Privacy Policy
Updated: May 19, 2026
JoinGonka Gateway operates the gate.joingonka.ai service. This page describes our policy regarding the collection and use of personal data.
1. What data we collect
Email and hashed password upon registration. API usage data (model, token count, time, technical request IDs for tracing purposes). Transaction records (amounts in nGNK). IP address (hashed). We DO NOT store the content of prompts and responses.
2. How we use the data
Provision of API Gateway service. Payment processing and billing. Abuse protection and incident investigation. Service quality improvement.
3. Data Transfer
We DO NOT sell your data. Inference requests are transmitted to the Gonka network (decentralized GPU nodes). Payments are processed via OxaPay (transaction data only). In the event of a justified request from a Gonka network infrastructure provider as part of an incident investigation (violation of network terms of use, infrastructure abuse, security incidents), we may confirm the fact that a specific request was processed through our gateway. We do not store the content of requests and responses and cannot provide it.
4. Data Storage
Account – until deletion. Transactions – indefinitely (financial reporting). Inference logs and associated technical identifiers – 90 days. Hashed IPs – 30 days.
5. Your Rights (GDPR)
Access to data. Account deletion. Data export in JSON. Email and password change.
6. Security
API keys are HMAC-SHA256 hashed with a pepper. Passwords — bcrypt (12 rounds). All connections via TLS 1.3.
7. Legal Basis for Processing
We process your data on the following GDPR grounds: contractual necessity (Art. 6(1)(b)) – for providing API Gateway service, billing, and authentication; legitimate interest (Art. 6(1)(f)) – for protecting the service from abuse, incident investigation, and cooperation with infrastructure providers; legal obligation (Art. 6(1)(c)) – for financial reporting and responding to lawful requests from regulatory authorities.
For privacy inquiries: [email protected]