Halfbill Code — Supplemental Privacy Policy
Effective date: [EFFECTIVE DATE PLACEHOLDER]
Last updated: September 11, 2026
Code plan privacy in plain English
A human-readable summary of the key points. This overview is for convenience only and is not legally binding — the full text below is what governs.
This policy adds Code plan detail to the Halfbill Privacy Policy, which still governs everything else — legal bases, your GDPR rights, security and international transfers.
We log tokens, cost, latency, model and which coding tool sent the request. Prompts and responses are not stored, and there is no setting to turn payload storage on for a Code plan.
Requests to /v1/responses are stateful, so their input and output items are stored for up to 30 days to make response chaining work. Send store: false to opt out.
Prompts are forwarded to the vendor behind the model you chose (Anthropic or OpenAI) through our infrastructure providers, under their API terms, which do not use API inputs to train models.
We do not sell personal data and we do not train models on your prompts or completions. Data is shared only with the processors listed in the main policy.
Request metadata is kept for 30 days; billing records for 10 years where tax law requires it. Halfbill SRL is an EU controller — write to legal@halfbill.uk to exercise your GDPR rights.
This Supplemental Privacy Policy describes how Halfbill SRL, [PLACEHOLDER: registered company name and address], Bucharest, Romania (“Halfbill”, “we”, “us”) processes personal data when you use a Halfbill Code plan, the website at code.halfbill.uk and the Code dashboard.
It is an addendum to, and incorporates by reference, the Halfbill Privacy Policy (the “Base Policy”). The Base Policy applies in full and governs everything not specifically addressed here — our role as controller and processor, legal bases, processors and international transfers, security, your rights under the GDPR and how to exercise them. Where the two conflict on a point that concerns Code plans, this Supplemental Policy controls for that point only.
1. What we collect
a. Account and billing
Name, email address and authentication credentials when you sign up; billing details (name or company, country, VAT number where given) and the payment method token processed by our payment processor. We never see your full card number.
The API key issued with your plan is shown once, when created or rotated. We store a keyed one-way hash and a masked preview; requests are authenticated by hashing the key you present.
b. Request metadata
For every request made with your plan's key we log:
- timestamps, latency, finish reason and HTTP status;
- token counts (prompt, completion, cached, reasoning) and the computed cost in Halfbill credits;
- the model requested and the coding tool that sent the request, where the tool identifies itself (for example Claude Code, Cursor, Codex);
- IP address, user agent and approximate region.
Code plans are metadata only: prompts and model responses are not written to persistent storage and do not appear in your dashboard. There is no setting to turn content storage on for a Code plan; the optional content retention available for pay-as-you-go projects under the Base Policy does not apply.
Exception — the Responses API. Requests to /v1/responses (used by tools such as Codex CLI) are stateful: so that previous_response_id chaining works, the input and output items of those requests are stored for up to 30 days and then deleted. Send store: false to opt out. Other endpoints (/v1/chat/completions, /v1/messages) are not affected. Content may be held transiently in memory while a request is processed.
c. Cookies and local storage
We use first-party cookies and local storage to keep you signed in and remember your preferences, and product analytics as described in the Base Policy. To object to analytics write to legal@halfbill.uk.
2. How we use it
- to provide, secure and improve the Service;
- to meter usage, enforce the allowance and fair-use windows and bill you;
- to power the dashboard (usage by model and by coding tool);
- to detect abuse, fraud and duplicate accounts;
- to send transactional email (receipts, plan changes, allowance notices).
We do not sell personal data and we do not use your prompts or completions to train models.
3. Model vendors
Your prompt is forwarded to the vendor behind the model you selected — Anthropic for Claude models, OpenAI for GPT models — through the infrastructure providers listed in the Base Policy, under those vendors' API terms, which state that API inputs are not used to train their models. Halfbill is an independent service and is not affiliated with either vendor.
4. Processors
Code plans use the same processors as the rest of Halfbill. The list, what each one processes and where, is maintained in the Base Policy and available on request at legal@halfbill.uk.
5. Retention
- Account data — for the life of the account, then deleted within 30 days of closure.
- Billing and accounting records — 10 years, as required by Romanian tax and accounting law, even after account closure.
- Request metadata — 30 days.
- Prompt and response content — not stored, except Responses API items kept for up to 30 days (section 1b).
- Server and security logs — 30 days.
6. Your rights and contact
Halfbill SRL is established in Romania and is the controller for the data above. You may request access, rectification, erasure, restriction, portability and object to processing based on legitimate interest, as described in the Base Policy. Write to legal@halfbill.uk from the address on your account; we respond within one month. You may also complain to the Romanian supervisory authority (ANSPDCP) or the authority in your country of residence.
Halfbill SRL · [PLACEHOLDER: registered company name and address] · Bucharest, Romania · legal@halfbill.uk