Privacy Policy
Effective date: July 1, 2026
1. Who we are
Coding Plan is a product of New Information Technology Co., Ltd. (ModelHarbor), operated at coding.modelharbor.com. It is a prepaid API gateway for agentic AI coding: you prepay credit, call our API from your coding tools, and we forward your requests to an upstream model service. This policy explains what we collect and, importantly, what we do not.
2. Data handling during inference
We do not store your prompt content or the model's output content.
- We do not log the text of your requests.
- We do not log the text of the model's responses.
- Your prompts and outputs pass through our servers in memory only, to translate between API formats and to count tokens for billing. They are discarded immediately and are never written to our database, our logs, or our backups.
This is a hard, code-enforced constraint, not just a policy statement. We do not store, sell, or train on your submissions.
No training
Except when using specific third-party models, we do not use data for training our own models, do not store it on disk, and use it only for inference.
No sharing
We do not share your API-submitted data with any third party, except where required to operate the service (forwarding your request to the upstream model service you selected). Metering metadata is internal and not shared.
Logs
We generally do not log API-submitted data. Only metadata useful for debugging is logged — such as request ID, inference cost, and sampling parameters. We reserve the right to view and log small portions of requests for debugging or security.
3. What we do collect and store
- Account: when you sign in with Google, we receive your Google account email and a stable Google account identifier (sub). We never see or store your Google password.
- API keys: you may create up to two API keys. Keys are stored as one-way hashes — the full key is shown to you exactly once, at creation or renewal, and cannot be recovered by us. If you lose a key, you must renew it.
- Payment metadata: topups are processed by Omise (Opn Payments). We receive and store the Omise charge identifier, the amount, and the charge status. We do not store your card number, CVV, or full card details — those are handled entirely by Omise.
- Metering data: for each API request we store token counts (input cache-hit, input cache-miss, output), the model used, the charge, the credit bucket it was drawn from, and timestamps. No content.
- Topup & balance history: your topup records, current credit balance, and per-bucket expiry timestamps.
- Other information: non-identifying device and usage data (such as IP address and interaction times) collected automatically to operate and improve the service.
4. How long we keep data
- Credit buckets: a bucket expires 30 days after its topup. Remaining balance is forfeited at expiry. The transaction record is retained for accounting.
- Metering metadata (token counts, charges): retained for audit and dispute resolution.
- Account data: retained until you request account closure. After account deletion, personal information is removed after 30 days.
5. How we use your information
- To present and operate the service.
- To provide account notices, including expiry and renewal notices.
- To carry out billing and collection.
- To notify you of changes to the service.
- For any other purpose with your consent.
6. Refunds
Unused balance is refundable before a topup's 30-day expiry. Consumed credit and expired credit are non-refundable. See the Terms of Service.
7. Payment processing
Omise is the data controller for your payment details. We do not receive or store full card data. Your payment relationship is with Omise under its terms.
8. Disclosure of your information
We do not sell your data. We share only what is necessary to operate the service: Google (sign-in), Omise (payment), and the upstream model service (forwarding your request). We may disclose personal information to comply with legal processes, to enforce these Terms, or to protect rights, property, or safety.
9. Your rights
You may close your account, request a refund of unused balance within a bucket's 30-day life, review, correct, or delete your personal information, and export your metering history. Personal information cannot be deleted without also deleting your account. To exercise any of these, contact us (below). EU residents may have additional rights under GDPR.
10. Data security
Security measures comply with relevant industry standards, including technical and organizational measures to protect against accidental loss and unauthorized access, use, alteration, and disclosure. Payment transactions are encrypted. However, no security measures are perfect, so information security cannot be guaranteed. You are responsible for keeping your API keys confidential.
11. Children under 18
The service is not intended for children under 18. We do not knowingly collect personal information from children under 18. If discovered, it will be deleted.
12. Changes to this policy
Significant changes to how personal information is handled will be communicated via email or a notice on the service. The last-updated date appears at the top of this page.
13. Contact
New Information Technology Co., Ltd.
110/42 Village No. 3 Rattanathibet Road, Sai Ma
Mueang Nonthaburi, Nonthaburi 11000, Thailand
Phone: +66 2594 3334 - 5
Email: info@modelharbor.com
Website: https://www.nti.co.th