AI Gateway HQ
ProductQuality of earningsPrivate equityPricingLearning centerTrustSign inStart free
Data handling

Privacy Notice

This notice separates public-site analytics, account administration, gateway request processing, provider credentials, support data, and payment records so customers can understand which data is used where.

EffectiveAugust 6, 2026
Customer policiesTerms of ServiceEvaluation AgreementPrivacy NoticeRefund and Cancellation PolicyAcceptable Use PolicySubprocessor List
On this page1. Scope and roles2. Information we collect3. Prompt, output, and credential handling4. How information is used5. Disclosure and subprocessors6. Analytics and privacy choices7. Retention and deletion8. Security9. International processing10. Individual rights11. Children and changes

1. Scope and roles

This Privacy Notice applies to personal information processed through AI Gateway HQ public websites, account and support workflows, control plane, gateway services, and commercial interactions. It does not govern a model provider, identity provider, payment processor, or other third party operating under its own terms.

For public-site, account, security, and billing administration data, AI Gateway HQ generally determines why and how information is used. For Customer Content sent through the gateway on an organization's instructions, AI Gateway HQ generally acts as that organization's service provider or processor. An executed data processing addendum controls if it conflicts with this notice.

2. Information we collect

  • Account and organization data: name, work email, organization, role, authentication identifiers, membership, permissions, and administrative contacts.
  • Configuration and security data: virtual-key metadata, provider and route configuration, budget and policy settings, IP address, user agent, sign-in and administrative events, and support-access approvals.
  • Gateway evidence: request identifiers, model and provider choice, decision reason, status, timing, token and cost measurements, cache and fallback outcome, and policy or guardrail result.
  • Customer Content: prompts, files, tool instructions, outputs, and related request content when needed to relay or evaluate the request under Customer's configuration.
  • Commercial data: plan, service credit ledger, invoices, payment status, Stripe customer and transaction identifiers, billing contact, tax status, and dispute or refund events. AI Gateway HQ does not store full card numbers or card security codes.
  • Support and public inquiries: messages, attachments, troubleshooting evidence, ticket history, and the contact information submitted with them.
  • Consent-based website analytics: page, referrer, campaign, approximate location, device/browser data, and interaction measurements only after the visitor permits analytics where the consent control is presented.

3. Prompt, output, and credential handling

The gateway is designed not to persist prompt and output bodies in ordinary request evidence by default. Request content is processed in memory as needed to evaluate policy, route the request, relay it to the selected provider, and return a response. A Customer-enabled cache, support investigation, guardrail integration, webhook, or future feature can change that data path; the applicable interface, documentation, or Order must identify the change.

Provider credentials submitted through supported write-only workflows are encrypted at rest and decrypted only for authorized request execution. Interfaces return credential status and metadata rather than the secret value. We do not use Customer provider credentials to train models or for unrelated traffic.

A selected model provider receives the content Customer sends to it. Customer must review that provider's data-use, retention, region, and model-training settings. BYOK traffic uses the provider relationship chosen by Customer; managed-provider traffic, when expressly enabled, follows the provider and deployment terms stated for that service.

4. How information is used

  • Authenticate users and service clients; enforce membership, role, policy, rate, concurrency, and budget boundaries.
  • Route and deliver model requests, calculate usage, reserve and reconcile service credit, and operate customer-selected features.
  • Secure the Services, investigate misuse or incidents, diagnose failures, prevent fraud, and preserve audit evidence.
  • Provide onboarding, support, service notices, and requested commercial or security information.
  • Process payments, subscriptions, refunds, disputes, taxes, and accounting records when billing is enabled.
  • Measure and improve public content and campaigns using consented analytics. Public-site analytics are not used to collect prompt content or provider credentials.
  • Comply with law, enforce agreements, and establish or defend legal claims.

5. Disclosure and subprocessors

We disclose information only as needed to operate the Services, follow Customer instructions, process a transaction, protect rights and safety, complete a corporate transaction with appropriate safeguards, or comply with valid legal process. We do not sell personal information for money and do not use Customer Content for cross-context behavioral advertising.

The Subprocessor List identifies infrastructure, payment, and analytics providers used by AI Gateway HQ and explains customer-directed model providers separately. Personnel and contractors receive access only for a defined business need and are subject to confidentiality and access controls.

6. Analytics and privacy choices

The public website's analytics control defaults nonessential measurement off until a visitor makes a choice. A visitor can reopen Privacy choices in the site footer to change that decision. Essential storage used for security, load delivery, consent state, or sign-in is not advertising storage.

AI Gateway HQ uses aggregated service measurements to operate capacity and reliability. These operational measurements are separate from optional public-site analytics and are not intended to reconstruct prompt bodies.

7. Retention and deletion

Retention depends on the record and service configuration. Ephemeral request content is not intentionally retained after request processing unless a Customer-enabled feature or support action requires it. Security, administrative, usage, billing, and audit records are retained for the period reasonably needed to operate the Services, meet contractual or legal duties, prevent fraud, resolve disputes, and maintain financial records. An enterprise Order may define specific retention and deletion requirements.

When an account closes, we delete or de-identify personal information that is no longer required, subject to backup cycles, security evidence, payment and tax records, legal holds, and records necessary to establish that a request was handled. Customers should export records they are required to retain before closing the service.

8. Security

AI Gateway HQ uses administrative, technical, and organizational safeguards designed for the sensitivity of the data, including scoped identity, encrypted transport, encrypted secrets, tenant boundaries, audit events, deployment review, and security monitoring. Security design and current certification status are described in the Trust Center; design-for-a-framework is not a certification.

No online service is risk free. Please report a suspected vulnerability or account compromise through the Contact and Security Disclosure page without including active credentials, sensitive production content, or exploit payloads beyond what is needed to reproduce safely.

9. International processing

The current hosted production service is designed around an AWS region in the United States. Customer-selected model providers and website, identity, support, or payment services may process data in other locations according to their own infrastructure. Enterprise deployment and transfer terms must be confirmed in an Order; the public site does not promise data residency that has not been contracted and validated.

10. Individual rights

Depending on applicable law, a person may have rights to access, correct, delete, restrict, or receive certain personal information, withdraw consent, or object to particular processing. Submit a request through the secure contact channel on this page using the relevant work email. We may verify identity and organizational authority before acting. If information is controlled by a Customer organization, we may direct the request to that organization.

You may also have a right to appeal our response or complain to a privacy regulator. We will not discriminate against a person for exercising an applicable privacy right.

11. Children and changes

The Services are for organizations and are not directed to children under 13 or the minimum age required by local law. We do not knowingly collect a child's personal information through a self-service account.

We may update this notice as the Services and legal requirements change. The effective date identifies the current version. Material changes will be communicated through a reasonable account or website notice when appropriate.

Questions, requests, or notices

Use the encrypted contact workflow for account, billing, privacy, cancellation, or legal requests. Do not submit passwords, card data, provider credentials, gateway keys, or sensitive prompt content.

Open secure contact form
AI Gateway HQ

One secure place to control AI access, cost, routing, and operating evidence.

Checking service status

Platform

RoutingGovernanceSecurityCost control

Use cases

CIOCTOCISOSysadminsFinOpsPrivate equityQuality of earningsFinancial servicesHealthcarePublic sector

Resources

No-card Test LabDocumentationLearning centerStart hereIntegrationsComparisonsInvestorsPartnersTrust centerService statusPricingAI value baselineAI value realization office

Legal

TermsEvaluation termsPrivacyRefunds & cancellationAcceptable useSubprocessors
© 2026 AI Gateway HQ. All rights reserved.
InvestorsSecurityTermsPrivacyContact & disclosures