Legal
Privacy Policy
Last updated: July 28, 2026
This policy explains what data RouterPlex collects, why we collect it, and where your prompts actually go. We have tried to keep it short and honest.
01What we collect
- Account data — email address, first and last name, a salted hash of your password (never the password itself), and, if you enable it, a TOTP two-factor secret.
- Usage metadata — per-request logs with timestamp, model, token counts, cost, and the API key used. This powers your dashboard analytics and billing.
- Arena evaluation metadata — when you use Model Arena, we retain the two model IDs, preset task ID or a one-way custom-prompt hash, token counts, cost, latency, your vote, and an optional invalid-result reason. We do not retain the prompt or either model response.
- Payment records — top-up amount, payment method, status, and a payment reference from the processor. Card details are handled entirely by our payment processors and never reach our servers.
- GitHub OAuth — if you sign in with GitHub we receive your GitHub account ID and email address, nothing else.
02Your prompts and outputs
RouterPlex does not store, log, retain, or read the content of your prompts or the model’s responses. Your request passes through our gateway in memory only, for the sole purpose of routing it to the model you selected and returning the response to you. Once the response is delivered, that content is gone from our systems — it is never written to a database, a log file, or long-term storage.
We do not use your prompts or outputs to train models, we do not analyze them, and we do not sell or share them with anyone beyond the model provider needed to answer the request. The only thing we keep about a request is the usage metadata listed above — model, token counts, cost, and timestamp — which is what powers your billing and dashboard. That metadata never includes the text you sent or received.
Model Arena follows the same rule. Both outputs are returned to your browser for the comparison and then discarded. Preset benchmark tasks are public task definitions that RouterPlex stores and versions; custom prompt text and all generated outputs remain ephemeral. Aggregate votes, latency, token use, and cost may be published as model benchmark statistics without identifying your account.
One thing we cannot do on your behalf: to actually answer a request, we must transmit your prompt to the third-party provider operating the model you chose, and they return the response. That provider processes your prompt under its own privacy terms while generating the answer — this is inherent to what an AI gateway does, and no gateway can avoid it.
03Cookies and analytics
We use a secure, first-party session cookie to keep you signed in and first-party attribution cookies to remember your first visit and most recent non-direct visit for up to 90 days. Attribution can include source, medium, campaign name, referrer domain, and landing-page path; we do not retain full URL query strings. After measurement consent, Affonso may store a first-party referral cookie for 30 days so an affiliate can be credited for a later signup or eligible payment. A Reddit click ID may also be stored in a first-party cookie for up to 30 days so a later signup or payment can be attributed to the ad engagement. With your consent, we load Google Analytics, Reddit Pixel, and Affonso to measure aggregate page visits and funnel events such as signup, checkout starts, and completed payments. Reddit Pixel and Reddit's server-side Conversions API also attribute conversions from Reddit ads and use matching event IDs to avoid double-counting. These tools are disabled by default, never receive prompt content, and operate only after you consent. For consented server-side events, we send Reddit a one-way hash of your normalized email address and account ID, plus event details such as type, time, value, currency, and conversion ID. When Reddit automatic advanced matching is enabled, Reddit may also collect email addresses or phone numbers shown or entered on the page after consent and hash them for conversion matching. You can decline measurement from the consent banner and continue using the service normally.
04Who we share data with
- Model providers — receive your prompts to generate a response, as described above.
- Payment processors — process card and crypto top-ups; they see the payment details, we see only the reference.
- Infrastructure — our servers and databases, operated by us and our hosting provider.
- Google Analytics — receives pseudonymous website and funnel activity only when you consent.
- Affonso — receives referral and eligible conversion information so affiliates can be credited, only when you consent to measurement.
- Reddit measurement — Reddit Pixel and the Conversions API receive selected conversion events and hashed account identifiers only when you consent, for Reddit ad attribution and deduplication.
- Sentry — receives technical error and performance metadata when error monitoring is enabled; default personal-data collection is disabled.
We do not sell personal data or share prompt content with analytics or advertising measurement providers.
05Retention
Prompt and response content is never retained — see section 02, it is not stored in the first place. Account data is kept while your account exists. Usage metadata and payment records are kept for accounting and abuse prevention. If you delete your account, we delete or anonymize your personal data within 30 days, except records we are legally required to keep (e.g. payment records for tax purposes).
06Your rights
You can access and update your account data from the dashboard. You can request a copy of your data, or deletion of your account and data, by emailing us. Depending on where you live (e.g. under GDPR), you may also have rights to restrict or object to processing and to lodge a complaint with a supervisory authority.
07Security
All traffic is encrypted in transit (TLS). Passwords are stored as salted hashes, API keys are held only in hashed or encrypted form by the gateway, two-factor authentication is available on every account, and access to production systems is restricted. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you without undue delay.
08Changes & contact
We will announce material changes to this policy on the website or by email. Privacy questions and requests: support at routerplex.com