Privacy Policy
This policy explains what information Hyperouter (“we”, “us”) collects when you use hyperouter.app, the Hyperouter API and Hyperouter Chat (the “Service”), how we use it, and the choices you have.
1. Summary
- We do not store your prompts or model outputs by default.
- We do not sell personal information, and we do not use your content to train models.
- Your prompts are sent to the model provider that serves each request. You control which providers are eligible.
- We keep request metadata (model, provider, token counts, cost, time) so we can bill you and keep the Service running.
2. Information we collect
Information you give us
- Account and contact details: name, email, company, and anything you include when you request access or email us.
- Payment information: card payments are handled by our payment processor; we receive only the card brand, last four digits, expiry and billing country. For crypto top-ups we record the sending wallet address, asset, amount and transaction hash.
Information collected automatically
- Request metadata: timestamp, API key ID, model, provider, token counts, cost, latency, status code and the optional
userfield you send. - Technical data: IP address, user agent and request headers, used for security, abuse prevention and rate limiting.
3. Prompts and outputs
Prompts, files and model outputs pass through our systems in memory to be routed and returned. They are not written to storage unless you turn on logging for your account, in which case they are kept for the period you choose so you can review them.
To fulfil a request we send its content to the model provider selected for that request. Providers process it under their own terms; some may retain data for a limited time for abuse monitoring. Set provider.data_collection to "deny" (see Routing) to use only providers that neither retain prompts nor train on them.
In rare cases we may review content linked to a specific request if it has been flagged for abuse or you ask us to investigate it.
4. How we use information
- to provide, route and bill requests, and to show you usage and spend;
- to issue API keys and respond to your emails;
- to detect and prevent fraud, abuse and security incidents;
- to measure provider performance and improve routing, using metadata only;
- to send service notices, such as changes to these policies or to pricing;
- to meet legal, tax and accounting obligations.
Where the GDPR applies, we rely on performance of our contract with you, our legitimate interests in running a secure service, and compliance with legal obligations.
5. Who we share information with
- Model providers, which receive request content needed to serve your request.
- Service providers that host our infrastructure, process payments or send email for us, under contracts that limit their use of the data.
- Authorities, when required by law or to protect the rights, safety or property of our users or others.
- A successor, if Hyperouter is involved in a merger, acquisition or sale of assets, subject to this policy.
6. Retention
| Data | Kept for |
|---|---|
| Prompts and outputs | Not stored, unless you enable logging |
| Request metadata | Life of the account, plus up to 24 months |
| Payment and invoice records | As long as tax and accounting law requires, typically 7 years |
| Security logs (IP, user agent) | 90 days |
| Access request emails | Until the request is closed, plus 12 months |
7. Security
Traffic to the Service is encrypted in transit with TLS. API keys are stored hashed. Access to production systems is limited to staff who need it. No system is perfectly secure; if we learn of a breach that affects your personal information, we will notify you as required by law.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. California residents may request to know what we collect and ask us to delete it; we do not sell or share personal information for cross-context behavioral advertising.
To make a request, email account@hyperouter.app from the address on your account. We will respond within 30 days. You may also complain to your local data protection authority.
9. International transfers
We and our providers may process information in countries other than yours. Where required, we use appropriate safeguards such as Standard Contractual Clauses for these transfers.
10. Cookies
hyperouter.app does not use advertising or analytics cookies. The site loads fonts from Google Fonts, which receives your IP address when you visit. Signed-in areas may use strictly necessary cookies to keep you logged in.
11. Children
The Service is not directed to children under 18, and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will delete it.
12. Changes
We may update this policy. We will post the new version here with a new effective date and, for material changes, notify account holders by email before they take effect.
13. Contact
Privacy questions or requests: account@hyperouter.app.