Log in
Legal

BYOK Addendum

Cloud Creator LLC · ozu.studio

Effective date: June 12, 2026 · Last updated: August 13, 2026

Version: 1.0

This page was first published on August 13, 2026. It is incorporated into the Terms of Service as of the Effective Date above.

This Bring Your Own Key Addendum (“Addendum”) is part of the Terms of Service between you and Cloud Creator LLC (“Ozu,” “we,” “us”). It applies if you enable Bring Your Own Key (“BYOK”) on the Service. If anything here conflicts with the Terms on a BYOK-specific point, this Addendum controls for that point. Our Privacy Policy still governs how we handle personal data, including keys.

1. What BYOK is

BYOK lets you use your own third-party AI provider API keys with Ozu instead of spending Ozu platform credits on those generations.

BYOK is a feature of the Studio+ tier. If you are not on Studio+, you cannot enable it.

Generation routed through your own keys is billed by the provider to the account that owns the key. It does not consume Ozu credits.

2. You pay the provider

If you use BYOK:

  • You are solely responsible for all API usage and costs charged by the third-party provider.
  • Ozu is not responsible for any charges, errors, rate limits, quotas, outages, model retirements, or service changes from those APIs.
  • A failed, throttled, or rejected BYOK call can still incur provider charges under that provider’s billing rules. We don’t control that bill and we don’t refund it.
  • You are responsible for complying with the terms of service, acceptable use rules, and commercial-use policies of each provider whose key you use.

Keep an eye on your provider dashboards. We will not invoice you for BYOK usage, and we will not cap the provider’s bill on your behalf.

3. How we store and use your keys

Your API keys are stored encrypted in our database. They are not stored in your browser, and they are not kept only in memory for the length of a single request.

We persist them so the Service can keep making calls for you across sessions, until you disable BYOK or replace the key.

We use your keys only to provide the Service to you: specifically, to authenticate API calls to the provider you designated, on your behalf. We don’t use them for our own generation, for other customers, for training, or for anything else.

We don’t expose your keys in the browser, in client-side code, or in API responses to you (beyond whatever masked hint the settings UI may show so you can tell which key is saved).

4. Ozu makes the HTTP call

This part matters, because it is easy to get wrong:

BYOK requests do not go from your device straight to the provider. Our servers make the HTTP call. We are an intermediary for that request. We send the prompt, reference media, and parameters needed to generate your output, authenticated with your key.

We do this so BYOK works inside Ozu’s pipeline (routing, UI, project storage) without shipping your raw key to the browser.

What we are not: a reseller of the provider’s API, a co-owner of your provider account, or a party to that account’s billing.

5. We don’t log the content of BYOK calls

As described in our Privacy Policy, we don’t log the content of BYOK calls. We may still record the operational facts we need to run the Service (for example: that a call was made, which provider, success or failure, and credit-routing so we know not to charge Ozu credits). We don’t keep the prompt or output body of a BYOK call as a content log.

Provider-side logs are a different story. Those are governed by your agreement with the provider, not by us.

6. The provider’s terms for your account apply

Because the call is authenticated with your key, the provider treats it as traffic on your account.

That means:

  • The provider’s training, retention, abuse-review, and logging terms for your account apply to BYOK traffic.
  • If you want “zero retention,” no-training, or similar account settings, you have to configure them on your provider account. We don’t inherit those settings from our own platform keys, and we can’t flip them for you.
  • Ozu still routes the request. A zero-retention setting on your provider account does not mean the request never touches our servers. It means you have asked the provider not to retain it, on whatever terms that provider actually offers. Confirm that with the provider. Don’t assume our routing is a no-op.

We cannot claw back a training license, logging practice, or data-use right a provider takes under its own terms. See also Terms of Service §6.2 and Privacy Policy §9.

7. Key rotation

You can replace a stored key at any time in Account Settings (or the BYOK settings surface in the app).

When you save a new key for a provider, we encrypt and store the new key and stop using the old one. We treat the replaced key as disabled and delete it on the same schedule as a disabled key (Section 9).

Rotate a key if you believe it may have been exposed, if the provider issued you a new one, or on whatever schedule your own security practice requires. We don’t rotate provider keys for you.

8. Invalid, revoked, or over-quota keys

If a key is missing, malformed, expired, revoked, rate-limited, or rejected by the provider:

  • The generation fails.
  • Ozu credits are not consumed (BYOK generations don’t use Ozu credits).
  • Any charge on the provider side is between you and the provider.
  • We are not required to retry with our platform keys unless you turn BYOK off and run the job on credits instead.

Fix it by updating the key, resolving the provider-side issue, or disabling BYOK.

9. Revocation, leaks, and disabling BYOK

You should revoke a key at the provider immediately if you think it leaked — in a screenshot, a log, a support ticket, a stolen device, or anywhere else. Then rotate it in Ozu.

If we reasonably believe a stored key is compromised, being abused, or being used in a way that violates these Terms, our Acceptable Use Policy, or the provider’s terms, we may disable that key or BYOK on your account without advance notice.

You can disable BYOK yourself at any time. Disabling it does not cancel your Studio+ subscription and does not delete your Ozu projects.

Retention: we keep BYOK API keys until BYOK is disabled, plus 30 days for cleanup, then delete them from active systems. That matches the retention table in our Privacy Policy. Replaced keys follow the same clock from the moment we stop using them.

Disabling BYOK in Ozu does not revoke the key at the provider. If you want the key dead, revoke it there too.

10. What we are not liable for

To the maximum extent permitted by law, Ozu is not liable for:

  • Provider invoices, overages, or surprise bills on your API account
  • Provider errors, refusals, safety-filter declines, rate limits, or model changes
  • Outputs generated with your key, including any claim that they infringe someone else’s rights
  • Your failure to configure the provider account the way you intended (retention, training opt-out, spend caps, organization permissions)
  • A leaked key, except to the extent caused by our willful misconduct

The limitation of liability and disclaimer of warranties in the Terms still apply.

11. Your content and the Service

Input you send and output you get through BYOK are still Input Content and Output Content under the Terms. Our assignment of rights we hold, the copyright limitation, and the vendor-terms caveat in Terms §6.2 all still apply.

BYOK does not change the Acceptable Use Policy. Don’t use a personal key to do an end-run around content rules. Providers will have their own filters as well; a decline by a provider safety system is not an Ozu AUP termination by itself.

12. Changes

We may update this Addendum the same way we update the Terms. Material changes will be posted at /legal/byok/ with a new Last Updated date and noticed as described in the Terms.

If you don’t agree, disable BYOK and stop using that feature before the changes take effect.

13. Contact

Questions about BYOK: [email protected]
Legal: [email protected]

Ozu / Cloud Creator LLC
c/o Northwest Registered Agent, 30 N Gould St, Ste N, Sheridan, WY 82801

Revised August 13, 2026: first publication of this Addendum, matching Terms §4 and Privacy Policy (encrypted database storage; Ozu servers make the call; no content logging of BYOK calls; provider-account training and retention settings are yours to configure).