Privacy Policy

Effective September 24, 2026

This policy explains what information Hyperouter (“we”, “us”) collects when you use hyperouter.app, the Hyperouter API and Hyperouter Chat (the “Service”), how we use it, and the choices you have.

1. Summary

2. Information we collect

Information you give us

Information collected automatically

3. Prompts and outputs

Prompts, files and model outputs pass through our systems in memory to be routed and returned. They are not written to storage unless you turn on logging for your account, in which case they are kept for the period you choose so you can review them.

To fulfil a request we send its content to the model provider selected for that request. Providers process it under their own terms; some may retain data for a limited time for abuse monitoring. Set provider.data_collection to "deny" (see Routing) to use only providers that neither retain prompts nor train on them.

In rare cases we may review content linked to a specific request if it has been flagged for abuse or you ask us to investigate it.

4. How we use information

Where the GDPR applies, we rely on performance of our contract with you, our legitimate interests in running a secure service, and compliance with legal obligations.

5. Who we share information with

6. Retention

DataKept for
Prompts and outputsNot stored, unless you enable logging
Request metadataLife of the account, plus up to 24 months
Payment and invoice recordsAs long as tax and accounting law requires, typically 7 years
Security logs (IP, user agent)90 days
Access request emailsUntil the request is closed, plus 12 months

7. Security

Traffic to the Service is encrypted in transit with TLS. API keys are stored hashed. Access to production systems is limited to staff who need it. No system is perfectly secure; if we learn of a breach that affects your personal information, we will notify you as required by law.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. California residents may request to know what we collect and ask us to delete it; we do not sell or share personal information for cross-context behavioral advertising.

To make a request, email account@hyperouter.app from the address on your account. We will respond within 30 days. You may also complain to your local data protection authority.

9. International transfers

We and our providers may process information in countries other than yours. Where required, we use appropriate safeguards such as Standard Contractual Clauses for these transfers.

10. Cookies

hyperouter.app does not use advertising or analytics cookies. The site loads fonts from Google Fonts, which receives your IP address when you visit. Signed-in areas may use strictly necessary cookies to keep you logged in.

11. Children

The Service is not directed to children under 18, and we do not knowingly collect their information. If you believe a child has given us information, contact us and we will delete it.

12. Changes

We may update this policy. We will post the new version here with a new effective date and, for material changes, notify account holders by email before they take effect.

13. Contact

Privacy questions or requests: account@hyperouter.app.