Privacy Policy

Last updated: August 7, 2026

1. Overview

TokenRouter LLC, located in Marlton, New Jersey 08053, USA ("TokenRouter", "we", "us") operates an AI gateway service that routes API requests from your applications to third-party AI model providers. This policy describes what data we collect, how we use it, and the choices you have. It applies to tokenrouter.io, the TokenRouter console, and the gateway API at api.tokenrouter.io. For account and billing data we act as the data controller; for content routed through the gateway we act as a data processor on your instructions.

2. The short version

  • We do not store your prompts or completions by default. Request and response bodies are processed transiently in memory to route them to your chosen provider and are discarded once the response is delivered.
  • Message capture is an explicit opt-in. On paid plans, organization admins can enable capture for specific API keys, teams, or members. Only conversations covered by an enabled scope are stored — encrypted at rest, deleted after your plan's retention window, and deletable at any time from the console.
  • For everything else we retain only usage metadata: token counts, computed cost, model and provider identifiers, latency, status codes, and the team/member/key attribution needed for budgets and analytics.
  • Provider API keys you bring (BYOK) are stored encrypted using authenticated AES encryption, decrypted only in memory at request time, and never written to logs.
  • We never sell personal data and never use your API traffic to train models.

3. Data we collect

Account data

Name, email address, password hash, organization and team names, and roles. If you sign in with Google or GitHub, we receive your name and email address from that provider; we never receive your password. We use account data to operate your account, authenticate you, and send transactional email (via Resend).

Billing data

Subscription plan, billing status, and invoices. Card details are collected and processed by Stripe; we never see or store full card numbers.

Gateway usage metadata

For each request routed through the gateway we record: timestamp, API key identifier, team and member attribution, model and provider, input/output token counts, computed cost, latency, and response status. Unless capture is enabled for the request's scope (below), we do not record prompt text, completion text, images, embeddings vectors, or tool arguments.

Captured messages (opt-in)

When an organization admin enables capture for an API key, team, or member, the request and response bodies of that scope's gateway traffic are stored so your organization can review them in the console and run evaluations. Captured bodies are encrypted at rest with authenticated encryption, oversized content is truncated at capture time, retention is capped by your plan (and any shorter window you configure), and admins can delete all captured data instantly. Capture never applies to organizations that have not enabled it.

Provider credentials

Provider API keys you add to your account are stored encrypted and used solely to forward your requests to the corresponding provider.

Site data

Standard server logs (IP address, user agent, requested URL) retained briefly for security and abuse prevention.

4. How we use data

To operate the gateway; enforce budgets, rate limits, and model allowlists; show you analytics; bill your subscription; provide support; secure the service; and comply with legal obligations. We process API traffic only as a data processor acting on your instructions. Where GDPR applies, our legal bases are performance of our contract with you, our legitimate interests in securing and improving the Service, and compliance with legal obligations.

5. Cookies

We use only essential cookies: session cookies that keep you signed in to the console and a short-lived cookie used during sign-in with Google or GitHub. We do not use advertising cookies, third-party analytics trackers, or cross-site tracking, so there is no cookie banner to click through.

6. Subprocessors

We rely on a small set of subprocessors:

  • Amazon Web Services (AWS) — cloud hosting and encrypted storage.
  • Stripe — payment processing and subscription billing.
  • Resend — transactional email delivery.

In addition, when you route a request through the gateway, its content is transmitted to the AI provider you selected (for example OpenAI or Anthropic) under your own account and keys. Each provider processes that content under its own terms and privacy policy.

7. Data retention

Usage metadata is retained for the life of your account so budgets and analytics work, and deleted within 90 days of account deletion. Captured messages (opt-in) are deleted automatically at the end of your plan's retention window — or the shorter window your admins configure — and can be purged on demand from the console. Encrypted provider keys are deleted immediately when you remove them or delete your account. Backups age out within 35 days.

8. Security

All traffic is encrypted in transit with TLS. Secrets and provider keys are encrypted at rest using authenticated AES encryption with managed key rotation. Access to production systems is restricted, logged, and protected by multi-factor authentication.

9. Your rights (GDPR / CCPA)

Depending on where you live, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. We do not sell personal data or share it for cross-context behavioral advertising, and we do not discriminate against you for exercising your rights. To exercise any of these rights, email support@tokenrouter.io. We respond within 30 days. If you are in the EEA or UK, you may also lodge a complaint with your supervisory authority.

10. Children

The Service is not directed to children and requires users to be at least 18 years old. We do not knowingly collect personal data from anyone under 18; if you believe we have, contact us and we will delete it.

11. International transfers

Data is processed in the United States. Where required, transfers from the EEA/UK are protected by Standard Contractual Clauses with our subprocessors.

12. Changes & contact

We will post any changes to this policy here and update the date above. Material changes will be announced by email. Questions or privacy requests: support@tokenrouter.io
TokenRouter LLC, Marlton, New Jersey 08053, USA