Privacy Policy
Last updated: 2026-07-10
This policy explains how KeepRouter ("the Service", "we", "us") collects, uses, stores and shares information when you use our multi-model LLM API gateway, and the rights you have under applicable law (such as the GDPR, UK GDPR, CCPA/CPRA). For GDPR purposes, we are the "data controller" to the extent we determine the purposes and means of processing; for the Inputs/Outputs you forward to upstream models through the Service, we generally act only as a forwarding conduit, and the relevant processing is the responsibility of each upstream provider as an independent controller.
The data controller is the Service operator, KeepRouter; the contact for data-protection matters is support@keeprouter.com.
1. Information We Collect
We follow the principle of data minimization and collect only what is necessary to operate:
- Account information: your email address (for one-time-code sign-in, billing and important notices).
- Usage metadata: per-call model name, token counts, cost, timestamp, and the request identifiers, status codes and latency needed for security and billing.
- Payment information: we do not collect or store your full card number or similar payment credentials; payment is handled by the Merchant of Record, Paddle. We receive from Paddle only the limited information needed to confirm and reconcile transactions (such as transaction id, amount, status, country/region).
- API keys: your
sk-kr-keys are stored hashed; we do not keep the plaintext. - Technical information: the basic information needed to maintain a sign-in session and prevent abuse (such as IP address, coarse geolocation, session identifier, basic device/browser information).
2. Prompts & Responses
2.1 Prompts and responses are not stored by default. Under the default configuration, we do not persistently store the prompts you send or the response bodies returned by models; we record only usage metadata.
2.2 Upstream forwarding notice: To provide the Service, your requests (including prompts) must be forwarded in real time through the routing/API intermediary and/or upstream model provider serving the selected model. A routing intermediary may receive the request before it reaches the model maker. Once data leaves the Service for any such recipient, it is subject to that recipient's own data and privacy policies, which may include using the data for its own purposes or model training.
We therefore cannot control or guarantee that these recipients will not use your Inputs/Outputs for training or other purposes. If you have concerns, review the relevant recipient policies before submitting, and avoid submitting sensitive or confidential information, special-category personal data, or other people's personal information.
3. Purposes & Legal Bases (GDPR)
The purposes for which we process personal data and the corresponding GDPR legal bases are:
- Providing and maintaining the Service, handling sign-in and request forwarding — performance of a contract (Art. 6(1)(b)).
- Metering, billing and credit management — performance of a contract (Art. 6(1)(b)); tax/accounting retention — legal obligation (Art. 6(1)(c)).
- Preventing abuse and fraud and ensuring security — legitimate interests (Art. 6(1)(f)).
- Service-related notices and customer support — performance of a contract / legitimate interests.
- Complying with legal obligations and responding to lawful law-enforcement or regulatory requests — legal obligation (Art. 6(1)(c)).
We generally do not rely on "consent" to process the necessary data above; where a processing activity is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
4. Sharing & Sub-processors
We do not sell, nor "share" for cross-context behavioral advertising (including "sale/share" as defined under CCPA/CPRA), your personal information. We disclose information only in the following cases: forwarding requests through routing/API intermediaries and upstream model providers to provide the Service; engaging the infrastructure/service providers (sub-processors) below to process under our instructions; where required by law or necessary to protect lawful interests; and in a merger, acquisition or transfer of assets (where this policy continues to apply).
Key sub-processors / third parties (category and purpose):
| Provider | Purpose |
|---|---|
| Cloudflare | Cloud compute, networking, edge storage and security (infrastructure) |
| Paddle | Payment processing and Merchant of Record, taxes, refunds |
| Cloudflare Email Sending | Sending one-time sign-in code emails |
| Routing/API intermediaries and upstream model providers (including API aggregators and model makers such as OpenAI, Anthropic, Google, Qwen, Kimi, GLM, DeepSeek and MiniMax) | Routing, processing and responding to the requests you forward |
A request may pass through a routing/API intermediary before reaching the model maker. These categories describe the current processing chain without publishing the private per-model serving route. The specific recipient and its data-protection role may change with routing configuration; a current recipient list is available on request at support@keeprouter.com.
5. Retention
5.1 Usage metadata and operational logs are retained for about 30 days, then deleted or anonymized (except where required by law or necessary to resolve disputes / prevent abuse).
5.2 Billing ledgers may be retained longer for tax, reconciliation and compliance needs; after account deletion they are retained in anonymized form (see Section 6).
5.3 Basic account information is retained for the life of the account; deletion requests are handled per Section 6.
6. Deletion & Anonymization
6.1 You can delete your account in console Settings, or contact support@keeprouter.com.
6.2 When a deletion is processed (typically within about 30 days), we anonymize / redact personally identifiable information (PII) (removing your email, etc.), while retaining the anonymized billing ledger to meet financial and compliance requirements. Anonymized records no longer point to you personally and cannot be reversed.
7. Cookies & Local Storage
We use cookies or equivalent local storage necessary to keep you signed in and save interface preferences. This release does not load Microsoft Clarity or any other third-party session-recording tool, and these storage mechanisms are not used for cross-site targeted advertising.
8. Security & Breach Notification
8.1 We take reasonable technical and organizational measures (key hashing, TLS in transit, access control, data minimization) to protect information; however, no system can guarantee absolute security.
8.2 Breach notification: If a security incident compromises your personal data, we will notify the relevant supervisory authority within the time required by applicable law (for example, generally within 72 hours of becoming aware under the GDPR), and notify affected users promptly where required by law.
9. International Transfers
The Service operates globally, and your information may be transferred to and processed in countries/regions outside your location (including where upstream providers and our service providers are located). For transfers out of the EEA/UK, we rely on appropriate transfer mechanisms (such as Standard Contractual Clauses / the UK IDTA, adequacy decisions, or certified transfer frameworks) as safeguards; related information is available on request.
10. Not Offered in Mainland China
The Service is not offered to users within mainland China, and does not seek to carry out personal-information processing within the meaning of the Personal Information Protection Law (PIPL) within mainland China or to collect personal information directed at mainland China.
11. Your Rights
11.1 Depending on applicable law (such as the GDPR / UK GDPR), you may have rights to access, rectify, delete, restrict processing, data portability, object to processing and withdraw consent, and the right to lodge a complaint with your local data-protection authority.
11.2 California residents (CCPA/CPRA): you have the right to know/access, delete and correct the personal information collected, the right to opt out of "sale/share" (as noted, we do not sell or share for cross-context advertising), the right to limit the use of sensitive personal information, and we will not discriminate or retaliate against you for exercising your rights. The Service is intended only for those 18 and older.
11.3 To exercise these rights, contact support@keeprouter.com; we will verify your identity as required by law and respond within the statutory time frame. You may also use an authorized agent to make a request.
12. DPA for Business Customers
If, as a business customer, you use the Service in a way where we process your end users' personal data on your behalf, contact support@keeprouter.com to discuss whether a Data Processing Agreement (DPA) is appropriate for your use case.
13. Minors
The Service is intended only for those aged 18 and older; we do not knowingly collect personal information from minors. If we discover such collection in error, we will delete it.
14. Changes
We may update this policy from time to time and will notify material changes by reasonable means (such as an in-product notice or email); the effective version is as of the "Last updated" date shown on this page.
15. Contact
For data-protection matters, contact: support@keeprouter.com