Rainspeed LabsAll terms & policies

Rainspeed Labs / Product Notice

AtlasFlux API Product Notice

Product-specific terms for the AtlasFlux API and Platform.

Last updated: 12 August 2026

1. Relationship with the central policies

This Product Notice supplements the Rainspeed Labs Terms of Use, Privacy Policy, Service Terms, Acceptable Use Policy, Refunds and Credits Terms and Subprocessors register. Those central policies apply to AtlasFlux API unless this Product Notice states a product-specific rule. The contracting entity remains Rainspeed Labs Solutions (business registration number 202603148143 (003857582-W)), Malaysia.

2. API features and intended use

AtlasFlux API may provide OpenAI-compatible Responses and Chat Completions endpoints, model listings, web search, content extraction, usage reporting, API-key management, a developer dashboard and billing controls. The available endpoints, models, tools, limits, regions, provider routes and documentation may change by account, environment and current configuration.

The API is intended for developers and organisations that integrate model and tool capabilities into their own applications. You are responsible for your application, End Users, prompts, retrieved data, Output, notices, permissions, moderation, security controls and actions taken using an API response. Do not expose a live API key in browser code, mobile app bundles, public repositories, prompts, support tickets or client-controlled logs.

3. API keys and access

API keys may use separate test and live environments and may have scopes, origin restrictions, expiry dates, monthly spend limits and other controls. A generated key may be shown only once; Rainspeed Labs is designed to retain a prefix and one-way hash rather than the complete secret. If a key is lost or compromised, revoke it, create a replacement and notify Support without sending the secret.

API requests are authenticated and may be rate-limited, rejected or stopped when the key, account, provider, safety control, spending limit, wallet balance or service configuration does not permit the operation. You must implement appropriate authorisation for your own End Users and must not allow an End User to use your key beyond the permission and budget you intend.

4. Prepaid MYR wallet and API usage

AtlasFlux API uses a prepaid MYR wallet where enabled. Top-ups, wallet balance, reservations, usage debits, releases, refunds, chargebacks, manual corrections and automatic reload are product-specific billing records. The wallet is a limited service entitlement, not a bank account, deposit, cryptocurrency, investment or transferable cash balance.

The current API pricing model may separately measure input, output and reasoning tokens, web-search operations, search-result ranges and content-extraction pages. The current price table, top-up amounts, taxes if applicable, limits and final transaction amount are shown in the API documentation, dashboard or checkout. The applicable pricing version and transaction record control the request. Prices and limits may change prospectively for future requests or purchases.

Before execution, the API may reserve an estimated maximum or requested amount. After execution it may settle the actual cost and release the difference. A confirmed provider or backend failure may release the reservation or produce a corresponding adjustment according to the implementation. A successful response is not refundable merely because the Output is unsatisfactory, subject to applicable law and the Refunds and Credits Terms.

5. Request, provider and usage records

To provide and secure the API, Rainspeed Labs may record request identifiers, developer account, API-key metadata, endpoint, public model, routing category, upstream provider/model, stream status, request status, token counts, cached tokens, search and content counts, cost, reservation, pricing version, latency, finish state, errors, rate-limit events and security metadata.

The API does not promise to retain or provide a complete copy of every prompt or Output. A completed non-streaming response may be stored in an idempotency record so that a repeated request can receive the same response. Provider attempts and aggregate usage may contain provider, timing, usage, cost and error information. Treat the API as a processing service, not as your permanent database or archival system.

6. Provider and international processing

API prompts, messages, tool parameters, selected context and other request data may be sent to the configured model-routing, inference, search or retrieval provider. Search queries and selected public URLs may be sent to search or content-retrieval providers. The provider, model and processing location depend on the request and current route; the Subprocessors register lists material providers.

Do not send passwords, private keys, payment secrets, regulated data or another person's confidential information unless you have lawful authority and the selected operation is appropriate. If you use AtlasFlux API to process data for your own customers, you remain responsible for your notices, lawful basis, instructions, security and any processor or subprocessor arrangements required for your use case.

7. Account closure, billing records and deletion

The current API account-closure control closes the developer account, revokes API keys and disables automatic reload. It is not a complete erasure workflow. Financial ledgers, payment transactions, Stripe event records, accounting records and other records needed for security, fraud prevention, disputes or law may remain. The closure endpoint does not necessarily delete the Clerk account, profile snapshots, API request history, usage aggregates, payment records or the Stripe-side customer record.

The current API retention targets are approximately 90 days for API request records and 7 days for idempotency records, subject to maintenance execution, backups, legal holds, billing needs and other applicable exceptions. Financial ledgers are retained separately. A rights request may therefore produce a partial deletion, restriction or export depending on the record and applicable law.

8. Business use and support

If you use the API for a company or organisation, you must ensure that authorised users accept the applicable terms and that your application presents any privacy, consent, attribution, safety or provider disclosures required for your use. API support may inspect limited account, wallet, API-key metadata and usage information needed to resolve a verified request; Support is not permitted to request or require a full secret key.

For API incidents, billing, compromised credentials or privacy requests, use https://support.atlasflux.my. Never send full payment details, passwords, bearer tokens or complete API keys through Support.

<- Back to terms & policies