Let’s build together.
The scope and essential terms of using WhatOTP. Effective: 26 September 2026.
01. Parties and scope
These Terms of Use (“Terms”) govern the relationship between WhatOTP, —, bayyazilimcioffical@gmail.com (“WhatOTP”, “we”) and the natural or legal person (“User”, “you”) using the WhatOTP website, dashboard, Playground, documentation and API (together, the “Service”).
By creating an account, signing in with Google or GitHub, using an API key or otherwise accessing the Service, you confirm that you have read, understood and accepted these Terms, the Privacy Policy and the Cookie Policy. If you do not accept them, do not use the Service.
If you use the Service on behalf of a company, organisation or another person, you represent that you are authorised to bind them to these Terms, and “you” includes them.
02. Definitions
Account: the user record created to use the Service. API key: a secret key linked to your account that authorises API requests. Token: the unit of text processed by models; the input (prompt) and output (response) tokens of a request are counted together.
Model: an AI language model accessed through the Service. Provider: a third-party AI service outside WhatOTP's control that runs models and generates responses. Input: messages, tool definitions and other content you send to the Service. Output: the response generated by a model.
Quota: the amount of tokens you may use free of charge in each 30-day period. Package: an unlimited-usage period, bonus token balance or model package added to your account with an activation code. Activation code: a single-use code that adds a package to your account.
03. Eligibility and registration
You must be at least 18 years old and have legal capacity to use the Service. Only one account per person is allowed. Opening multiple accounts to multiply quotas or promotions, opening accounts for others, and selling, transferring or sharing accounts is prohibited.
You must provide accurate, current information that belongs to you. Temporary or disposable email domains are not accepted. Registrations not verified within 24 hours may be deleted. You must verify your email address to use the API.
To prevent abuse, bot checks run at registration and sign-in, and network and device signals are evaluated (see the Privacy Policy). WhatOTP may refuse a registration without having to give reasons. After an account is deleted, re-registering with the same email or social account may not be possible.
04. Description of the Service
WhatOTP is an intermediary service that provides access to AI models offered by third-party providers through a single API address, with interfaces compatible with OpenAI Chat Completions, Anthropic Messages and OpenAI Responses. The Service also includes a web-based Playground, usage reports, API key management, support and a status page.
WhatOTP does not develop or train models or author their outputs; it forwards requests to providers and returns their responses to you. The compatibility interfaces are not official OpenAI or Anthropic services, imply no affiliation with those companies, and do not support every feature (for example image/file input, server-executed tools or persisted response IDs).
The “auto” model selects one of the currently available models automatically; which model is chosen is not guaranteed. Features labelled trial, preview or beta may be changed or removed at any time.
05. Free quota and token accounting
Each account may use a free token quota in 30-day periods starting from its registration date. As of the effective date, this quota is 100,000 tokens for accounts registered with email only and 1,000,000 tokens for accounts with a linked Google or GitHub account. The upgrade to 1,000,000 tokens can be used only once per Google/GitHub identity, on one account.
Unused quota does not carry over and cannot be exchanged for money. Spend order: while an unlimited package is active, tokens are not counted; otherwise the period quota is used first, then bonus balance. Once quota and bonus balance are exhausted, API requests are rejected with HTTP 429 (token_quota_exceeded).
Tokens are counted from the usage reported by the provider. If the provider reports no usage or the connection drops, consumption is estimated by WhatOTP and the estimate is marked in the records. For streams that are interrupted, cancelled or closed by the client, the output generated up to that point is charged. The maximum output of a request may be capped based on your remaining balance.
WhatOTP's system records govern quota, token accounting and usage. If you believe a record is wrong, open a support ticket with the request ID (X-Request-Id) within 30 days.
The free quota is a gift, not a legal entitlement, commitment or promise of continuity. Its amount, period length and conditions may change as described in the next section.
06. Models, limits and packages may change
The model list; model names, versions, context lengths and capabilities; request, rate and concurrency limits; and the free quota, bonus balance and package scopes are at WhatOTP's discretion and may be increased, reduced, changed, or temporarily or permanently removed without prior notice.
