams#

This is how the service fundamentally works, so please read it carefully:

  • Your prompts and the images and document fragments you upload are forwarded to the third-party provider behind the model you chose (including but not limited to direct or relayed services from OpenAI, Anthropic, Google, xAI, ByteDance Volcano Engine, Zhipu, Tencent and DeepSeek), which runs the inference and returns the result.
  • Those upstreams handle data under their own terms of service and privacy policies, and some retain API traffic for a limited period for abuse auditing as their policies allow.
  • Do not put information in a prompt that you are not entitled to disclose, or that you would rather did not leave this platform — someone else's identity document number, medical records, unredacted production credentials.

4. Other processors#

To run the service we use the infrastructure providers below, and your data may be transmitted through or stored on their systems:

ProviderPurpose
CloudflareCDN, network protection, object storage (R2, holding generated files and knowledge-base documents)
Railway / Supabaseapplication hosting and the database
Stripepayment processing
Sentryerror tracking (diagnostic information)

5. Cookies#

We use cookies for the sign-in session only:

  • an authentication cookie (HttpOnly, scoped to .dflop.top so the sites share a session);
  • a CSRF protection cookie.

We serve no advertising cookies and do no cross-site tracking. With cookies disabled you cannot stay signed in.

6. Retention and deletion#

  • Playground conversations and knowledge bases: kept until you delete them or close your account;
  • Usage and billing records: kept for the life of the account, for reconciliation and compliance;
  • Closing your account: request it through the contact in section 8 and we will delete your account data (except billing records the law requires us to keep).

7. Security#

  • HTTPS transport encryption site-wide;
  • passwords stored as one-way hashes; API keys and upstream credentials encrypted with AES-256-GCM;
  • database and object-storage access isolated per account.

No system can be absolutely secure. Should an incident occur that may affect your data, we will notify you promptly as the law requires.

8. Contacting us#

To exercise your rights of access, correction and deletion, or with any question about this policy, reach us at support@dflop.top or through the feedback channel in the console.

9. Changes to this policy#

We may update this policy from time to time, refreshing the effective date at the top of the page; significant changes will be announced separately.

See also the terms of service.