Legal
Privacy Policy
Last updated: August 27, 2026
This policy explains what data RouterPlex collects, why we collect it, and where your prompts actually go. We have tried to keep it short and honest.
01What we collect
- Account data — email address, first and last name, a salted hash of your password (never the password itself), and, if you enable it, a TOTP two-factor secret.
- Usage metadata — per-request logs with timestamp, model, token counts, cost, and the API key used. This powers your dashboard analytics and billing.
- Arena evaluation metadata — when you use Model Arena, we retain the two model IDs, preset task ID or a one-way custom-prompt hash, token counts, cost, latency, your vote, and an optional invalid-result reason. We do not retain the prompt or either model response.
- Payment records — top-up amount, payment method, status, and a payment reference from the processor. Card details are handled entirely by our payment processors and never reach our servers.
- GitHub OAuth — if you sign in with GitHub we receive your GitHub account ID and email address, nothing else.
02Your prompts and outputs
RouterPlex does not store, log, retain, or read the content of your prompts or the model’s responses. Your request passes through our gateway in memory only, for the sole purpose of routing it to the model you selected and returning the response to you. Once the response is delivered, that content is gone from our systems — it is never written to a database, a log file, or long-term storage.
RouterPlex does not use your prompts or outputs to train models, does not analyze them, and does not sell or share them with anyone beyond the model provider needed to answer the request. There is exactly one exception, it applies only to models explicitly labelled “Contributor”, and it takes effect only if you choose one of those models yourself — see the end of this section. The only thing we keep about a request is the usage metadata listed above — model, token counts, cost, and timestamp — which is what powers your billing and dashboard. That metadata never includes the text you sent or received.
Model Arena follows the same rule. Both outputs are returned to your browser for the comparison and then discarded. Preset benchmark tasks are public task definitions that RouterPlex stores and versions; custom prompt text and all generated outputs remain ephemeral. Aggregate votes, latency, token use, and cost may be published as model benchmark statistics without identifying your account.
One thing we cannot do on your behalf: to actually answer a request, we must transmit your prompt to the third-party provider operating the model you chose, and they return the response. That provider processes your prompt under its own privacy terms while generating the answer — this is inherent to what an AI gateway does, and no gateway can avoid it.
“Contributor” models are the one exception to the no-training rule above. A provider may offer a model at a heavily reduced token price on the condition that the prompts and completions sent to it may be used to train that provider’s future models. The discount is, in effect, paid for with the content of the request. Where RouterPlex lists such a model, the word “Contributor” appears in its name, and the condition is stated on its catalog entry and its model page.
For those models, and only those models, the text you send and receive leaves our gateway under a licence permitting the model’s operator to train on it. RouterPlex’s own rule is unchanged — we still store, log, and retain nothing — but we cannot retrieve that content from the provider once it has been sent, so you should not send confidential, personal, or client-owned material to a Contributor model. A Contributor model is never a default and never a fallback: a request reaches one only when you name it explicitly in the request’s model field. Providers may also limit these models to particular regions. Every other model in the catalog remains covered by the no-training rule above.