A model may be replaced with an equivalent or different model. Even if a model name stays the same, the underlying provider, version, quality, speed, context length or behaviour may change. There is no guarantee that a model will respond in the future as it does today. No commitment is made that any particular model, feature, quota or limit will remain available.
If a model covered by a package is removed or changed, the package remains usable for its remaining term on the replacement models or equivalent models chosen by WhatOTP. Bonus token balance remains usable on the models offered after a change.
Subject to mandatory consumer rights under applicable law, changes under this section do not entitle you to a refund, compensation, extension or additional balance. Continuing to use the Service means you accept the changes.
07. Packages and activation codes
Packages offered as of the effective date: daily, weekly and monthly unlimited packages (1, 7 and 30 days); 10M, 50M and 100M token packages; and custom model packages valid for specific models for a specific period. Packages are activated only with an activation code, in the Packages section of the dashboard, on accounts with a verified email.
Unlimited packages stop token counting for the stated period from activation; a new code extends the remaining time. “Unlimited” means only that the token quota is not counted; per-minute request, concurrency and technical limits, fair-use rules and provider capacity still apply. Token packages add non-expiring bonus balance, spent after the period quota.
Activation codes are single-use, cannot be exchanged for cash, are non-refundable and cannot be transferred to another account after redemption. Keeping a code secret is your responsibility; lost, stolen, already-used or expired codes are not replaced. Some codes may have a redemption deadline. Codes suspected of fraud, chargeback or unauthorised distribution may be revoked before use, and if already used, the granted package may be withdrawn.
Codes may be given free of charge by WhatOTP or sold through a sales channel authorised by WhatOTP. For paid sales, the pre-contract information and distance-sales terms presented at the time of sale also apply. WhatOTP is not responsible for codes obtained from unauthorised third parties.
Packages are digital content/services performed immediately and delivered electronically. Under Article 15 of the Turkish Distance Contracts Regulation, the right of withdrawal does not apply to packages whose performance started immediately with your approval and whose code has been redeemed to your account. Package fees are not refunded except where mandatory law requires.
If you delete your account or it is closed for breach of these Terms, any remaining package time and bonus balance end without refund or compensation.
08. Rate, concurrency and technical limits
Default limits as of the effective date: 15 requests per minute per account (different on some packages), at most 2 concurrent requests, request bodies up to 1 MB, up to 64,000 output tokens per request and up to 10 minutes per request. All of your account's API keys and the Playground share these limits.
Lower limits may apply due to overall platform capacity, provider capacity and system load. If many different accounts use the API from the same network within a short period, newer accounts may be stopped and flagged for review. Contact support if you believe this is a mistake.
Exceeding or circumventing limits, or using multiple accounts, keys, IP addresses or automation to do so, is prohibited.
09. Third-party providers
Model responses are generated by third-party AI providers outside WhatOTP's control. WhatOTP may change which providers are used at any time and is not obliged to disclose their identity.
WhatOTP is not liable for provider-caused outages, slowdowns and errors; capacity or rate limits; rejected requests or content filtering; inaccurate, incomplete, inappropriate or harmful responses; removal or change of models or features; changes to a provider's pricing, policies or data-processing practices; or a provider suspending or ending its service.
Your inputs are forwarded to providers to generate responses and may be subject to the providers' own data-processing, retention and usage terms. WhatOTP does not guarantee that providers will not retain or use inputs. Providers' usage policies also apply; your access may be restricted for use that violates them.
For consistency, responses may be processed automatically: for example, streaming formats are converted, request IDs and model names are replaced with WhatOTP identifiers, and some infrastructure and provider names in response text may be replaced with “WhatOTP”. These steps are not intended to change the meaning of a response but may occasionally affect part of the text.
10. Account security and API keys
You are responsible for keeping your password, sessions and API keys secret. API keys are shown only once, when created; do not expose them in browsers, mobile apps, public repositories or client-side code, and store them server-side only.
