Moxus AI is a model gateway. Request content is routed by the platform to the model service you choose. Each model service may have its own data retention, training, and compliance-region rules. Review the selected service’s policy before sending sensitive production data.
Data Moxus AI handles
Information Moxus AI does not ask for
Moxus AI support and docs do not ask you to provide:- Plaintext API keys.
- Login passwords.
- Payment passwords, card passwords, or verification codes.
- Private repository access tokens.
- Identity documents, contacts, or local files unrelated to model calls.
How request content flows
- Your client sends a request to Moxus AI with an API key.
- Moxus AI authenticates the key, checks limits, reserves balance, and processes parameters.
- The request content is routed to the selected model service for processing.
- After the response returns, Moxus AI settles usage and records necessary activity logs.
- You can view request activity and cost in Usage.
Retention and visibility
Platform protections
- Passwords are stored as hashes, not plaintext.
- API keys are shown in full only once after creation and are masked in lists.
- API keys can have quota, expiration, model, and source IP limits; groups are only for organizing the list.
- Admin-only diagnostic fields are hidden from normal user log views.
- Some privacy-sensitive request fields are filtered or controlled by platform settings, such as
safety_identifier.
What you can do
- Create separate API keys for development, production, and external tools.
- Set low quotas for browser extensions, desktop tools, and test scripts.
- Use source IP limits for server-side projects with fixed outbound IPs.
- Delete keys that are no longer used.
- Never expose keys in frontend code, public repositories, screenshots, or chat messages.
- Review the selected model service’s data policy before sending sensitive business data.
If something looks wrong
Balance decreased unexpectedly
Balance decreased unexpectedly
An API key may be leaked
An API key may be leaked
Delete or disable the key immediately, create a new key, and update your app configuration. Then review recent API activity for unusual calls.
The account may be compromised
The account may be compromised
Change the login password, review the bound email address and API keys, and delete unknown keys. If the issue continues, contact support with the time range, account email, and request IDs.
