Privacy Policy

Last updated: August 18, 2026

ModelRouters (“we,” “us”) is operated by Complex AI, Inc. and provides an OpenAI-compatible inference API at modelrouters.net and api.modelrouters.net. This policy explains what we collect, how we use it, and the choices you have.

Information we collect

  • Account information. Your email address, and — if you sign in with Google — your basic Google profile (name, email, avatar). Authentication is handled by Supabase.
  • Payment information. Subscription and card details are collected and processed by Stripe. We never receive or store your full card number; we store only a Stripe customer reference and your subscription status.
  • API usage metadata. For each request we record metadata needed for billing and abuse prevention: timestamp, the model used, token counts, and your API key identifier.
  • Provider credentials. If you connect a bring-your-own provider key, we store it encrypted at rest. The gateway decrypts it transiently only when forwarding a request to the provider endpoint you selected.
  • Optional memory and chats. Purchasing the memory and saved chats bundle enables both features by default; you can disable either one in the dashboard. While a feature is enabled, we retain the content needed to provide it. Message content, facts, summaries, profiles, and saved chats are encrypted at rest; distilled embeddings used for retrieval are not reversible encryption and are stored separately from raw messages.
  • Technical data. Limited network and security logs (e.g., IP address) processed by our infrastructure providers to operate and protect the service.

Content handling

When memory and chat storage are disabled, the gateway does not persist your prompt or completion content for ordinary billing. Requests and responses still pass through the gateway and the model provider you choose. If you enable memory or chat storage, the encrypted content described above is retained so those features can work. When memory is enabled, relevant conversation excerpts and derived summaries may be processed transiently by contracted AI model and embedding providers to extract and retrieve memory; those providers receive only the content needed for that operation and process it under their API data terms. Limited owner test accounts may separately opt into explicit quality-evaluation capture; ordinary users are not included.

How we use data

  • To provide, maintain, and secure the API and your account.
  • To meter hosted-model usage, apply credits, and process billing.
  • To provide memory, retrieval, and saved chats when you opt in.
  • To prevent fraud, abuse, and violations of our Terms.
  • To respond to support requests and required legal obligations.

Service providers

We share the minimum data necessary with providers that help us run the service: Stripe (payments), Supabase (auth and database), Cloudflare (network and DDoS protection), and our hosting providers. We do not sell your personal information. For opted-in memory processing, we also use contracted AI model and embedding API providers, currently including OpenAI and Anthropic, with server-side credentials.

Data retention

We keep account and billing records for as long as your account is active and as required for legal, accounting, and fraud-prevention purposes. Usage metadata is retained to support billing and security. Raw memory turns expire according to the configured retention period; derived memory and saved chats remain until you delete them, disable the feature as described in the product, or delete your account.

Your choices

You may access, correct, or delete your account information, and revoke or regenerate your API key, remove provider connections, and view, edit, pin, or delete supported memory from your dashboard. You may delete saved chats and your account through the product.

Security

ModelRouters API keys are random, shown once, and stored as one-way SHA-256 hashes. BYOK credentials and opted-in content are encrypted at rest with per-account keys derived from a protected master key. Traffic is encrypted in transit. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect your data.

Children

The service is not directed to individuals under 18, and we do not knowingly collect their data.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above.

Contact

Questions or requests? Email support.modelrouters@gmail.com.