All requests, tokens consumed and consequences arising through your account or keys are your responsibility unless you revoke the key and notify us promptly after discovering unauthorised use. You can limit keys to selected models and an expiry date and end sessions from the dashboard.
Quota or package balance consumed through unauthorised use is not refunded. WhatOTP may revoke your keys, end your sessions or require additional verification if it sees a security risk.
11. Acceptable use
You must use the Service in compliance with the law, these Terms and providers' usage policies. In particular, you may not:
a) generate, process or distribute content that is criminal, sexually exploits children, promotes terrorism, violence or hatred, or infringes others' personality rights, intellectual property or personal data; b) create malware, phishing, spam, fraud, fake content or disinformation campaigns; c) monitor or profile others without authorisation or make discriminatory automated decisions;
d) attack, scan for vulnerabilities in, or overload the Service, its infrastructure or other users, or try to bypass limits, quotas, bot checks or security measures; e) open multiple accounts, sell, rent or share accounts, keys or activation codes without permission, or resell the Service or offer it as an intermediary service to third parties without WhatOTP's written permission;
f) reverse-engineer the Service or models, try to reveal providers or system instructions, or use outputs to train competing models in breach of provider terms; g) mislead others by presenting AI output as human-written; h) use outputs as the sole basis for decisions without human oversight in areas that require special authorisation or professional supervision (health, law, finance, safety-critical systems).
Where a breach is suspected, WhatOTP may reject the request, revoke keys, suspend or close the account without notice, and inform the competent authorities where required.
12. Inputs and outputs
You are responsible for ensuring that your inputs are lawful, that you have the right to process them and forward them to providers, and that they do not infringe third-party rights. If your inputs contain others' personal data, you must have a legal basis and inform the data subjects. Do not include special categories of personal data (health, biometric, criminal records), passwords, card details or trade secrets in your inputs.
Outputs are generated automatically by AI; they may be inaccurate, incomplete, outdated, biased, inappropriate or similar to outputs given to other users, and they are not professional advice (medical, legal, financial, psychological, etc.). You are responsible for verifying outputs before using, publishing or relying on them. Review and test generated code before running it.
If you use outputs in your own products or services, you are responsible for disclosing the use of AI to your end users and complying with applicable law (consumer, advertising, personal data and AI regulations).
13. Intellectual property
The website, dashboard, software, design, documentation, blog content, and the WhatOTP name and logo belong to WhatOTP or its licensors. These Terms grant you no rights other than a limited, non-exclusive, non-transferable and revocable right to use the Service. Licences of open-source components also apply.
You keep your rights in your inputs. You grant us a limited permission to process your inputs, forward them to providers and deliver the responses to you so we can provide the Service. WhatOTP claims no rights in outputs but gives no assurance as to whether outputs are protected by copyright, infringe third-party rights, or are restricted by provider terms.
We may use suggestions and feedback you send us to improve the Service without any obligation to you.
14. Availability, maintenance and backups
The Service is provided “as is” and “as available”. No commitment is made to uninterrupted or error-free service, a particular speed or any uptime level (SLA). The Service may be temporarily stopped without notice for planned or unplanned maintenance, updates and security work.
Percentages and history on the status page show only the results of recorded checks; they are not a guarantee or commitment.
WhatOTP takes regular backups but does not guarantee that data loss will never occur. Keep your own copies of data that matters to you, including usage reports. Inputs and outputs are not stored in WhatOTP's database and cannot be recovered.
15. Disclaimer of warranties
To the fullest extent permitted by law, WhatOTP gives no express or implied warranty as to the accuracy, reliability, completeness, timeliness, fitness for a particular purpose or merchantability of the Service, models and outputs, that they do not infringe third-party rights or contain viruses or harmful components, or that they will meet your expectations.
16. Limitation of liability
The core service is free. To the extent permitted by law, WhatOTP is not liable for indirect, incidental, special or consequential damages, or for loss of data, profits, revenue, customers, business opportunities or reputation, arising from use of or inability to use the Service, outputs, providers, unauthorised access or the changes described in these Terms.