03Cookies and analytics
We use a secure, first-party session cookie to keep you signed in and first-party attribution cookies to remember your first visit and most recent non-direct visit for up to 90 days. Attribution can include source, medium, campaign name, referrer domain, and landing-page path; we do not retain full URL query strings. After measurement consent, Affonso may store a first-party referral cookie for 30 days so an affiliate can be credited for a later signup or eligible payment. A Reddit click ID may also be stored in a first-party cookie for up to 30 days so a later signup or payment can be attributed to the ad engagement. After measurement consent, a Paved click ID may likewise be stored in a first-party cookie for up to 60 days so a later paid top-up can be attributed to a Paved newsletter or ad placement. After measurement consent, Google's tag may store a Google click identifier from a paid search ad so a later payment can be attributed. We operate Plausible Community Edition on our own infrastructure to count aggregate page visits and selected funnel events. Plausible does not use cookies or persistent cross-site identifiers, does not retain raw IP addresses, and never receives prompt content or account identifiers. The Google tag (gtag.js) is present on public pages so Google Ads can detect it and so Consent Mode can run. Until you allow measurement, Google storage is denied: we do not set Google Analytics or Ads cookies, and conversion events are not sent. Cookieless Consent Mode pings may still reach Google. With your consent, we also load PostHog, Google Analytics, Google Ads conversion measurement, Reddit Pixel, Paved, and Affonso to measure signups, checkout starts, and completed payments. The Paved pixel records only a page load; a completed top-up is reported to Paved from our server once the payment settles, so no purchase event is sent from your browser. Google Ads is used to attribute a later paid top-up or paid plan to a search ad click. We do not use it for remarketing or ad personalization. PostHog provides product analytics and session replay: it sets first-party cookies, records pageviews, clicks, and funnel events, and reconstructs a visual replay of your session on our site. Replay masks every form input, is switched off entirely on the API keys and guided setup pages, and redacts key-shaped text before it leaves your browser. If you are signed in we associate PostHog activity with your account ID; we never send PostHog your email address. Reddit Pixel and Reddit's server-side Conversions API also attribute conversions from Reddit ads and use matching event IDs to avoid double-counting. These tools are disabled by default, never receive prompt content, and operate only after you consent. For consented server-side events, we send Reddit a one-way hash of your normalized email address and account ID, plus event details such as type, time, value, currency, and conversion ID. When Reddit automatic advanced matching is enabled, Reddit may also collect email addresses or phone numbers shown or entered on the page after consent and hash them for conversion matching. You can decline measurement from the consent banner and continue using the service normally.
04Who we share data with
- Model providers — receive your prompts to generate a response, as described above.
- Payment processors — process card and crypto top-ups; they see the payment details, we see only the reference.
- Infrastructure — our servers and databases, operated by us and our hosting provider.
- PostHog — receives product analytics, funnel events, and masked session replays only when you consent; processed in the United States.
- Google Analytics — the tag loads with storage denied; it receives pseudonymous website and funnel activity only when you consent.
- Google Ads — the same Google tag is used so Ads can detect installation. Conversion events for paid top-ups and paid plans, with value and a transaction ID, are sent only when you consent. Remarketing and ad personalization stay off.
- Affonso — receives referral and eligible conversion information so affiliates can be credited, only when you consent to measurement.
- Reddit measurement — Reddit Pixel and the Conversions API receive selected conversion events and hashed account identifiers only when you consent, for Reddit ad attribution and deduplication.
- Paved — receives a page-load signal from the pixel and, when a top-up settles, a server-side conversion containing only the Paved click ID and the top-up value. No email address, account ID, or prompt content is sent, and only when you consent to measurement.
- Sentry — receives technical error and performance metadata when error monitoring is enabled; default personal-data collection is disabled.
We do not sell personal data or share prompt content with analytics or advertising measurement providers.
05Retention
Prompt and response content is never retained — see section 02, it is not stored in the first place. Account data is kept while your account exists. Usage metadata and payment records are kept for accounting and abuse prevention. If you delete your account, we delete or anonymize your personal data within 30 days, except records we are legally required to keep (e.g. payment records for tax purposes).
06Your rights
You can access and update your account data from the dashboard. You can request a copy of your data, or deletion of your account and data, by emailing us. Depending on where you live (e.g. under GDPR), you may also have rights to restrict or object to processing and to lodge a complaint with a supervisory authority.
07Security
All traffic is encrypted in transit (TLS). Passwords are stored as salted hashes, API keys are held only in hashed or encrypted form. To let you resume guided setup, we temporarily retain your setup key encrypted in our database and remove that recoverable copy after your first successful request. Two-factor authentication is available on every account, and access to production systems is restricted. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you without undue delay.
08Changes & contact
We will announce material changes to this policy on the website or by email. Privacy questions and requests: support at routerplex.com