AnRouter

Privacy Policy

Last updated: September 9, 2026

1. Scope and Roles

This Privacy Policy explains how the operator of AnRouter (“AnRouter,” “we,” “us,” or “our”) processes information when you use the AnRouter website, dashboard, API gateway, documentation, payment features, or support channels (the “Services”). It should be read with our Terms of Service.

When you use the API for an organization, that organization normally decides what data is submitted and is responsible for its lawful collection and use. AnRouter processes that data only to provide the Services, subject to this Policy and any written data processing agreement. This Policy does not replace obligations that apply to you as a data controller or business.

“Personal Data” means information that identifies or can reasonably be linked to a person. “API Conversation Content” has the meaning set out below.

2. Zero Data Retention for API Conversation Content

AnRouter does not retain your API prompts or model outputs.

We do not write API Conversation Content to application databases, request or response logs, analytics systems, support systems, or backups, and we do not use it to train, fine-tune, evaluate, or improve any AI model.

API Conversation Content includes prompts, messages, system instructions, uploaded text, files, images or audio, source data submitted for embeddings or reranking, tool arguments and results, and model-generated responses. It does not include the limited usage and security metadata listed in Section 3.

Content is processed only in transient memory or short-lived request buffers for validation, format conversion, routing, retries, streaming, and delivery. Those buffers are removed when the request completes or fails and are not included in backups. Zero retention does not mean zero processing: the selected model provider must receive the content to generate a response.

Because completed API Conversation Content is not retained, AnRouter personnel cannot retrieve it after the request. If you voluntarily paste prompts, outputs, screenshots, or files into a contact form, email, or support ticket, that copy becomes Support Data and is retained under Section 7 rather than this API-path commitment.

A lawful request can require us to disclose data we actually retain, but it cannot make us produce API Conversation Content that was never stored.

3. Other Data We Collect and Retain

Account and contact data

  • Username, email address, password hash, account group, preferences, API key identifiers and status, and information needed to administer an organization or account.
  • Messages and files you choose to send through contact, support, privacy, security, or enterprise channels.

Billing and transaction data

  • Order and transaction identifiers, amount, currency, status, plan, subscription state, credit balance, and related accounting records.
  • When a payment provider hosts checkout, it receives the payment credentials needed to complete the transaction. AnRouter does not need to receive full card details from that hosted flow.

API usage and security metadata

  • Request identifier, timestamp, API route, requested model, token or unit counts, latency, response status, streaming status, error category, route or channel, and amount charged.
  • IP address, user agent, authentication events, rate-limit events, and other security signals needed to protect accounts and infrastructure.

Website analytics and advertising-measurement data

  • Pages viewed on the public website, the referring page, approximate location derived from IP address, browser and device type, and identifiers set by the third-party tools described in Section 8. This category relates to the public website only and never includes API Conversation Content.

Usage metadata describes the request but does not contain API Conversation Content. We design diagnostics to exclude prompts, uploaded content, and model responses.

4. How and Why We Use Data

  • Provide the Services, authenticate accounts and API keys, route requests, calculate usage, and deliver responses.
  • Process purchases, manage credits and subscriptions, reconcile charges, and maintain required accounting records.
  • Prevent fraud and abuse, enforce limits and provider restrictions, investigate metadata-only errors, and protect users and infrastructure.
  • Respond to support and privacy requests and send transactional, security, billing, or material service notices.
  • Meet legal obligations and establish, exercise, or defend legal claims.
  • Plan capacity and improve reliability using operational or aggregated statistics that do not contain API Conversation Content.

Depending on applicable law, these activities are based on performance of our contract with you, compliance with legal obligations, our legitimate interests in operating and securing the Services, or consent where consent is required. We do not sell Personal Data, use API Conversation Content for advertising, or use it for model training.

5. When We Disclose Data

  • Model and infrastructure providers. We transmit API Conversation Content and the parameters needed for inference to the selected upstream model provider. Hosting and network providers process traffic only as needed to deliver the Services.
  • Payment, email, support, and security providers. These providers receive only the account, transaction, communication, or technical data needed to perform their contracted function.
  • Legal requirements and safety. We may disclose retained data when reasonably necessary to comply with valid legal process, protect rights and safety, investigate fraud, or enforce our Terms.
  • Business transfers. Retained data may transfer as part of a merger, financing, reorganization, or sale of all or part of the Services, subject to this Policy and applicable law.
  • Your direction. We may disclose data when you direct us to do so or give valid consent.