In all cases, WhatOTP's total liability arising from these Terms or the Service is limited to the amount you actually paid WhatOTP for the Service in the 12 months before the event giving rise to the claim; if you paid nothing, liability is limited to the lowest level permitted by law.
You are responsible for using, publishing and relying on model outputs. WhatOTP is not liable for third-party claims arising from use of outputs or API keys by you or your application's users.
These limitations do not affect liability for intent or gross negligence under Article 115 of the Turkish Code of Obligations, liability for harm to life or health, or consumer rights that cannot be limited by contract.
17. Force majeure
Events beyond WhatOTP's reasonable control, such as natural disasters, epidemics, fire, flood, war, terrorism, strikes, power, infrastructure or internet outages, cyberattacks, outages at data-centre, hosting, email or AI providers, providers discontinuing their services, government orders and changes in law, are force majeure. WhatOTP's obligations are suspended for their duration and WhatOTP is not liable for resulting delay or non-performance.
18. Indemnity
To the extent permitted by law, you agree to hold WhatOTP harmless from, and reimburse amounts WhatOTP has to pay for, claims, lawsuits, administrative fines and costs (including reasonable legal fees) brought against WhatOTP because of your breach of these Terms, applicable law or third-party rights, your inputs, the way you use outputs, or use made through your API keys.
19. Suspension and termination
You may delete your account at any time from the dashboard. Deletion revokes your API keys, ends your sessions, and ends any remaining quota, package time and bonus balance without refund.
WhatOTP may suspend or close your account, keys or specific features temporarily or permanently without notice in case of breach of these Terms or provider policies, suspected abuse or fraud, security risk, requests by competent authorities, or where needed to protect the Service or other users. Packages and balances on accounts closed for breach are not refunded.
WhatOTP may discontinue the Service or part of it with reasonable prior notice on the site or by email. In that case your mandatory consumer rights regarding unused paid packages remain reserved.
Provisions on intellectual property, disclaimer of warranties, limitation of liability, indemnity, evidence and disputes survive termination.
20. Notices and communication
WhatOTP may send notices to the email registered to your account, through dashboard notifications, or by publishing them on the site. Keeping your email current is your responsibility; notices sent to the registered address are deemed received when sent. Service emails about quota, security and account actions are necessary; optional notification emails can be turned off in settings. Marketing messages are not sent without your separate consent.
You can reach us through dashboard support or the contact email address.
21. Evidence
In disputes arising from these Terms, WhatOTP's database, request and usage records, server logs, email correspondence and audit logs constitute evidence under Article 193 of the Turkish Code of Civil Procedure No. 6100. This does not remove your right to present counter-evidence or your consumer rights.
22. Changes
WhatOTP may update these Terms to reflect changes to the Service, the law or provider terms. The current text is published on this page with its effective date; material changes are also announced on the site or by email. Continuing to use the Service after publication means you accept the updated Terms. If you do not accept them, stop using the Service and delete your account.
23. Governing law and disputes
These Terms are governed by the laws of the Republic of Türkiye. For disputes to which you are a party as a consumer, consumer arbitration committees at your place of residence or where the transaction took place have jurisdiction within the monetary limits set annually by the Ministry of Trade, and consumer courts have jurisdiction above those limits. For users who are not consumers, the courts and enforcement offices at WhatOTP's place of business have jurisdiction.
Before taking a dispute to formal proceedings, we ask you to contact us through support and allow reasonable time for a resolution.
24. Miscellaneous
If any provision of these Terms is held invalid or unenforceable, the remaining provisions stay in effect; the invalid provision is deemed replaced by the valid provision closest to its purpose. WhatOTP's failure to exercise a right is not a waiver of it.
You may not transfer your rights and obligations under these Terms without WhatOTP's written permission. WhatOTP may transfer these Terms in a merger, acquisition or asset transfer. These Terms, together with the Privacy Policy and Cookie Policy, form the entire agreement between the parties. If the Turkish and English texts conflict, the Turkish text prevails.
Contact: bayyazilimcioffical@gmail.com · Dashboard support ↗