We do not sell or rent Personal Data. The third-party advertising-measurement tools described in Section 8 may involve “sharing” Personal Data for cross-context behavioral advertising as some privacy laws define that term. Section 8 describes what those tools receive and how you can limit them.

6. Upstream Model Providers and Route Privacy

AnRouter is an inference gateway. Your API Conversation Content is sent to the model provider selected by you or by the routing configuration. That provider is an independent recipient and may operate in another country. Its terms, retention rules, safety systems, and legal obligations may differ from ours.

AnRouter’s zero-retention commitment applies to systems controlled by AnRouter. Provider-level or end-to-end zero data retention applies only when the selected route, model documentation, or written enterprise agreement expressly identifies that protection. A promise that a provider does not use content for training is not necessarily the same as a promise that it stores nothing.

If your workload contains regulated, confidential, biometric, or highly sensitive data, use only a route expressly identified as meeting your retention and regional requirements, or contact enterprise support before sending it. You are responsible for obtaining any notice or consent required for data about another person.

7. Retention by Data Category

  • API Conversation Content: zero retention after request completion. Transient request buffers are removed when processing completes or fails and are not backed up.
  • API usage metadata: retained only as needed to provide usage history, reconcile billing, prevent abuse, resolve disputes, and meet legal obligations; it never includes conversation bodies.
  • Account data: retained while the account is active and then deleted or de-identified when no longer needed, subject to security, fraud, dispute, and legal requirements.
  • Billing and transaction records: retained for the period required by tax, accounting, payment, anti-fraud, and other applicable laws.
  • Support Data: retained for as long as reasonably needed to resolve the request, maintain a service record, and protect legal rights. Do not send API keys or unnecessary conversation content to support.
  • Security logs: retained for the shortest period reasonably necessary to investigate abuse and protect the Services.

Backups may contain retained account, billing, support, or metadata records until normal backup rotation completes. They do not contain API Conversation Content. A legal hold applies only to data already retained; it does not change the zero-retention design for completed API content.

8. Cookies, Local Storage, and Tracking

The dashboard may use strictly necessary session or authentication cookies. The public website stores a language preference in your browser’s local storage. These technologies support login, security, navigation, and your selected interface settings.

The AnRouter public website uses a limited number of third-party analytics and advertising-measurement tools, including conversion tracking provided by advertising platforms on which we run our own campaigns. We use them to understand how visitors reach and use the site and to measure the performance of our own marketing. These tools may set or read their own cookies and receive standard request data such as the page viewed, the referring page, your IP address, and your browser type. If you are signed in to a provider’s own service in the same browser, that provider may associate the visit with your account there; the provider’s handling of that data is governed by its own privacy policy.

We do not use session-replay tools and we do not sell Personal Data. These tools never receive API Conversation Content.

You can clear cookies or local storage in your browser, use your browser’s tracking-protection settings, or use the opt-out controls a provider offers, although doing so may sign you out or reset preferences.

9. Your Choices and Privacy Rights

Depending on your location, you may have rights to know, access, correct, delete, restrict, object to, or receive a portable copy of Personal Data, and to withdraw consent where processing relies on consent. You may also complain to your local data protection authority.

You can update certain account data in the dashboard and submit a request through the contact form or the email in Section 13. We may verify your identity and may deny or limit a request where permitted by law, including to protect another person, preserve transaction records, or prevent fraud.

Because API Conversation Content is not retained after a request, there is no stored conversation history for us to access, export, correct, or delete.

10. Security

We use technical and organizational safeguards designed for the nature of the Services, including encrypted transport, access controls, credential protection, data minimization, and separation of conversation content from retained usage metadata.

No internet service can guarantee absolute security. Keep passwords and API keys confidential, never place secret keys in public or client-side code, restrict key permissions where available, and revoke exposed keys promptly. Contact us if you suspect unauthorized access.

11. International Processing

Model, hosting, network, payment, email, and support providers may process data outside your country. Where applicable law requires transfer safeguards, we use or require an appropriate lawful mechanism. A particular data-residency region is guaranteed only when expressly stated for a route or in a written enterprise agreement.

12. Children and Policy Changes

The Services are intended for business and developer use and are not directed to anyone under 18. If you believe a minor provided Personal Data without appropriate authorization, contact us so we can review and take appropriate action.

We may update this Policy when the Services, providers, or law change. The date at the top identifies the current version. If a change materially reduces privacy protections or changes how retained Personal Data is used, we will provide notice through the website, dashboard, or account contact channel before it takes effect where required.

13. Contact

For privacy, account, deletion, enterprise data processing, or security requests, contact us through: